# Noiz Knowledgebase, full text
410 articles. Source: https://docs.noiz.ie
# Getting Started with Noiz Hosting
Source: https://docs.noiz.ie/getting-started/getting-started-with-noiz-hosting/
This guide gives you a high-level overview of your Noiz hosting account. It helps you start building your website, get your email working, and find your way around the tools included with your plan.
Your Noiz account has two parts. The **client area** at [noiz.co.za](https://www.noiz.co.za) is where you manage your billing, your domains, and your support tickets. Your **hosting control panel** is where you build your website and manage your mailboxes. Depending on your plan, that panel is **Plesk**, **DirectAdmin**, or **ISPConfig**. Both parts are reached from the same login on the Noiz website.
**Table of contents**
- [Set up a website](#set-up-a-website)
- [Manage a domain](#manage-a-domain)
- [Manage emails](#manage-emails)
- [Get help](#get-help)
- [More tools](#more-tools)
If you have not signed up for hosting yet, choose a hosting package on the [Noiz website](https://www.noiz.co.za) and follow the checkout steps. If you get stuck at any point, contact Noiz support using one of the methods in [Get help](#get-help) below.
## Set up a website
Getting a site live comes down to three things: a domain that points at Noiz, the website files themselves, and a secure HTTPS connection. Start here.
- [Set up a domain for your website](/getting-started/how-to-set-up-a-domain-for-your-website/), so visitors can reach your site by name.
- Build a new site. WordPress is the usual starting point. You can [install WordPress manually](/wordpress/how-to-manually-install-wordpress/), or use the one-click installer in your control panel.
- Moving an existing site across? See [how to migrate a WordPress site to Noiz Hosting](/wordpress/how-to-migrate-a-wordpress-site-to-noiz-hosting/).
- Every Noiz hosting plan includes free SSL certificates (Let's Encrypt), so your site can be served securely over HTTPS without any extra purchase.
## Manage a domain
Your domain name and your hosting are separate things: the domain is the address, the hosting is where the site lives. These guides cover choosing, registering, and pointing a domain.
- [Choose the right domain name](/domains-dns/how-to-choose-the-right-domain-name-for-your-website/) for your website.
- [Check whether a domain name is available](/domains-dns/how-to-check-if-a-domain-name-is-available/) before you register it.
- [Claim your free .co.za domain](/domains-dns/your-free-coza-domain-with-noiz-shared-hosting/) with a Noiz shared hosting plan.
- [Point your domain to Noiz Hosting](/domains-dns/how-to-point-your-domain-to-noiz-hosting/) so it serves your new site.
- [Update your registrant (Domain Guardian) details](/domains-dns/what-is-the-domain-guardian-registrant-contact-and-how-to-update-it/).
- [Look up who owns a domain](/domains-dns/what-is-the-whois-lookup-service/) with the WHOIS service.
- [Understand top-level domains (TLDs)](/domains-dns/what-is-a-tld-top-level-domain/) such as .com, .co.za, and .ie.
If you are pointing a domain by nameserver, Noiz client hosting uses `ns1.noiz.co.za` and `ns2.noiz.co.za`.
## Manage emails
Mailboxes are created inside your hosting control panel. Once a mailbox exists, add it to your phone and computer using the setup guides below.
- Create a mailbox in your control panel: [Plesk](/plesk/how-to-create-an-email-address-in-plesk/), [DirectAdmin](/directadmin/how-to-create-an-email-account-in-directadmin/), or [ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/).
- [Set up email on iPhone or iPad](/email/how-to-set-up-email-on-iphone-or-ipad/).
- [Set up email on Android](/email/how-to-set-up-email-on-android/).
- [Set up email in Microsoft Outlook](/email/how-to-set-up-email-in-microsoft-outlook/).
- [Set up email in Mozilla Thunderbird](/email/how-to-set-up-email-in-thunderbird/).
- Email not arriving or being rejected? Work through the [email troubleshooting guide](/email/why-is-my-email-not-working-an-email-troubleshooting-guide/).
## Get help
Noiz support is there whenever a guide does not cover your exact situation.
- [Contact Noiz support](/getting-started/how-to-contact-noiz-for-support/) to see the available channels, response times, and what your plan covers.
- Browse the full [Noiz knowledgebase](https://www.noiz.co.za/knowledgebase/) for step-by-step guides on hosting, email, domains, and WordPress.
## More tools
- Back up your website before you make big changes: [Plesk](/plesk/how-to-generate-a-full-backup-in-plesk/) or [DirectAdmin](/directadmin/how-to-create-and-download-a-full-backup-of-your-account-in-directadmin/).
- Running WordPress? See how to [speed up your WordPress site](/wordpress/how-to-speed-up-your-wordpress-site/) and work through the [WordPress security checklist](/wordpress/wordpress-security-checklist/).
- Manage your billing and [pay with Stripe](/billing/how-to-pay-your-invoice-with-stripe/), and read how to [save (and make) money on your web hosting](/billing/how-to-save-and-make-money-on-your-web-hosting/).
Still not sure where to start? [Contact Noiz support](/getting-started/how-to-contact-noiz-for-support/) and the team will point you in the right direction.
# How to Contact Noiz for Support
Source: https://docs.noiz.ie/getting-started/how-to-contact-noiz-for-support/
Need a hand with your hosting, a technical problem, or a billing query? The Noiz support team can be reached through any of the channels below. Choose whichever suits you best, as every route reaches the same team.
1. **Search the knowledgebase first.** A great many questions already have a step-by-step answer here, so it is worth a look before you get in touch. Browse or search the Noiz knowledgebase at [https://hosting.noiz.co.za/knowledgebase](https://hosting.noiz.co.za/knowledgebase).
2. **Open a support ticket.** Once signed in to the client area, you can raise a ticket directly here: [https://hosting.noiz.co.za/submitticket.php?step=2&deptid=1](https://hosting.noiz.co.za/submitticket.php?step=2&deptid=1). A ticket keeps the full history of your request in one place and is the best channel for anything that needs investigation.
3. **Send an email.** Emailing [support@noiz.co.za](mailto:support@noiz.co.za) automatically opens a ticket. Send it from the email address registered to your account so that the ticket links to your services straight away.
4. **Message on Signal.** For quick questions, the Noiz support team is also on Signal. You can reach the team directly here: [Noiz support on Signal](https://signal.me/#eu/MijTW7DVstP8svqJly0yU4Dhq1M7TaTAU9w06jT61GP3UsAknfdIMoDOomdh7LT2).
## Help Noiz Help You Faster
Whichever channel you use, including a few details up front usually means a quicker resolution:
- The **domain name** or service the request relates to.
- The **exact error message**, copied in full wherever possible.
- What you were doing when the problem occurred, and the steps needed to reproduce it.
- A **screenshot** if the issue is visual.
The Noiz team monitors every one of these channels and aims to respond as quickly as possible. If a request is urgent, note that clearly in the subject line or message so it can be prioritised.
# How to Set Up a Domain for Your Website
Source: https://docs.noiz.ie/getting-started/how-to-set-up-a-domain-for-your-website/
**Table of contents**
- [Register a new domain](#register-a-new-domain)
- [Transfer a domain from another registrar](#transfer-your-domain-from-another-registrar)
- [Use an existing domain and update its nameservers](#i-will-use-my-existing-domain-and-update-my-nameservers)
Every website starts with a domain name. Whether you are registering a brand new domain or bringing one you already own, you choose how the domain is handled at the point where you sign up for a hosting package. This guide walks you through all three options on the Noiz order form so you pick the correct one the first time.
**Last reviewed:** 27 July 2026. This guide covers the domain step of the Noiz order form and client area, and is kept current as the signup flow changes.
Once you have selected a hosting plan from the Noiz website ([shared](https://www.noiz.co.za/shared.php), [WordPress](https://www.noiz.co.za/wordpress.php), [cloud](https://www.noiz.co.za/cloud.php) and so on), the order form presents three options for your domain:
- "[Register a new domain](#register-a-new-domain)",
- "[Transfer your domain from another registrar](#transfer-your-domain-from-another-registrar)", and
- "[I will use my existing domain and update my nameservers](#i-will-use-my-existing-domain-and-update-my-nameservers)".
## Register a new domain
If you do not already have a domain name, choose "**Register a new domain**". Type the name you want for your website, choose a TLD (for example `.co.za` or `.com`) from the drop-down menu, then click the "**Check**" button. The Noiz system runs a WHOIS lookup to determine whether the domain is available for registration.
If the domain is available, a success message confirms it has been added to your cart. If it is unavailable or already registered elsewhere, you receive a warning and can try a different name.
**Note:** If you already own a previously registered domain, skip this section and jump to [transferring](#transfer-your-domain-from-another-registrar) or [pointing](#i-will-use-my-existing-domain-and-update-my-nameservers) it instead.
### Nameservers
Next, set the nameservers for the domain under the "Domains Configuration" section of the order form. The default Noiz nameservers, `ns1.noiz.co.za` and `ns2.noiz.co.za`, are safe to use. If you are new to this and are not sure what nameservers do, leave the defaults in place and continue with the rest of the checkout.
After the domain configuration, the "Billing Details" section appears in one of two states: either you are creating a new customer profile, or you already have one and need to log in.
### Create a new account
New customers complete the "Create a New Account" sign-up form. Fill in your billing and registrant information so Noiz can process the order, then proceed to the next step to complete the checkout.
**Note:** If you are a new customer, skip the next step.
### Already registered?
If you are a returning customer, select the "Already Registered" toggle at the top of the "Billing Details" section to open the login form. Log in with the administrative email address on your account and the password you chose when you signed up. If you have forgotten your details, check your inbox for previous correspondence from Noiz, or [reset your password](https://www.noiz.co.za/password/reset) before proceeding.
### Payment method
Choose a payment method. This is used to register the domain, pay for hosting, and as your default payment method going forward. Noiz accepts:
- **PayFast** and **Stripe** for debit and credit card payments, including automatic recurring billing,
- **Bank transfer (EFT)** for manual payments, and
- **Cryptocurrency** through NOWPayments, including the privacy-focused coin Monero (XMR) and Bitcoin.
If you would like to learn more about paying privately with Monero, see [Pay with Monero (XMR)](/billing/pay-with-monero-xmr/).
**Note:** Noiz requires proof of payment for all EFT payments. Send your proof of payment to `admin[at]noiz.co.za`, quoting the invoice number as the reference. EFT payments can take up to 4 working days to reflect and are only allocated once the proof of payment is received.
### Complete the order
To complete your order, you can optionally add "Additional Notes" in the next section.
**Important:** You must tick the check box next to "I have read and agree to the [Terms of Service](https://www.noiz.co.za/agreement.php)" before you can complete the order.
Finally, in the floating "Order Summary" box on the right, click the "**Complete Order**" button to proceed to payment.
That is it for registering a new domain. Once payment is received, the order is sent automatically to the domain registry with your registrant information and nameservers, and the domain is associated with the matching hosting plan.
**Note:** Domain registration is subject to propagation and can occasionally take up to 24 hours to complete.
## Transfer your domain from another registrar
If you already have a domain name registered with another registrar, you can transfer it to Noiz so your domain and hosting live in one place.
1. Select the "**Transfer your domain from another registrar**" option.
2. Enter the name of the domain you wish to transfer and select its TLD from the drop-down.
3. Click the "**Transfer**" button.
4. If the domain is eligible for transfer, a green success message appears with a "Continue" button. Click it and proceed with the checkout as described above.
**Note:** Transferring a `.co.za` domain is free. Other TLDs may incur a transfer fee, which is shown before you complete the order.
**Note:** If your domain is not eligible for transfer, [contact Noiz support](https://www.noiz.co.za/submitticket.php) to find out the next steps.
### Transfer ticket
If you are only transferring the domain name (with no website or email to worry about), the [domain guardian (registrant contact)](/domains-dns/what-is-the-domain-guardian-registrant-contact-and-how-to-update-it/) receives a "Transfer ticket" as soon as the order is processed, which can safely be accepted.
### Moving website and email data too
If you are also moving other data, such as the website, DNS zone records or email, there are additional things to consider. Complete those migrations before the domain guardian accepts the transfer ticket, so nothing goes offline during the switch. The following guides cover each part:
- How to **transfer a domain** to Noiz,
- How to **transfer an existing website**, and
- How to **migrate email** from your previous host to Noiz.
## Use an existing domain and update its nameservers
Occasionally a customer chooses to keep their domain registered with the current registrar and use Noiz for hosting only. This is possible, though it is not recommended, because your DNS records and nameservers are then managed by a third party rather than in your Noiz client area. If you point the domain at the Noiz nameservers, however, you still get automated DNS updates for your hosting.
1. To order hosting while keeping the domain at another registrar, choose the third option, "**I will use my existing domain and update my nameservers**".
2. Type the domain-name portion in the first box (marked "example").
3. Type the TLD in the second box (marked "com").
4. Click the "**Use**" button and complete the checkout as above.
**Note:** Remember to update the nameservers to the Noiz nameservers from your current registrar's control panel. See [How to Point Your Domain to Noiz Hosting](/domains-dns/how-to-point-your-domain-to-noiz-hosting/) for step-by-step instructions.
## Conclusion
That covers setting up a domain for your website hosting plan across all three signup options.
If you still need to decide on and secure a domain name, these guides help:
- [How to Choose the Right Domain Name for Your Website](/domains-dns/how-to-choose-the-right-domain-name-for-your-website/), and
- [How to Check If a Domain Name Is Available](/domains-dns/how-to-check-if-a-domain-name-is-available/).
Once your hosting and domain are set up, you will usually want to create a website, secure it with an SSL certificate, and create your email accounts. The steps for those depend on the control panel that comes with your plan.
If you have any questions, feel free to [get in touch with Noiz support](https://www.noiz.co.za/submitticket.php).
# How to Access Email from Plesk Webmail
Source: https://docs.noiz.ie/plesk/how-to-access-email-from-plesk-webmail/
Plesk webmail lets you read and send email straight from a web browser, with nothing to install and no mail client to configure. It is the quickest way to check a Noiz mailbox from any computer or phone. This guide shows you how to reach the webmail login page for your domain and what to check if it does not open.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (mail management and webmail)
## Prerequisites
- An email account already created on your Noiz hosting, for example `you@yourdomain.com` (replace with your real address).
- The password for that email account.
- Your domain resolving to Noiz, which is already the case for domains hosted with Noiz.
## Log In to Plesk Webmail
1. Open your browser and go to `https://webmail.yourdomain.com`, replacing `yourdomain.com` with your own domain name.
2. In the **Login** (username) field, enter your **full email address**, for example `you@yourdomain.com`. Do not enter only the part before the @ sign.
3. Enter your email **password**. Passwords are case sensitive.
4. Click **Login**.

After you sign in, you can read, reply to, forward, compose, and organise your email, and set up a signature or an auto-reply from within webmail.
## Other Ways to Open Webmail
If the address above does not work, either of these will take you to the same login page:
- **Via the domain:** open `https://yourdomain.com/webmail` instead of the `webmail.` subdomain.
- **From the Plesk control panel:** log in to Plesk, go to **Mail**, and select the email address you want. Plesk provides a webmail link for each mailbox, which is the most reliable route while a domain's DNS is still settling.
## If the Webmail Page Does Not Load
- **Symptom: the page will not open, or the browser shows a site-not-found or certificate warning.** For a newly added or recently transferred domain, the `webmail.yourdomain.com` address may not have finished propagating in DNS yet. Wait for propagation to complete, or open webmail from the Plesk control panel (see above) in the meantime.
- **Symptom: login is rejected as invalid.** Confirm you typed the full email address, including everything after the @ sign, and that the password is correct. Retype the password rather than pasting it, in case a trailing space was copied. If you have forgotten the password, reset it in the Plesk control panel under **Mail**.
- **Symptom: the page loads but keeps returning to the login screen.** Clear the browser cache or open the page in a private or incognito window, then log in again.
## Need a Hand?
If webmail still will not open after these checks, Noiz support can confirm your mailbox settings and DNS from the server side. Open a ticket from your [Noiz client area](https://www.noiz.co.za) with your domain name and the exact error you see, and the team will take it from there.
# How to Access Your Plesk Mailbox in Gmail
Source: https://docs.noiz.ie/plesk/how-to-access-your-plesk-mailbox-in-gmail/
This guide shows you how to read and send mail from a Noiz mailbox, hosted in Plesk, using Gmail. It is written for people who already live in Gmail all day and would rather not run a second inbox for their domain mail. Gmail can do this, and thousands of businesses run their domain mail this way, but there is one thing to understand before you start, because it decides which of the two routes below you should take.
**Gmail on the web and the Gmail app on your phone are not equally capable here.** The Gmail app can connect to a Noiz mailbox over IMAP, which keeps everything in sync properly. Gmail in a web browser cannot: it can only collect your mail over POP, which is a one-way download. That single difference changes what you get, and it is the reason this guide is split in two.
**Last reviewed:** 29 July 2026, against Gmail on the web and the current Gmail mobile app, with a mailbox hosted in Plesk on Noiz. This guide is written for Noiz hosting and is kept current against Gmail. It complements, and does not replace, the official Google documentation linked below. Google changes the Gmail settings screens regularly: where a screen differs from what is described here, the field names and the values you enter stay the same even when their arrangement moves.
### Official Documentation Reference
- [Check emails from other email accounts (Google)](https://support.google.com/mail/answer/21289): Google's own page for the POP collection feature used in the web route below, including its five-account limit.
- [Send emails from a different address or alias (Google)](https://support.google.com/mail/answer/22370): the "Send mail as" feature, which is the half of the setup that lets you reply from your own domain.
- [Add or remove your email account in the Gmail app (Google)](https://support.google.com/mail/answer/6078445): the mobile route, and the only one that offers full IMAP.
- [Access your mailbox (Plesk Customer Guide)](https://docs.plesk.com/en-US/obsidian/customer-guide/quick-start-with-plesk/set-up-mail-accounts/2-access-your-mailbox.65691/): Plesk's overview of the ways to reach a mailbox. It does not cover Gmail, which is why this guide exists.
## Prerequisites
- The mailbox already exists on the Noiz mail server. If you have not created it yet, do that first: see [How to Create an Email Address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/).
- You know the full email address, for example `you@yourdomain.com`, and its password. The username for Noiz mail is always the full email address, never just the part before the `@`. If you have lost the password you can reset it from Plesk: see [How to Log In to Plesk](/plesk/how-to-log-in-to-plesk/).
- You can reach the mailbox at least once through [Plesk webmail](/plesk/how-to-access-email-from-plesk-webmail/). The web route below requires you to open a verification message that Google sends to the mailbox, and webmail is the simplest place to read it.
- A Gmail account. A free `@gmail.com` account is enough; a Google Workspace account works the same way.
- Your domain's mail is hosted at Noiz. If the domain was pointed to Noiz recently, allow DNS changes time to take effect before `mail.yourdomain.com` will resolve.
## Understand What Each Route Gives You
Read this section before you choose. It is short, and it saves undoing a setup later.
| | Gmail app (IMAP) | Gmail on the web (POP) |
| --- | --- | --- |
| Protocol | IMAP | POP only |
| Folders on the server | Visible and in sync | Not visible. Only new mail in the inbox is collected |
| Read, deleted and filed status | Syncs both ways | Does not sync back to the server |
| New mail arrives | Promptly | When Google next checks, which can be up to an hour |
| Sending as your own address | Handled during setup | Needs a separate "Send mail as" step |
| Accounts you can add | No practical limit | Five |
The practical rule: **if you want your domain mail to behave like a real mailbox, use the Gmail app route.** Use the web route when you specifically want everything funnelled into one browser inbox and you accept that it is a one-way copy.
Many people end up doing both, and that is fine, but only if you set POP to leave a copy of each message on the server. That setting is covered below, and getting it wrong is the single most common way people lose mail in this setup.
## The Noiz Mail Settings
These are the settings a Noiz mailbox uses in any mail program, Gmail included. Wherever you see `yourdomain.com`, replace it with your own domain.
| Setting | Incoming, IMAP (Gmail app) | Incoming, POP (Gmail web) | Outgoing, SMTP (both) |
| --- | --- | --- | --- |
| Server / hostname | `mail.yourdomain.com` | `mail.yourdomain.com` | `mail.yourdomain.com` |
| Port | `993` | `995` | `465` |
| Encryption | SSL/TLS | SSL/TLS | SSL/TLS |
| Username | Your full email address, for example `you@yourdomain.com` | | |
| Password | The mailbox password | | |
Two points that catch people out:
- The username is the **whole address**, including `@yourdomain.com`. A username of just `you` will fail to authenticate.
- Noiz uses **SMTP on port 465 with SSL/TLS**. Gmail's "Send mail as" screen offers 465, 587 and 25; choose **465** and **Secured connection using SSL**. Do not use the unencrypted ports (143, 110 or 25), which Noiz mail does not accept.
## Route 1: The Gmail App on Your Phone (IMAP, Recommended)
This is the better route. The Gmail app treats a Noiz mailbox as a real IMAP account, so folders, and the read or unread status of every message, stay in step with Plesk webmail and any other device.
1. Open the **Gmail** app.
2. Tap your **profile picture** at the top right, then **Add another account**.
3. Choose **Other (IMAP)** from the list of account types. Do not choose Google, Outlook or Yahoo.
4. Enter your full Noiz email address, for example `you@yourdomain.com`, then tap **Next**.
5. If you are offered a choice, select **Personal (IMAP)**.
6. Enter the mailbox password, then tap **Next**.
7. On the **Incoming server settings** screen, confirm the server is `mail.yourdomain.com`, the port is `993` and the security type is **SSL/TLS**. Correct them if the app has guessed differently.
8. On the **Outgoing server settings** screen, set the SMTP server to `mail.yourdomain.com`, the port to `465` and the security type to **SSL/TLS**. Leave **Require sign-in** ticked and confirm the username is your full email address.
9. Tap **Next**, choose your sync preferences, and finish.
Your Noiz mailbox now appears alongside your Gmail account in the app's account switcher. Send yourself a short test message and reply to it, to confirm that sending and receiving both work.
The account you have just added is a normal IMAP account, so the same settings work in any other mail program if you later decide to use one. [Thunderbird](/email/how-to-set-up-email-in-thunderbird/) and [Microsoft Outlook](/email/how-to-set-up-email-in-microsoft-outlook/) are both covered separately.
## Route 2: Gmail in a Web Browser (POP)
Gmail on the web cannot connect to a third-party mailbox over IMAP. It can only fetch mail over POP, and sending is configured separately. That means this route is two jobs, not one, and **you need both halves**. If you set up only the first, your domain mail will arrive in Gmail but every reply will go out from your `@gmail.com` address, which is rarely what anyone wants.
### Part 1: Collect Your Mail (Receiving)
1. Open Gmail in a browser, click the **Settings** gear at the top right, then **See all settings**.
2. Go to the **Accounts and Import** tab.
3. Beside **Check mail from other accounts**, click **Add a mail account**.
4. Type your full Noiz address, for example `you@yourdomain.com`, and click **Next**.
5. Choose **Import emails from my other account (POP3)** and click **Next**.
6. Fill in the POP settings:
- **Username**: your full email address, for example `you@yourdomain.com`
- **Password**: the mailbox password
- **POP Server**: `mail.yourdomain.com`
- **Port**: `995`
7. Tick **Always use a secure connection (SSL) when retrieving mail**. This must be ticked, and the port must read `995`, or the connection will be refused.
8. Tick **Leave a copy of retrieved message on the server**. Read the warning below before you decide otherwise.
9. Optionally tick **Label incoming messages** so domain mail is easy to pick out from your personal Gmail.
10. Click **Add Account**.
**Leave a copy on the server, unless you are certain.** POP's traditional behaviour is to download each message and then delete it from the server. If you untick that box, every message Gmail collects disappears from the Noiz mailbox, which means it vanishes from Plesk webmail, from your phone, and from any other device. It is also no longer covered by mail backups on the server. Leaving a copy costs you nothing except mailbox space, and it is what almost everyone should do.
### Part 2: Send From Your Own Address
Gmail will now offer to let you send from the address as well. If you skipped that prompt, this is how to do it afterwards.
1. Still in **Settings**, on the **Accounts and Import** tab, find **Send mail as** and click **Add another email address**.
2. Enter the **Name** you want recipients to see, and the full address, for example `you@yourdomain.com`.
3. Leave **Treat as an alias** ticked unless you have a specific reason not to, then click **Next Step**.
4. Fill in the SMTP settings:
- **SMTP Server**: `mail.yourdomain.com`
- **Port**: `465`
- **Username**: your full email address
- **Password**: the mailbox password
- Select **Secured connection using SSL**
5. Click **Add Account**. Google sends a verification message to the mailbox.
6. Open that message and click the confirmation link, or copy the code into Gmail. The quickest place to read it is [Plesk webmail](/plesk/how-to-access-email-from-plesk-webmail/), because Gmail's own POP collection may not run for another hour.
Once verified, set the address as your default if your domain mail is the mail you send most: on the **Accounts and Import** tab, click **make default** beside the address. When composing, the **From** line lets you switch between addresses.
## Things Gmail Does Not Do Well With a Custom Domain
None of these are faults in your mailbox. They are how Gmail works, and knowing them up front prevents a support ticket later.
- **POP collection is on Google's schedule, not yours.** Gmail decides how often to check, and the gap can stretch to an hour on a quiet mailbox. If you need mail the moment it arrives, use the Gmail app route, Plesk webmail, or a desktop client. There is no setting that makes web Gmail check on demand reliably.
- **Only the inbox is collected.** POP fetches new messages from the inbox. Mail already filed into folders on the server, and anything a server-side filter moved out of the inbox, will not appear in Gmail.
- **Nothing syncs back.** Reading, deleting or filing a message in web Gmail changes nothing on the Noiz server. If you also use webmail or a phone, the same message will still be sitting there unread.
- **Five accounts is the ceiling.** Gmail on the web will collect from at most five external accounts.
- **Your mail is copied into Google's infrastructure.** Anything Gmail collects is stored on Google's servers and processed there. If keeping your business mail on Noiz infrastructure matters to you, whether for privacy, data residency or POPIA reasons, use [Plesk webmail](/plesk/how-to-access-email-from-plesk-webmail/) or a mail client such as [Thunderbird](/email/why-and-how-to-switch-to-thunderbird/), both of which talk to the Noiz server directly.
- **Sending still goes through Noiz.** Because "Send mail as" is configured against the Noiz SMTP server, your outgoing mail is authenticated as your mailbox and carries your domain's reputation, which is what you want for deliverability. Do not be tempted to remove the SMTP settings so that Gmail sends on your behalf instead.
## Troubleshooting
**Symptom: "Authentication failed" or "Username and password not accepted".** Almost always the username. It must be the full address, `you@yourdomain.com`, not `you`. Confirm the password by signing in to Plesk webmail with the same credentials; if webmail rejects them too, reset the mailbox password in Plesk.
**Symptom: "Could not connect to server" or the request times out.** Check the port and the encryption together. POP must be `995` with SSL ticked, and SMTP must be `465` with "Secured connection using SSL" selected. A mismatched pair, such as port 995 with SSL unticked, fails in exactly this way.
**Symptom: the server name is not recognised.** Confirm that `mail.yourdomain.com` resolves. On a domain recently pointed to Noiz, this can lag behind the rest of the DNS changes. As a temporary measure the server's own hostname will also work, but `mail.yourdomain.com` is the correct long-term value.
**Symptom: the verification message never arrives.** Look in the mailbox directly through Plesk webmail rather than waiting for Gmail to collect it, and check the spam folder. Google's verification mail is sent to the mailbox itself, so it is there even when Gmail has not fetched it yet.
**Symptom: replies go out from your @gmail.com address.** The "Send mail as" half was not completed, or the domain address was never made the default. Return to Part 2 above.
**Symptom: mail has disappeared from webmail and your phone.** The "Leave a copy of retrieved message on the server" box was not ticked, so Gmail has been deleting each message after collecting it. Tick it now to stop further losses. Messages already collected still exist inside Gmail and can be forwarded back to the mailbox, but they are no longer on the server.
For anything not covered here, the general guide is [Why Is My Email Not Working? An Email Troubleshooting Guide](/email/why-is-my-email-not-working-an-email-troubleshooting-guide/).
## Still Stuck?
If the mailbox works in Plesk webmail but will not connect from Gmail, the problem is in the Gmail configuration rather than the mailbox, and the settings table above is the place to start. If webmail will not accept the password either, the mailbox itself needs attention. Open a ticket from the Noiz client area with the address you are configuring, the route you chose, and the exact wording of any error Gmail showed you, and Noiz support will pick it up from there.
# How to Add a New Domain in Plesk
Source: https://docs.noiz.ie/plesk/how-to-add-a-new-domain-in-plesk/
This guide shows you how to add a new domain to your hosting in Plesk, so you can host an additional website alongside the ones you already run. It applies whether the domain is already registered or you want to start building before you own it.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide: Websites & Domains](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Prerequisites
- An active Plesk subscription on your Noiz hosting plan, with room in your plan for an additional domain.
- Access to your Plesk login. You reach the panel from your Noiz client area, or at the panel address supplied when your hosting was set up.
- The domain name you want to add. If it is not registered yet, you can still create the site using a temporary domain name and switch to the real one later.
## Add a New Domain in Plesk
1. Log in to your Plesk panel.
2. In the sidebar, click **Websites & Domains**. 
3. Click **Add Domain**. 
4. On the **Add a Domain** screen, choose **Blank Website**. This creates an empty document root that you can upload your own files to, or install an application into afterwards. 
5. Under **Adding New Domain**, complete the form: 
- **Select your domain name**: choose **Registered domain name** if you already own the domain. Choose **Temporary domain name** if you do not own one yet. Plesk then gives you a preview address that you can replace with the real domain later.
- **Registered domain name**: type your domain, for example `yourdomain.com` (replace this with your own).
- **Hosting type**: select **Website Hosting**. You can leave the remaining DNS and mail options at their defaults.
6. Click **Add Domain**.
Plesk creates the domain and returns you to **Websites & Domains**, where the new domain appears as its own card. From there you can upload files, install applications, create mailboxes and manage DNS.
## Make the Domain Resolve
Adding a domain in Plesk sets up the hosting space, but the domain will not load in a browser until its DNS points at Noiz. If you registered the domain elsewhere, set its nameservers to:
- `ns1.noiz.co.za`
- `ns2.noiz.co.za`
DNS changes can take up to 24 to 48 hours to propagate. Once the domain resolves to the server, you can issue a free SSL certificate for it from the domain's card in **Websites & Domains**.
## Troubleshooting
**The Add Domain button is greyed out or missing**: your subscription may have reached the number of domains allowed on your plan. Check your plan limits in the Noiz client area, or upgrade to add more.
**The domain shows a default or placeholder page**: this is normal for a blank website until you add content. Upload your files to the domain's document root, or install an application onto it.
**The domain will not load at all**: confirm the nameservers are set to `ns1.noiz.co.za` and `ns2.noiz.co.za`, and that DNS has had time to propagate.
If you are on a managed Noiz plan, or you would like Noiz to add or configure a domain for you, contact the Noiz support team from your client area and the team will set it up.
# How to Add a Subdomain in Plesk
Source: https://docs.noiz.ie/plesk/how-to-add-a-subdomain-in-plesk/
A subdomain lets you run a separate section of your website under your main domain, for example `blog.yourdomain.com` or `shop.yourdomain.com`, without registering a new domain name. Each subdomain gets its own folder on the server, so you can host a completely separate site, application or staging environment under it. This guide shows you how to add a subdomain from your Plesk control panel on Noiz hosting.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/). The Websites & Domains section covers subdomains, document roots and hosting settings in depth.
## Prerequisites
- An active Noiz hosting plan with a Plesk login.
- A domain already present in your Plesk subscription. A subdomain is always created under an existing domain.
## Add a Subdomain
1. Log in to your Plesk account.
2. Click **Websites & Domains** in the sidebar menu.

3. Click **Add Subdomain**.

4. Enter a **Subdomain name** and choose the parent domain from the **Domain** field. Plesk suggests a document root path automatically. You can leave it as the default or point it at an existing folder.

5. Click **OK**.
Once the subdomain is created, it appears under **Websites & Domains**, where you can manage its files, DNS, email and SSL/TLS settings in the same way as a normal domain.
## What to Do Next
- **Upload your content.** A new subdomain's document root starts empty apart from a placeholder page, so upload your site into that folder using File Manager or FTP.
- **Secure it with HTTPS.** A subdomain needs its own certificate. Open the subdomain's **SSL/TLS Certificates** and issue a free Let's Encrypt certificate so that `subdomain.yourdomain.com` loads over HTTPS.
- **Allow for DNS.** When your domain uses the Noiz nameservers (`ns1.noiz.co.za` and `ns2.noiz.co.za`), the DNS record for the subdomain is created for you automatically. If your DNS is hosted elsewhere, add an A or CNAME record for the subdomain and allow time for it to propagate.
## Troubleshooting
**The subdomain shows the default Plesk page:** no content has been uploaded yet, or the document root points at the wrong folder. Check the document root under the subdomain's **Hosting Settings**.
**The subdomain will not load, or the browser warns about the certificate:** DNS may still be propagating, or the subdomain has no SSL certificate yet. Issue a Let's Encrypt certificate for the subdomain and try again.
If you are on a managed Noiz plan and would prefer the Noiz team to add or configure a subdomain for you, open a support ticket from your client area and the team will take care of it.
# How to Change Email Account Password in Plesk
Source: https://docs.noiz.ie/plesk/how-to-change-email-account-password-in-plesk/
This guide shows you how to change the password for an email account (mailbox) that is hosted in Plesk. You would typically do this when a mailbox password has been forgotten, may have been exposed, or simply needs rotating as good security hygiene.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting, where Plesk runs on `neo.noiz.co.za`, and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide (Mail section)](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Prerequisites
- A Plesk login with access to the subscription that owns the mailbox.
- The email address whose password you want to change.
## Change the Mailbox Password
**1.** Log in to your Plesk account.
**2.** Click **Mail** in the sidebar menu.

**3.** In the list of email addresses, click the mailbox whose password you want to change.

**4.** In the **Password** field, type a new password, or click **Generate** to have Plesk create a strong one for you. Click **Show** to reveal the password so you can copy it and store it somewhere safe.

**5.** Click **OK** (or **Apply**) to save the change. The new password takes effect immediately.
## After You Change the Password
Changing the password in Plesk changes it everywhere that mailbox is used. Any device or program that was signed in with the old password will stop sending and receiving mail until you update it:
- Update the saved password in every email client (for example Outlook, Apple Mail or Thunderbird) and on every phone or tablet that collects that mailbox.
- Webmail sessions that are already open stay signed in, but you will need the new password the next time you log in.
Leaving an old password configured on a device is one of the most common causes of "cannot connect" errors, and the repeated failed login attempts can temporarily block your connection for security reasons. If that happens, correct the password on every device first, then wait a few minutes before trying again.
## Troubleshooting
**Plesk rejects the password as too weak**: Plesk enforces a minimum strength policy. Use the **Generate** button, or choose a longer passphrase that mixes upper and lower case letters, numbers and symbols.
**Mail still will not connect after the change**: Confirm the new password is entered correctly on the device, with no trailing spaces, and that the account is still using the correct incoming and outgoing server settings for your domain.
If you are on a Noiz managed hosting plan and would prefer the Noiz team to reset a mailbox password for you, contact support and Noiz will take care of it.
# How to Change View Mode in Plesk
Source: https://docs.noiz.ie/plesk/how-to-change-view-mode-in-plesk/
The **Websites & Domains** page in Plesk can be shown in different view modes, which change how your domains and their tools are laid out on screen. This guide shows you how to switch between those view modes on your Noiz hosting, so you can pick the layout that suits how you work.
Plesk offers three view modes on this page:
- **Active List**: the default modern layout. Each domain is shown as a panel with its most-used tools (files, databases, email, and so on) grouped together.
- **Classic List**: a more compact, table-style layout that lists domains in rows. Handy if you manage many domains and want them all visible at once.
- **Dynamic List**: an older layout carried over from earlier Plesk releases.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Prerequisites
- Your Plesk login details for your Noiz hosting account.
## Change the view mode in Plesk
**1.** Log in to your Plesk account.
**2.** Click **Websites & Domains** in the sidebar menu.

**3.** If the page is currently in **Dynamic List** view, click **Change View** on the right-hand side and choose your preferred mode.

**4.** If the page is currently in **Active List** or **Classic List** view, click the **wrench** icon to switch to a different mode.

Your choice takes effect straight away and Plesk remembers it for the next time you open the page. You can switch back at any time using the same controls, so there is no harm in trying each mode to see which one you prefer.
## Need a hand?
If the view controls are not where you expect, or the page will not load, contact the Noiz support team through your client area and they will help you sort it out.
# How to Change Your Plesk Account Contact Details
Source: https://docs.noiz.ie/plesk/how-to-change-your-plesk-account-contact-details/
Your Plesk account holds the contact details Plesk uses to identify you and to send you account notifications, such as certificate expiry warnings and administrative alerts. This guide shows you how to view and update those details (your name, email address, phone number, and address) from inside the Plesk control panel on your Noiz hosting.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Before you start
- You need your Plesk login details for your Noiz hosting account.
- The contact details you set here apply to your Plesk panel only. They are separate from the billing contact details Noiz holds for you in the client area, which you update from your client-area profile. Changing one does not change the other.
## Change your Plesk contact details
**1.** Log in to your Plesk account.
**2.** Click **Account** in the sidebar menu.

**3.** Click **My Profile**.

**4.** Click the **Contact Details** tab.

**5.** Update the details as needed. The email address you enter here is where Plesk sends account notifications, so keep it current and make sure you can receive mail at it.

**6.** Click **Apply**.

Plesk shows a success message confirming that your contact details have been updated.
## Need a hand?
If you cannot reach your Plesk panel or the change does not save, contact the Noiz support team through the client area and they will help you sort it out.
# How to Change Your Plesk Account Password
Source: https://docs.noiz.ie/plesk/how-to-change-your-plesk-account-password/
This guide shows you how to change the password you use to sign in to your Plesk control panel, from inside Plesk itself. Use this when you already know your current password and simply want to set a new one. If you have forgotten your password and cannot log in at all, use the password reset option on the Plesk login screen instead.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide: Account Management](https://docs.plesk.com/en-US/obsidian/customer-guide/account-management.65207/)
## Prerequisites
- Your current Plesk sign-in details (username or email address, and current password).
- Access to the Plesk control panel for your Noiz hosting account.
## Change your Plesk password
1. Log in to your Plesk control panel with your current password.
2. In the sidebar menu, click **Account**. 
3. Click **My Profile**. 
4. In the **Password** field, type the new password you want to use, or click **Generate** to have Plesk create a strong password for you. 
5. Click **OK** to save.
Your password is updated immediately. You can now sign in with the new password.
## Good to know
- Plesk enforces a minimum password strength. If you type your own password and it is rejected as too weak, add length and a mix of upper case, lower case, numbers and symbols, or use the **Generate** button, which always meets the requirement.
- This changes the password for signing in to the Plesk control panel. If you set up separate FTP or database users, those keep their own passwords and are changed separately.
- Choose a unique password you do not use anywhere else, and store it in a password manager rather than a note or browser you share.
## Troubleshooting
**The new password is rejected as too weak**: increase its length and complexity, or click **Generate** and use the suggested password.
**You cannot log in to change the password**: this procedure is for changing a password you already know. If you have forgotten it, use the password reset link on the Plesk login screen to receive a reset by email.
If you are on a managed Noiz plan and would rather the Noiz team make this change for you, or you are locked out and the reset email is not arriving, open a support ticket from your Noiz client area and the team will assist.
# How to Change an FTP Account Password in Plesk
Source: https://docs.noiz.ie/plesk/how-to-change-an-ftp-account-password-in-plesk/
This guide shows you how to change the password on an **additional FTP account** for a domain hosted on your Noiz Plesk hosting. Rotating an FTP password is the quickest way to lock out old credentials after someone leaves the team, a device is lost or stolen, or you suspect a login has been exposed.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
Plesk keeps two different kinds of FTP login, and they are changed in different places:
- The **main FTP account** is the subscription's own system user. Its password is the same credential as your main Plesk hosting login, so you change it by changing your hosting account password rather than through the FTP Access screen below. It is not a "root" account and has no server-wide access.
- **Additional FTP accounts** are the extra logins you create per domain to give a person or an application access to a specific folder. The steps below cover these.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide: FTP Access to Your Websites](https://docs.plesk.com/en-US/obsidian/customer-guide/website-management/ftp-access-to-your-websites.65210/)
- [Plesk Obsidian Customer Guide: Adding and Managing FTP Accounts](https://docs.plesk.com/en-US/obsidian/customer-guide/website-management/ftp-access-to-your-websites/adding-ftp-accounts.65212/)
## Prerequisites
- Your Plesk login for the subscription that hosts the domain.
- The name of the FTP account you want to update, if the domain has more than one.
## Change an FTP Account Password
1. Log in to your Plesk account.
2. Click **Websites & Domains** in the sidebar menu. 
3. Under the list of **Domain names**, click the domain you want to work with. 
4. Under **Files & Databases**, click **FTP Access**. 
5. Click the FTP account you want to change. 
6. In the **Password** field, type a new password, or click **Generate** to have Plesk create a strong one for you. Click **Show** to reveal the password so you can copy it before you save. 
7. Confirm with **OK**.
The change takes effect immediately. There is no need to restart anything, and other FTP accounts on the domain are not affected.
## After You Change the Password
- **Update your FTP client.** Any saved connection in FileZilla, WinSCP, Cyberduck or a similar client still holds the old password and will fail to connect until you update the stored credential.
- **Update anything that logs in automatically.** Backup jobs, deployment pipelines and site plugins that upload over FTP will stop working until they are given the new password.
- **Prefer a secure connection.** Where your client supports it, connect over **FTPS** (explicit FTP over TLS) or **SFTP** rather than plain FTP so that the password and file contents are encrypted in transit.
## Troubleshooting
**The new password is rejected**: Plesk enforces a minimum password strength. Use a longer password that mixes upper and lower case letters, digits and a symbol, or click **Generate** to let Plesk produce one that meets the policy.
**Connections still fail after saving the new password**: the client is almost certainly reusing the old, cached credential. Remove the saved password from the FTP client's site or bookmark entry and enter the new one by hand.
**You cannot see an FTP Access option, or no accounts are listed**: confirm you are inside the correct domain and that your hosting plan includes additional FTP accounts. If the domain only shows the main system user, that login is changed through your Plesk hosting password, not here.
If you are on a Noiz managed plan and would rather Noiz rotate the credential for you, or you have lost access to the Plesk account entirely, contact Noiz support and the team will assist.
# How to Change the Language in Plesk
Source: https://docs.noiz.ie/plesk/how-to-change-the-language-in-plesk/
This guide shows you how to change the interface language of your Plesk account on Noiz hosting. The change applies to your own account only, so other users on the same server keep whatever language they have chosen. You can switch back to English, or to any other installed language, at any time by repeating these steps.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) covers your account and profile settings.
- [Plesk Interface Languages](https://docs.plesk.com/en-US/obsidian/administrator-guide/plesk-administration/interface-languages.73349/) explains how languages are installed and managed server-wide (administrator only).
## Prerequisites
- A Plesk account on your Noiz hosting service, with your login details to hand.
- The language you want must already be installed on the server. English is always available. If the language you need is not in the list, contact Noiz support and it can be added.
## Change Your Plesk Interface Language
1. Log in to your Plesk account.
2. In the sidebar menu, click **Account**. 
3. Click **My Profile**. 
4. Scroll down to **Interface language** and choose the language you want from the drop-down menu. Depending on your Plesk view, this field may instead be labelled **Plesk language**. 
5. Click **Apply**. The interface reloads in your chosen language straight away. 
Your Plesk interface language has now been changed.
## Good to Know
- **Your setting is personal.** This preference is stored against your own account and does not change the language for any other user, or the server default.
- **A few items may stay in English.** Some third-party extension screens and error messages are not fully translated, so the odd label can remain in English even after you switch.
## Troubleshooting
**The language you want is not in the drop-down menu:** only languages installed on the server appear in the list. Ask Noiz support to install the language pack you need, then repeat the steps above.
**The interface did not switch after clicking Apply:** refresh the page or log out and back in. If it still shows the previous language, clear your browser cache and try once more.
If you are on a Noiz managed hosting plan and would like the change made for you, or you need a language installed that is not yet available, contact Noiz support and the team will take care of it.
# How to Check Disk and Bandwidth Usage in Plesk
Source: https://docs.noiz.ie/plesk/how-to-check-disk-and-bandwidth-usage-in-plesk/
Every hosting plan comes with a set amount of disk space (how much your files, databases, and mailboxes take up on the server) and a monthly bandwidth allowance (how much data your site transfers to visitors). Keeping an eye on both helps you spot a mailbox that is filling up, a backup that is eating space, or a sudden traffic spike before any of it starts to affect your site. This guide shows you how to check your current disk and bandwidth usage from the Plesk control panel on your Noiz hosting.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Before you start
- You need your Plesk login details for your Noiz hosting account.
- Statistics in Plesk are refreshed on a schedule rather than in real time, so the figures you see reflect the last update and may lag the current moment by a few hours. Disk usage tends to update sooner than traffic figures.
## Check your disk and bandwidth usage
**1.** Log in to your Plesk account.
**2.** Click **Statistics** in the sidebar menu.

**3.** If your account holds more than one domain, click the domain you want to check.

**4.** Read your usage from the summary. Disk space usage is shown on the left, and your traffic (bandwidth) usage is shown on the right.

From the same page you can drill into the detailed breakdowns for **FTP**, **Data Transfer**, and **Web Statistics** to see where your space and traffic are actually going.
## Making sense of the figures
- **Disk space** counts everything stored under your account: website files, databases, email held in mailboxes, and any logs or backups kept on the server. If your disk figure climbs unexpectedly, a large mailbox or an old backup is the usual culprit.
- **Traffic (bandwidth)** measures the data your account transfers over the billing period and resets at the start of each new period. A one-off spike usually just means a busy day; a steady climb can point to growing traffic or a resource being downloaded repeatedly.
- The **Data Transfer** breakdown separates web, FTP, and mail traffic, which makes it easy to tell ordinary visitor traffic apart from, say, a large FTP upload.
## Need a hand?
If your usage is close to your plan's limits, or you are not sure what is consuming your space or bandwidth, contact the Noiz support team through the client area. They can help you track down the cause and, where it makes sense, look at the right plan for your needs.
# How to Configure FTP Remote Backup Storage in Plesk
Source: https://docs.noiz.ie/plesk/how-to-configure-ftp-remote-backup-storage-in-plesk/
Remote backup storage keeps a copy of your website and database backups on a separate server, so a failure of the hosting server does not take your only backups with it. This guide shows you how to point Plesk at an external FTP or FTP(S) server and use it as a backup destination on your Noiz hosting account.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide: Backing Up and Restoring Websites](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Prerequisites
- Access to your Plesk hosting account on the Noiz Plesk server, with the **Websites & Domains** area available.
- A reachable FTP or FTP(S) server to hold the backups, and its hostname or IP address.
- An FTP user name and password for that server, plus a target directory that already exists and is writable.
## Configure the FTP(S) Storage in Plesk
1. Log in to Plesk on your Noiz hosting account.
2. Go to **Websites & Domains** and open **Backup & Restore**. 
3. Click **Remote Storage Settings**. 
4. Click **FTP(S)**. 
5. Complete the following fields: 
- **Use FTP(S) storage**: tick this so the storage is enabled.
- **FTP server hostname or IP address**: enter the address of your FTP server.
- **Directory for backup files storage**: enter the path where backups are written, for example `/backups`. The directory must already exist on the FTP server.
- **FTP user name**: enter the user name for the FTP account.
- **FTP password**: enter the password for the FTP account.
- **Use passive mode**: enable this unless you have a specific reason not to. Passive mode is usually required when the server sits behind a firewall or NAT, and it avoids most connection problems.
- **Use FTPS**: tick this only if the remote server supports FTP over TLS. It encrypts the connection so your credentials and backup data are not sent in clear text.
6. Click **OK** to save. In some Plesk builds this button is labelled **Apply**.
If Plesk shows a success message, the FTP(S) storage is configured. You can now select it as the destination when you create a backup manually, or when you set up a scheduled backup.
## Good to Know
- FTPS here means FTP over TLS, not SFTP over SSH. The two are different protocols, and this screen configures FTP or FTP over TLS only.
- Plain FTP sends your user name, password and backup data unencrypted. Where the target server supports it, always tick **Use FTPS**.
- Run a small manual backup to the FTP(S) storage first to confirm the connection and credentials work, before you rely on it for scheduled backups.
- Remote storage is a destination only. You still create or schedule the backups themselves from **Backup & Restore**.
## Troubleshooting
- **Connection failed or times out**: check the hostname or IP address, and confirm the FTP server is reachable from the internet. Enable **Use passive mode** if the connection hangs.
- **Authentication failed**: re-enter the FTP user name and password, and confirm the account has write access.
- **Cannot write to the directory**: make sure the path in **Directory for backup files storage** already exists and that the FTP user can write to it.
If you are on a Noiz managed hosting plan and would like help configuring remote backups or checking your backup schedule, contact Noiz support and the team will assist.
# How to Configure Local Backups in Plesk for a Subscription
Source: https://docs.noiz.ie/plesk/how-to-configure-local-backups-in-plesk-for-a-subscription/
Keeping a recent copy of your website, mail, and databases means you can recover quickly from a bad update, a compromised file, or an accidental deletion. Plesk includes a built-in Backup Manager that lets you create, schedule, and restore backups for a subscription without any extra software. This guide shows you how to configure **local backups** (stored on the server) for a subscription on Noiz hosting.
**Local backups are for fast rollbacks, not disaster recovery.** Because they live on the same server as your website, they will not help if the server itself is lost. Pair local backups with an off-server copy using remote storage (see the related articles at the end).
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/): see the "Backing Up and Recovering Websites" section for the full reference on the Backup Manager, on-demand backups, and scheduled backup settings.
## Prerequisites
- A hosting subscription on a Noiz Plesk server, with the login details from your Noiz welcome email.
- Access to the Plesk panel, usually reached on port `8443`, for example `https://yourdomain.com:8443` (replace `yourdomain.com` with your own domain).
- Enough free disk space in your subscription quota. Local backups are stored on the server and count towards your subscription's disk usage.
## Accessing the Backup Manager
Log in to your Plesk panel and go to **Websites & Domains**. On the card for the domain you want to back up, open the **Dashboard** tab and click **Backup & Restore**. This opens the Backup Manager, where every backup task for the subscription is listed and managed.
## Creating an on-demand backup
An on-demand (manual) backup is the quickest way to capture a known-good state just before you make a risky change, such as updating a theme, a plugin, or the PHP version.
1. In the Backup Manager, click **Back Up**.
2. Under **Back up the subscription**, choose what to include:
- **Configuration**: the hosting and service settings for the subscription.
- **Mail messages**: the contents of the mailboxes.
- **User files**: the website files and content.
- **Databases**: all databases attached to the subscription.
3. Under **Store in**, select **Server storage** to keep the backup locally.
4. Choose the **Type**:
- **Full**: backs up everything you selected, every time.
- **Incremental**: backs up only the web and mail data that changed since the last backup. Databases are always backed up in full.
5. (Optional) Add a **Comment** to label the backup so it is easy to identify later.
6. (Optional) Enable any of the following:
- **Exclude log files** to reduce the backup size.
- **Exclude specific files from the backup** to skip chosen paths.
- **When a backup task is completed, send a notification email to**, then enter an address for status updates.
7. Click **OK** to start the backup. It appears in the Backup Manager list once it finishes.
## Scheduling automatic backups
A schedule protects the subscription without you having to remember. Set it once and Plesk runs it in the background.
1. In the Backup Manager, click **Schedule**.
2. On the **Scheduled Backup Settings** page, tick **Activate this backup task**.
3. Under **Run this backup task**, choose how often it runs:
- **Daily**: set the hour and minute, and confirm the timezone is correct.
- **Weekly**: pick the day (or days) of the week and the time.
- **Monthly**: pick the day of the month and the time.
4. Choose the backup type:
- **Use incremental backup**: stores only what changed since the previous run.
- Leave it unticked to perform a **full backup** on every run.
5. Set **Maximum number of full backup files to store**. This is your retention limit: once it is reached, Plesk removes the oldest backup as it creates a new one. Plesk also enforces a server-level cap, shown on screen, and your value must be equal to or less than it.
6. Under **Back up**, select what to include (configuration, mail messages, user files, databases).
7. Under **Store in**, select **Server storage** for local backups.
8. (Optional) Enable **Exclude log files**, **Exclude specific files from the backup**, or **If errors occur during the execution of this backup task, send a notification email to**.
9. Click **OK** to save the schedule.
## Restoring from a backup
**Restoring overwrites the current data** with the contents of the backup, so make sure you have selected the right one before you confirm.
1. In the Backup Manager, find the backup you want to use.
2. Click the backup date to open its details.
3. Choose what to restore: the entire subscription, or only the files, mail, databases, or configuration.
4. Click **Restore** and confirm.
## Best practices for local backups
- Keep several recent backups so you can roll back to more than just the latest state.
- Combine full and incremental backups to balance storage use against restore speed.
- Check your available disk space regularly. Local backups count towards your subscription quota, and a full quota is the most common reason a backup task fails.
- Use clear comments when creating backups so the right one is easy to find at restore time.
- Always keep at least one off-server copy as well (see the remote backup options below). Local backups on their own will not protect you if the server is lost.
## Troubleshooting
- **Backup fails with a disk space or quota error**: local backups are stored inside your subscription and count towards its disk quota. Free up space, lower the retention limit, or enable **Exclude log files**.
- **A scheduled backup did not run**: confirm **Activate this backup task** is ticked, and check the time and timezone set on the schedule. Add a notification email so Plesk can alert you if a run fails.
- **Cannot raise the retention number**: Plesk caps the maximum number of stored full backups at server level, and your value cannot exceed the limit shown on screen.
Local backups are a first line of defence, but they are only half of a safe backup strategy. If you would like Noiz to help set up off-server backups or advise on a retention policy for your subscription, contact the Noiz support team through your client area.
## Related articles
- [How to configure remote backups in Plesk using FTP(S) storage](/plesk/how-to-configure-remote-backups-in-plesk-using-ftps-storage/)
- [How to configure remote backups in Plesk using Dropbox storage](/plesk/how-to-configure-remote-backups-in-plesk-using-dropbox-storage/)
- [How to configure remote backups in Plesk using SFTP storage](/plesk/how-to-configure-remote-backups-in-plesk-using-sftp-storage/)
# How to Configure Remote Backups in Plesk Using Dropbox Storage
Source: https://docs.noiz.ie/plesk/how-to-configure-remote-backups-in-plesk-using-dropbox-storage/
Plesk can send subscription backups straight to your own Dropbox account, giving you an off-site copy that survives problems on the server itself. This guide shows you how to connect Plesk to Dropbox, run and schedule backups to it, and restore from a Dropbox backup when you need to. It is written for Noiz Plesk hosting, where your subscription lives on a shared, managed Plesk server.
The key thing to understand before you start: Dropbox support is not part of core Plesk. It is added by the **Dropbox Backup** extension, which the server administrator installs once for the whole server. On Noiz managed Plesk the extension is provided for you, so you connect your own Dropbox account and Plesk stores backups inside a dedicated app folder that Plesk creates in your Dropbox.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** and the Dropbox Backup extension **4.4.2** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Dropbox Backup extension](https://www.plesk.com/extensions/dropbox-backup/) (features, requirements and version)
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (backing up and restoring your subscription)
## Prerequisites
- Access to your subscription in Plesk on your Noiz hosting account.
- A Dropbox account with enough free space for the backups you intend to keep. Backups can be large, so check your Dropbox quota first.
- The **Dropbox Backup** extension available on the server. On Noiz managed Plesk this is already in place. If the Dropbox option is missing from **Remote Storage Settings**, contact Noiz support rather than trying to install extensions yourself, as extension installation is a server-administrator task.
## Accessing remote storage settings
1. Log in to Plesk.
2. Open **Websites & Domains** and select **Backup & Restore** (sometimes shown as the Backup Manager) for your subscription.
3. In the Backup Manager, click **Remote Storage Settings**.
4. In the list of storage types, select **Dropbox**.

## Connecting Plesk to your Dropbox account
Plesk uses Dropbox's own sign-in and permission screen (OAuth) to connect. You never enter your Dropbox password into Plesk; you authorise Plesk from within Dropbox instead, and Dropbox hands back a token that Plesk stores securely.
1. On the **Dropbox** tab in Remote Storage Settings, click the option to connect or authorise (labelled **Configure** or **Sign in to Dropbox** depending on your Plesk build).
2. A Dropbox window opens. Sign in with your Dropbox account if you are not already signed in.
3. Review the access Dropbox is about to grant and click **Allow**. Plesk requests access only to its own app folder, not to the whole of your Dropbox.
4. You are returned to Plesk, which confirms the connection. Backups are stored in the app folder that Plesk creates inside your Dropbox (typically under `Apps`).
## Backing up a subscription to Dropbox
Once the connection is in place, Dropbox appears as a destination whenever you create a backup.
1. In the Backup Manager, click **Back Up**.
2. Under **Store in** (or **Backup location**), select **Dropbox storage**.
3. Choose what to include (for example, configuration and content, or configuration only), and whether the backup is **Full** or **Incremental**.
4. Click **OK** to start the backup. Larger sites take longer, and the transfer to Dropbox is limited by your server and Dropbox upload speed.

### Scheduling backups to Dropbox
To back up on a recurring basis, use **Schedule** in the Backup Manager, set the frequency and retention (how many backups to keep), and choose **Dropbox storage** as the destination.
Note that **scheduled** backups to remote cloud storage such as Dropbox depend on the Backup to Cloud Pro capability of the extension. On-demand backups to Dropbox work without it. If **Dropbox storage** does not appear as a destination when scheduling, that capability is not enabled for your plan; contact Noiz support to discuss options. Setting a sensible retention limit also matters, so old backups are rotated out and do not fill your Dropbox quota over time.
## Restoring from a Dropbox backup
1. Open the **Backup Manager** for the subscription.
2. Make sure the **Dropbox** storage is shown, so its backups are listed.
3. Select the backup you want, click **Restore**, and choose whether to restore everything or only specific objects (for example, a single mailbox or database).
4. Confirm to begin. Restoring overwrites current data with the contents of the backup, so restore to the right subscription and be sure you have chosen the correct backup point.
## Troubleshooting
- **Dropbox is missing from Remote Storage Settings**: the Dropbox Backup extension is not enabled on the server. Contact Noiz support.
- **Authorisation fails or the connection is lost**: revoking Plesk's access in your Dropbox account settings, or changing your Dropbox password, can break the stored token. Reconnect by repeating the authorisation step above.
- **Backup fails partway through**: this is almost always a full Dropbox account. Free up space or reduce how many backups you retain, then run the backup again.
- **Dropbox does not appear when scheduling**: scheduled cloud backups require the Backup to Cloud Pro capability. On-demand backups still work; contact Noiz support about scheduled cloud backups.
## Related articles
- [How to Configure Local Backups in Plesk for a Subscription](/plesk/how-to-configure-local-backups-in-plesk-for-a-subscription/)
- [How to Configure Remote Backups in Plesk Using FTP(S) Storage](/plesk/how-to-configure-remote-backups-in-plesk-using-ftps-storage/)
- [How to Configure Remote Backups in Plesk Using SFTP Storage](/plesk/how-to-configure-remote-backups-in-plesk-using-sftp-storage/)
If you would like Noiz to review your backup strategy or help set up off-site backups for your subscription, contact Noiz support and the team will assist.
# How to Configure Remote Backups in Plesk Using FTP(S) Storage
Source: https://docs.noiz.ie/plesk/how-to-configure-remote-backups-in-plesk-using-ftps-storage/
For added resilience, you can store your Plesk backups on your own remote server instead of keeping them only on the hosting server. Plesk has built-in support for FTP and FTPS (FTP over TLS) connections, so setting up off-site backup storage does not require any extra extensions. This guide shows you how to configure FTP(S) storage for a subscription, send scheduled backups to it, and restore from it. "FTP(S)" simply means the same feature works with either a plain FTP server or an encrypted FTPS server.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable line). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (open **Website Management**, then **Backing Up and Restoring Websites**, for the full remote-storage reference).
## Prerequisites
- Access to your subscription in Plesk (the **Websites & Domains** area).
- Your own remote server running an FTP or FTPS service that is reachable from the internet.
- The remote server's hostname or IP address, an FTP username and password with write access, and the directory path where backups should be written.
- FTPS enabled on that remote server if you want encrypted transfers, which Noiz recommends over plain FTP.
If you only need backups kept on the hosting server itself, see [How to configure local backups in Plesk for a subscription](/plesk/how-to-configure-local-backups-in-plesk-for-a-subscription/) instead.
## Accessing FTP(S) storage settings
1. Log in to Plesk.
2. Go to **Websites & Domains** and open **Backup & Restore**.
3. In the Backup Manager, click **Remote Storage Settings**.
4. Select **Use FTP(S) storage**.
## Configuring FTP(S) storage
Complete the fields as follows:
- **FTP server hostname or IP address (required)**: the address of your remote FTP server, for example `backup.yourdomain.com` or `203.0.113.10`.
- **Directory for backup files storage**: the path on the remote server where backups are written, for example `/backups/plesk/`. The FTP account must have write permission to this directory. If you leave it blank, backups are placed in the FTP user's home directory.
- **FTP username (required)**: the login for the FTP account on your remote server.
- **FTP password**: the password for that FTP account.
- **Use passive mode**: enable this if the remote server or an intervening firewall requires passive FTP. Servers behind NAT usually do, so if the connection test times out, this is the first setting to try.
- **Use FTPS**: enable this to encrypt the connection with TLS. Plain FTP sends the username, password, and backup data in clear text, so use FTPS whenever the remote server supports it.
Fields marked as required cannot be left empty. After entering your details, click **OK**. Plesk tests the connection immediately and reports an error if the host is unreachable or the credentials are rejected, so you will know straight away whether the settings are correct.

## Creating and scheduling backups to remote storage
1. In the Backup Manager, click **Back Up** to run a backup now, or **Schedule** to set up recurring backups.
2. In the **Store in** section, select **FTP storage** instead of server storage.
3. Choose what to include (configuration and content, or configuration only). For scheduled backups, set the frequency, the time of day, and how many backups to keep before older ones are pruned.
4. Click **OK** to run the backup or save the schedule.

## Restoring from FTP(S) backups
1. Open **Backup Manager**.
2. Set the storage selector to **FTP storage** so that the remote backups are listed.
3. Select the backup you want to restore and click **Restore**.
4. Choose whether to restore everything or only specific objects, then confirm.
Plesk needs to reach the remote server during a restore, so the FTP(S) storage settings must still be valid and the server reachable at that moment.
## Troubleshooting
- **The connection test fails when you click OK**: double-check the hostname or IP address, username, and password, confirm the remote FTP service is running and reachable, and enable **Use passive mode**.
- **The backup runs but nothing appears on the remote server**: the FTP account most likely lacks write permission to the target directory, or the directory path does not exist. Create the path first and confirm the account can write to it.
- **FTPS fails but plain FTP works**: the remote server may present a self-signed or mismatched TLS certificate, or may not support explicit FTPS. Confirm FTPS is enabled and correctly configured on the remote server.
- **Backups are slow to complete**: transferring full backups over FTP can be slow across long distances. Schedule them for off-peak hours and keep storage in check by lowering the number of backups to retain.
Noiz hosting plans include Plesk backup support. If you would like help configuring or verifying remote FTP(S) backups for your subscription, contact the Noiz support team and they will assist.
## Related articles
- [How to configure local backups in Plesk for a subscription](/plesk/how-to-configure-local-backups-in-plesk-for-a-subscription/)
- [How to configure remote backups in Plesk using Dropbox storage](/plesk/how-to-configure-remote-backups-in-plesk-using-dropbox-storage/)
- [How to configure remote backups in Plesk using SFTP storage](/plesk/how-to-configure-remote-backups-in-plesk-using-sftp-storage/)
# How to Configure Remote Backups in Plesk Using SFTP Storage
Source: https://docs.noiz.ie/plesk/how-to-configure-remote-backups-in-plesk-using-sftp-storage/
SFTP (SSH File Transfer Protocol) lets you store your Plesk backups on your own remote server over an encrypted connection. Unlike plain FTP, SFTP encrypts both the login and the file transfer, so your credentials and backup data never travel in clear text. This guide shows you how to configure SFTP storage for a subscription, send backups to it, and restore from it. It is written for Noiz Plesk hosting, where your subscription lives on a shared, managed Plesk server.
The key thing to know before you start: SFTP storage is not part of core Plesk. It is added by the **SFTP Backup** extension, which the server administrator installs once for the whole server. On Noiz managed Plesk the extension is provided for you, so you only need to supply the details of your own remote SFTP server and Plesk writes backups to it.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** and the SFTP Backup extension **2.2.2** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk SFTP Backup extension](https://www.plesk.com/extensions/sftp-backup/) (features, requirements and version)
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (backing up and restoring your subscription)
## Prerequisites
- Access to your subscription in Plesk (the **Websites & Domains** area) on your Noiz hosting account.
- Your own remote server running an SSH/SFTP service that is reachable from the internet.
- The remote server's hostname or IP address, an SFTP username and password with write access, and the directory path where backups should be written.
- The **SFTP Backup** extension available on the server. On Noiz managed Plesk this is already in place. If **SFTP** is missing from **Remote Storage Settings**, contact Noiz support rather than trying to install extensions yourself, as extension installation is a server-administrator task.
If you only need backups kept on the hosting server itself, see [How to Configure Local Backups in Plesk for a Subscription](/plesk/how-to-configure-local-backups-in-plesk-for-a-subscription/) instead.
## Accessing SFTP storage settings
1. Log in to Plesk.
2. Go to **Websites & Domains** and open **Backup & Restore** (sometimes shown as the Backup Manager) for your subscription.
3. In the Backup Manager, click **Remote Storage Settings**.
4. In the list of storage types, select **SFTP** (labelled **SFTP Backup** on some builds).

## Configuring SFTP storage
Complete the fields as follows:
- **SFTP server hostname or IP address (required)**: the address of your remote SFTP server, for example `backup.yourdomain.com` or `203.0.113.10` (replace these with your own).
- **Directory for backup files storage**: the path on the remote server where backups are written, for example `/backups/plesk/`. The SFTP account must have write permission to this directory, and the path must already exist. If you leave it blank, backups are placed in the SFTP user's home directory.
- **SFTP username (required)**: the login for the SFTP account on your remote server.
- **SFTP password**: the password for that SFTP account. Whether SSH key authentication is offered as an alternative depends on your Plesk build and the extension version, but password authentication is always available. Either way, SFTP encrypts the whole session, so the credentials are never sent in clear text.
Fields marked as required cannot be left empty. After entering your details, click **OK**. Plesk tests the connection immediately and reports an error if the host is unreachable or the credentials are rejected, so you will know straight away whether the settings are correct.
## Creating and scheduling backups to SFTP storage
1. In the Backup Manager, click **Back Up** to run a backup now, or **Schedule** to set up recurring backups.
2. In the **Store in** section, select **SFTP storage** instead of server storage.
3. Choose what to include (configuration and content, or configuration only) and whether the backup is **Full** or **Incremental**. For scheduled backups, set the frequency, the time of day, and how many backups to keep before older ones are pruned.
4. Click **OK** to run the backup or save the schedule.
Note that **scheduled** backups to remote storage such as SFTP depend on the extension's paid capability. On-demand backups to SFTP work without it. If **SFTP storage** does not appear as a destination when scheduling, that capability is not enabled for your plan; contact Noiz support to discuss options.

## Restoring from SFTP backups
1. Open the **Backup Manager** for the subscription.
2. Set the storage selector to **SFTP storage** so that the remote backups are listed.
3. Select the backup you want to restore and click **Restore**.
4. Choose whether to restore everything or only specific objects (for example, a single mailbox or database), then confirm.
Plesk needs to reach the remote server during a restore, so the SFTP storage settings must still be valid and the server reachable at that moment. Restoring overwrites current data with the contents of the backup, so restore to the right subscription and be sure you have chosen the correct backup point.
## Troubleshooting
- **The connection test fails when you click OK**: double-check the hostname or IP address, username, and password, and confirm the remote SSH/SFTP service is running and reachable. If the remote server or an intervening firewall blocks unknown addresses, allow the Noiz Plesk server's IP so it can connect.
- **The backup runs but nothing appears on the remote server**: the SFTP account most likely lacks write permission to the target directory, or the directory path does not exist. Create the path first and confirm the account can write to it.
- **SFTP storage is missing from Remote Storage Settings**: the SFTP Backup extension is not enabled on the server. Contact Noiz support.
- **SFTP does not appear when scheduling**: scheduled remote backups require the extension's paid capability. On-demand backups still work; contact Noiz support about scheduled remote backups.
- **Backups are slow to complete**: transferring full backups over SFTP can be slow across long distances. Schedule them for off-peak hours and keep storage in check by lowering the number of backups to retain.
Noiz hosting plans include Plesk backup support. If you would like help configuring or verifying remote SFTP backups for your subscription, contact the Noiz support team and they will assist.
## Related articles
- [How to Configure Local Backups in Plesk for a Subscription](/plesk/how-to-configure-local-backups-in-plesk-for-a-subscription/)
- [How to Configure Remote Backups in Plesk Using FTP(S) Storage](/plesk/how-to-configure-remote-backups-in-plesk-using-ftps-storage/)
- [How to Configure Remote Backups in Plesk Using Dropbox Storage](/plesk/how-to-configure-remote-backups-in-plesk-using-dropbox-storage/)
# How to Create Files and Directories in the Plesk File Manager
Source: https://docs.noiz.ie/plesk/how-to-create-files-and-directories-in-the-plesk-file-manager/
This guide shows you how to create a new directory (folder) and a new file inside the **File Manager** in Plesk. You can use these steps to organise your website content, add a fresh page, or drop in a configuration file such as `.htaccess` without needing an FTP client or SSH access.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide: Website Content (File Manager)](https://docs.plesk.com/en-US/obsidian/customer-guide/websites-and-domains/website-content.65173/)
## Prerequisites
- A Noiz hosting account with Plesk access.
- At least one domain or subscription added to your Plesk account.
## How to Create a Directory in the Plesk File Manager
1. Log in to your Plesk account.
2. Click **Files** in the sidebar menu. 
3. If your account holds more than one domain, click the domain you want to work on. 
4. Under **File Manager**, open the directory in which the new folder should live. For website content this is usually **httpdocs**, which is the document root that Plesk serves to visitors. Open a different directory first if you want the new folder created somewhere else. 
5. Click the **+ (plus)** icon and choose **Create Directory**. 
6. Type a directory name, for example `my-directory`, in the input box, then confirm with **OK**. The new folder appears inside whichever directory you had open in step 4. 
## How to Create a File in the Plesk File Manager
1. Open the directory that should contain the file, then click the **+ (plus)** icon and choose **Create File**. 
2. Type the file name, for example `home.html`, in the input box, then confirm with **OK**. To edit the file straight away, tick **Use HTML editor** (or the code editor) before you confirm, or select the file afterwards and choose **Edit**.
## Useful to Know
- **Web root:** anything you place directly in **httpdocs** is publicly reachable. A file created as `httpdocs/home.html` is served at `yourdomain.com/home.html` (replace `yourdomain.com` with your own domain).
- **Nested paths:** the File Manager creates the folder or file inside the directory you currently have open, so open the target folder before you click the plus icon.
- **Hidden files:** names that begin with a dot, such as `.htaccess`, are hidden by default. If you cannot see a file you created, enable **Show Hidden Files** from the settings toggle in the File Manager toolbar.
- **Naming:** avoid spaces and special characters in file and folder names to keep URLs and scripts predictable; use hyphens instead, for example `my-page.html`.
## Troubleshooting
**The Create Directory or Create File option is greyed out:** you have not selected a writable directory. Open **httpdocs** (or another folder you own) first, then click the plus icon.
**The new file or folder does not appear:** it was likely created inside a different directory than you expected. Check the breadcrumb path at the top of the File Manager, and enable **Show Hidden Files** if the name starts with a dot.
If you need a hand creating or editing content in your Plesk File Manager, the Noiz support team is available. Open a ticket from your Noiz client area and the team will assist.
# How to Create Scheduled Tasks in Plesk
Source: https://docs.noiz.ie/plesk/how-to-create-scheduled-tasks-in-plesk/
Scheduled Tasks in Plesk are the panel's front end for cron: they run a command, fetch a URL, or execute a PHP script automatically on a schedule you set. Follow this guide to create one on your Noiz Plesk hosting, whether you need a nightly database backup, a Laravel scheduler tick, a WordPress `wp-cron` replacement, or any recurring maintenance job.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Customer Guide: Scheduled Tasks](https://docs.plesk.com/en-US/obsidian/customer-guide/website-management/scheduled-tasks.74605/)
- [Plesk Customer Guide: Task Scheduling (crontab) Format](https://docs.plesk.com/en-US/obsidian/customer-guide/website-management/scheduled-tasks/task-scheduling-format.76870/)
## Prerequisites
- An active Noiz hosting subscription on a Plesk server, with login access to the Plesk panel.
- The exact command, URL, or script path you want to run, and how often it should run.
## Open Scheduled Tasks
**1.** Log in to your Plesk account.
**2.** Go to **Websites & Domains** and click **Scheduled Tasks**. On some layouts this sits under a **Dev Tools** or additional tools group, so click **Show More** if you do not see it straight away. You can also reach it from the sidebar menu.

**3.** On the **Scheduled Tasks** page, click **Add Task**.

## Configure the Task
**4.** Enter the task details:
- **Webspace:** If your subscription hosts more than one domain, choose the domain the task should run under from the drop-down.
- **Task type:** Choose one of the following.
- **Run a command** for a shell command or script (for example a backup script or a PHP CLI call).
- **Fetch a URL** to have Plesk request a URL on a schedule, which is the usual way to trigger a web-based cron endpoint.
- **Run a PHP script** to execute a `.php` file with the PHP version selected for the domain, no interpreter path needed.
- **Command / Script path:** Enter the value for the type you picked. For a command, use the full absolute path to the binary and script, for example `/usr/bin/php /var/www/vhosts/yourdomain.com/httpdocs/artisan schedule:run`. Relative paths and bare command names often fail because cron runs with a minimal environment.
- **Run:** Choose how often the task runs. The simple options (**Minutely**, **Hourly**, **Daily**, **Weekly**, **Monthly**) fill in the schedule for you. Choose **Cron style** if you need a specific pattern, then enter the five crontab fields (minute, hour, day of month, month, day of week), for example `*/15 * * * *` to run every 15 minutes.
- **Description:** A short note so you can recognise the task later.
- **Notify:** Leave on **Errors only** so you are emailed when a run fails but not on every successful run. Change to **Always** only while testing, or to **Do not notify** for noisy tasks.

**5.** Click **OK**.
## Verify the Task Runs
The task now appears in the Scheduled Tasks list and will run on the schedule you set. To confirm it works without waiting, select it and click **Run Now**, then check for the expected result (a new backup file, an updated database row, an email if you set **Notify** to **Always**).
## Troubleshooting
**The task runs but nothing happens:** Check the command path is absolute and correct. Cron does not use your interactive shell's `PATH`, so `php artisan ...` may need to be written as `/usr/bin/php /full/path/to/artisan ...`.
**Permission denied or wrong PHP version:** Use the **Run a PHP script** task type where possible, as it runs the script with the same PHP version and handler configured for the domain, avoiding version mismatches.
**You do not see the Scheduled Tasks option:** The feature can be disabled at the plan level. If it is missing on your subscription, contact Noiz support and it can be enabled for you.
If you would like Noiz to set up or troubleshoot a scheduled task for you, open a support ticket from your Noiz client area and the team will assist.
# How to Create a Database in Plesk
Source: https://docs.noiz.ie/plesk/how-to-create-a-database-in-plesk/
This guide shows you how to create a MySQL/MariaDB database in Plesk on your Noiz hosting account. Databases store the content and settings for applications such as WordPress, Joomla, and most other content management systems, so you will usually create one before installing or connecting an app.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Customer Guide: Databases](https://docs.plesk.com/en-US/obsidian/customer-guide/websites-and-domains/databases.59397/)
## Prerequisites
- A Noiz hosting subscription with at least one website (domain) already added in Plesk.
- Access to your Plesk account.
## Create the Database
**1.** Log in to your Plesk account.
**2.** Click on **Databases** from the sidebar menu.

**3.** Click on **Add Database**.

**4.** Under **Add a Database**, fill in the following details:
- **Database name:** A short, meaningful name, such as `blog`. Plesk usually prefixes the name automatically to keep it unique on the server.
- **Related site:** Choose the appropriate website from the drop-down menu. This links the database to the correct subscription.
- **Users:** Uncheck **Create a database user**, then confirm with **OK**.

A success message is displayed, confirming that your database has been created.
## Add a Database User
The steps above create an empty database only. Before an application can read from or write to it, the database needs a user account with a username and password. That is why you unchecked **Create a database user** here: it keeps user creation as a separate, deliberate step so you control the credentials your application will use.
To add a user to your new database, follow [How to Create a New Database User in Plesk](/plesk/how-to-create-a-new-database-user-in-plesk/).
## Troubleshooting
**The Related site drop-down is empty**: You need at least one website added to your subscription before you can create a database. Add the domain in Plesk first, then return to this step.
**You cannot see the Databases option**: Confirm you are logged in to the correct subscription. If your hosting plan does not show a Databases section, contact Noiz support to check that database provisioning is enabled on your plan.
If you get stuck at any point, the Noiz support team is happy to help. On managed plans, Noiz can create and configure the database for you.
# How to Create a New Database User in Plesk
Source: https://docs.noiz.ie/plesk/how-to-create-a-new-database-user-in-plesk/
This guide shows you how to create a database user in Plesk and attach it to one of your databases. A database user is the account your website or application uses to read from and write to its MySQL or MariaDB database, so you will normally create one whenever you set up a new site, content management system, or app that stores its own data.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/). See the Databases section for the full reference on managing databases and database users.
## Prerequisites
- An active Noiz hosting plan with access to Plesk.
- At least one database already created for the user to belong to. If you have not created one yet, add it first from the same **Databases** page.
## Create the Database User
1. Log in to your Plesk account.
2. Click **Databases** in the sidebar menu. 
3. Click **User Management** in the right-hand sidebar. 
4. Under **Database Users**, click **Add Database User**. 
5. Under **Adding Database User**, fill in the following details: 
- **Database user name:** Enter a username, for example `blog`.
- **Password:** Enter a password, or click **Generate** to have Plesk create a strong one for you. Click **Show** and copy the password somewhere safe before you leave the page, as Plesk will not show it to you again.
- **Database:** Choose the database this user should belong to from the drop-down menu.
- **Access control:** Choose the option that suits how the database will be reached. See [Choosing the right access control](#access-control) below if you are unsure.
6. Confirm with **OK**. Your new database user is created and ready to use.
## Choosing the Right Access Control
Plesk lets you control where the user is allowed to connect from and what it is allowed to do. Two settings matter here.
- **Where it can connect from.** Most websites and CMS applications (WordPress, Joomla, and similar) run on the same server as the database, so **Allow local connections only** is the correct and safest choice. Only allow remote connections when an external service genuinely needs to reach the database over the network, and even then restrict it to the specific host that needs access.
- **What it can do.** A normal website needs full read and write access to its own database. If the account is only used by a reporting or backup tool that should never change data, grant a read-only role instead so a compromised or misconfigured tool cannot alter or delete your data.
In Plesk, each database user is linked to a specific database. If your application uses more than one database, create a user for each one. When you place these credentials into your application's configuration, for example `wp-config.php` for WordPress, the database host is normally `localhost` because the application and the database live on the same server.
## Troubleshooting
**Symptom:** The application reports `Access denied for user`. **Fix:** Re-check the username and password character for character. If you are unsure of the password, edit the user in Plesk, generate and copy a fresh one, and update it in your application's configuration. Confirm the user is attached to the same database the application is trying to open.
**Symptom:** An external service cannot connect. **Fix:** The user was most likely created with local connections only. Edit the user, allow remote connections for the host that needs access, and use the server hostname rather than `localhost` in that service's connection settings.
## Need a Hand?
If you are on a managed Noiz plan and would prefer Noiz to create the database and user for you, open a support ticket from your Noiz client area and the team will set it up.
# How to Create an Email Address in Plesk
Source: https://docs.noiz.ie/plesk/how-to-create-an-email-address-in-plesk/
By following this quick tutorial, you will learn how to create an email address in Plesk on your Noiz hosting subscription.
**Note:** An email address is sometimes referred to as an email account, a mailbox, or a domain mailbox. These terms all describe the same thing: a place to send and receive mail on your domain.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Customer Guide (Obsidian)](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Watch the Video: How to Create an Email Address in Plesk
## Steps for Creating an Email Address for Your Domain
**Step 1:** Log in to the Plesk hosting control panel for the subscription you have with Noiz.
**Note:** If you are not sure how to do this, follow the instructions in this tutorial: [How to Log In to Plesk](/plesk/how-to-log-in-to-plesk/).
**Step 2:** Once logged in, click the **'Mail'** tab in the sidebar menu of the Plesk control panel.

**Step 3:** In the main content area, click the blue **'Create Email Address'** button.

**Step 4:** On the **'Create Email Address'** page, select the **'General'** tab and fill in the following fields:
- **Email address:** Enter the user part of your new email address (the part before the @ symbol). If you have multiple domains under your subscription, be sure to choose the correct domain from the drop-down menu to the right of the @ symbol.
- **Password:** Enter a **strong** password, or click the **'Generate'** button to have one created for you. You can then click the **'Show'** button to reveal and copy the generated password for later use.
- **Confirm password:** Repeat the password used above, or paste the generated password from your clipboard.
- **Mailbox:** Choose a size for this mailbox. The **'Default size'** is set to 'Unlimited'. You can also set a specific limit by selecting **'Another size'** and entering an amount in KB, MB, GB or TB.
**Note:** The mailbox size set here defines only the maximum storage this single mailbox is allowed to use. The total storage available across all services on your domain is governed by your subscription plan, so the sum of all your mailboxes cannot exceed your plan's allowance.

**Step 5:** Finally, click the **'OK'** button to create the mailbox.
## Conclusion
That's it. You can now start sending and receiving email using this new address. There are two common ways to do so:
- Use the webmail interface for the mailbox in your web browser, or
- Configure a mail client such as **Thunderbird** (or Outlook) using the new **email address**, the **password** you set above, and the mail server settings for your domain.
Remember to search the Noiz knowledgebase for other helpful tutorials, including guides on accessing webmail and setting up your mail client.
# How to Create an FTP Account in Plesk
Source: https://docs.noiz.ie/plesk/how-to-create-an-ftp-account-in-plesk/
You can already reach your files over FTP with your main Plesk subscription login, which gives full access to the subscription's home directory. When you instead want to give someone access to only one website, or only a single folder, create a separate FTP account. Each FTP account is locked to the home directory you assign, so the user cannot browse or change anything outside it. This is the safe way to hand a developer, designer or client limited upload access without sharing your main Plesk login.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation.
## Prerequisites
- A hosting subscription on a Noiz Plesk server, with login access to the Plesk control panel.
- The website (domain) you want to grant access to, already added to your subscription.
- The folder you want the account restricted to, for example the whole site or a single subfolder.
## Create the FTP Account
1. Log in to your Plesk account.
2. Click **Websites & Domains** in the sidebar menu. 
3. Under the list of **Domain names**, click the appropriate domain. 
4. Under **Files & Databases**, click **FTP Access**. 
5. Click **Add an FTP Account**. 
6. Fill in the account details: 
- **FTP account name:** a username for the account, for example `john`. This is the name the user logs in with.
- **Home directory:** click the folder icon and choose the directory this account may access. Point it at the whole site (for example `httpdocs`) or at a single subfolder. The account cannot move above the folder you choose.
- **Password:** type a strong password, or click **Generate** to create one. Click **Show** to reveal and copy it.
7. Confirm with **OK**.
## Connect With the New Account
Use these settings in any FTP client, such as FileZilla, to connect with the account you just created:
- **Host:** your domain name, such as `ftp.yourdomain.com`, or the server's IP address. Replace `yourdomain.com` with your own domain.
- **Username:** the FTP account name you set, for example `john`.
- **Password:** the password you set for the account.
- **Port:** `21` (the default FTP port).
### Use an Encrypted Connection
Plain FTP sends your username and password across the internet in clear text. Where your FTP client offers it, choose **FTP over TLS (FTPS, explicit encryption)** so both the login and the file transfer are encrypted. In FileZilla, set the encryption to **Require explicit FTP over TLS**. This still uses port `21` but protects your credentials.
## Troubleshooting
**Login fails or "530 Login incorrect":** re-check the username and password, and confirm you are connecting to the correct host. Passwords are case sensitive.
**The account cannot see other websites or folders:** this is expected. An FTP account is restricted to its home directory and cannot browse outside it. Create a separate account, or widen the home directory, if broader access is needed.
**Connection times out:** confirm the host and port are correct and that no local firewall is blocking outbound FTP. Switching the client to passive mode resolves most transfer stalls behind home or office routers.
If you are on a managed Noiz plan and would prefer the Noiz team to set up FTP access for you, contact Noiz support and the team will take care of it.
# How to Delete a Database in Plesk
Source: https://docs.noiz.ie/plesk/how-to-delete-a-database-in-plesk/
This guide shows you how to permanently delete a MySQL or MariaDB database from your hosting account using the Plesk control panel. It is written for the Plesk-based Noiz hosting platform, and takes only a few clicks.
**Warning:** deleting a database is permanent and cannot be undone. Every table and record it holds is removed straight away, and there is no recycle bin to restore from. If the database is used by a live website or application (for example a WordPress, Joomla or custom PHP site), that site will stop working the moment the database is gone. Export a backup first if there is any chance you will need the data again, and confirm that nothing still depends on the database before you continue.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (see the Databases section for full details on managing databases and database users)
## Before You Start
- Make sure you are removing the correct database. Note down its exact name, because two databases can look almost identical apart from a suffix.
- If you might need the data again, export a backup first (for example with the **Export Dump** option in phpMyAdmin, or via your account backups) before deleting anything.
- Update any website or application that connects to the database, so it no longer points at the database you are about to remove.
## Delete a Database in Plesk
### 1. Log in to Plesk
Log in to your Plesk account. If you are unsure of your login URL or details, they are shown in your Noiz welcome email or client area.
### 2. Open the Databases page
Click **Databases** in the sidebar menu.

### 3. Select the database to remove
From the **list of databases**, find and select the database you want to delete. Double-check the name against the one you noted earlier before going any further.

### 4. Remove the database
Click **Remove Database**. A confirmation box appears; confirm with **Yes**. The database, along with all of its tables and data, is then removed.

Your database is now deleted.
## What Happens to the Database User
Removing a database does not always remove the database user that was linked to it. If you created a dedicated user for this database and no longer need it, delete that user separately from the **Databases** page (each database lists its users, and each user has its own **Remove** option). Leaving unused database users behind is a small tidiness and security issue rather than a fault, but it is good practice to clear them out.
## Troubleshooting
**Your website shows a database connection error after deletion**: the site is still trying to reach the database you removed. Restore the database from a backup, or update the site so it connects to the correct, existing database instead.
**The database will not delete or the option is greyed out**: an active process or connection may be holding it open. Wait a moment and try again, and make sure no application is actively using it.
If you are on a managed Noiz plan and would rather not do this yourself, or you delete a database by mistake, contact Noiz support and the team will help you remove it safely or restore from the most recent backup.
# How to Edit a File in the Plesk File Manager
Source: https://docs.noiz.ie/plesk/how-to-edit-a-file-in-the-plesk-file-manager/
The Plesk File Manager lets you view and edit the files inside your hosting subscription directly in the browser, without needing an FTP client or SSH access. This guide shows you how to open a file for editing, make your changes, and save them on Noiz hosting.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Customer Guide: Managing Files with File Manager](https://docs.plesk.com/en-US/obsidian/customer-guide/website-and-domains/file-manager.76013/)
## Prerequisites
- Access to your Plesk control panel. If you are not sure how to log in, see [How to Log in to Plesk](/plesk/how-to-log-in-to-plesk/).
- An existing file in your subscription that you want to edit.
## Edit a File in the Plesk File Manager
**Step 1:** Log in to your Plesk account.
**Step 2:** Click **Files** in the sidebar menu.

**Step 3:** Under **File Manager**, open the **httpdocs** directory. This is the document root for your main website, so the files that make up your site live here.

**Step 4:** Hover over the file you want to change so its row is highlighted, then click the **menu icon**  at the end of the row to open the context menu. Choose **Edit in Code Editor** for source-accurate editing of code, or **Edit in HTML Editor** for a visual editor.

**Step 5:** Make your changes, then save by clicking **OK**. The saved file goes live immediately, so there is no separate upload or publish step.

## Which Editor Should You Use?
Plesk offers more than one editor from the context menu, and the choice matters:
- **Code Editor** shows the raw source with syntax highlighting and line numbers. Use it for HTML, CSS, PHP, JavaScript, configuration files (such as `.htaccess` or `wp-config.php`), and anything where the exact characters matter.
- **HTML Editor** is a visual (WYSIWYG) editor. It is convenient for simple text and formatting changes, but it can rewrite or reformat your markup when it saves. Avoid it for files that contain code you have hand-written, or your layout may change unexpectedly.
- **Text Editor** is a plain, no-frills option for quick edits to plain-text files.
## Before You Save: A Few Gotchas
- **Changes are live instantly.** Because you are editing the file in place on the server, saving overwrites the running copy at once. For an important file, make a copy first: select the file, choose **Copy** from the context menu, and keep the copy as a quick rollback.
- **Permissions.** If saving fails, the file or its parent directory may not be writable. Check the file's permissions in the File Manager and adjust them if needed.
- **Encoding.** The editors save in UTF-8. If you paste content from another program and see odd characters, that is usually a character-encoding mismatch in the source you copied.
## Need a Hand?
If you would rather not edit production files yourself, or a change has broken your site, Noiz support can help. Managed hosting customers can ask the Noiz team to make the edit or restore the file for you.
# How to Edit or Delete Scheduled Tasks in Plesk
Source: https://docs.noiz.ie/plesk/how-to-edit-or-delete-scheduled-tasks-in-plesk/
A Scheduled Task (also called a cron job) runs a command or script automatically on a schedule you set. As your needs change, you will sometimes want to adjust an existing task, for example to correct its command, change how often it runs, or switch the email address that receives its output. Other times you will want to remove a task you no longer need. This guide shows you how to edit and how to delete Scheduled Tasks from inside the Plesk control panel on your Noiz hosting. If you need to create a new task instead, see the guide on adding Scheduled Tasks.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Before you start
- You need your Plesk login details for your Noiz hosting account.
- You need at least one Scheduled Task already set up. If the list is empty, there is nothing to edit or delete yet.
- Editing or removing a task changes what runs automatically on your hosting, so make sure you know what a task does before you change or delete it.
## How to edit a Scheduled Task
**1.** Log in to your Plesk account.
**2.** Click the **pull-out (arrow) icon** in the right sidebar and choose **Scheduled Tasks**.

**3.** In the **Command** list, find the task you want to change and click it.

**4.** Make your changes, then confirm with **OK**. You can adjust the command or script that runs, the schedule (minute, hour, day of the month, month, and day of the week), and where the task sends its notification.

Your changes take effect from the task's next scheduled run; a run already in progress is not affected. If you want to check a change straight away without waiting, open the task and use **Run Now**.
**Tip:** if you only want to pause a task for a while rather than change it, you do not have to delete it. Open the task and clear its **enabled** (switched-on) state. The task stays in your list, keeps its command and schedule, and simply does not run until you switch it back on.
## How to delete a Scheduled Task
**1.** In the **Command** list, tick the box next to each task you want to remove, then click **Remove**.

**2.** A confirmation box appears. Click **Yes**, and the selected task is removed.
Removing a task is immediate and cannot be undone. The task's command and schedule are deleted, so if you think you might need it again, disable it (see the tip above) instead of removing it, or note down its command and schedule first so you can recreate it later.
## Need a hand?
If you cannot reach your Scheduled Tasks, a task will not save, or a job is not running as expected, contact the Noiz support team through the client area and they will help you get it sorted.
# How to Exclude Specific Files or Folders From a Plesk Backup
Source: https://docs.noiz.ie/plesk/how-to-exclude-specific-files-or-folders-from-a-plesk-backup/
Plesk lets you leave chosen files, folders, or file types out of a backup so the archive stays smaller and quicker to create. This is handy for excluding large media libraries, log files, or cache directories you do not need to protect. This guide shows you how to do that from the Plesk control panel on your Noiz hosting.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/). See the *Backing Up and Restoration* section for the full backup and restore reference.
## Prerequisites
- Access to your Plesk control panel for the subscription you want to back up.
- The path of the file, folder, or file type you intend to exclude.
## Exclude Files or Folders From a Plesk Backup
1. Log in to your Plesk account.
2. Go to **Websites & Domains** > click the **pull-down icon** > choose **Backup & Restore**. 
3. Under **Backup Manager**, click **Back Up**. 
4. Choose the backup type. 
5. Tick **Exclude specific files from the backup**. 
Enter one path per line. Paths are relative to the subscription's home directory. For example:
To exclude a single file:
```
/httpdocs/directory/filename.jpg
```
To exclude a whole directory:
```
/httpdocs/images
```
To exclude only a specific file type, such as PNG images:
```
/httpdocs/images/*.png
```
6. Confirm with **OK**. The backup starts generating in the background, so you can navigate away from the page while it runs.
## Good to Know
- Exclusions you set here apply to **this backup only**. To keep files out of automatic backups, set the same **Exclude specific files from the backup** option inside your **scheduled backup** settings.
- The wildcard `*` matches file names within a directory, so `*.log` or `*.png` is a quick way to skip a whole file type.
- Excluding large, easily replaced content (media libraries, caches, logs) keeps your backup archives smaller and faster to create and restore.
If you are on a managed Noiz plan and would like a hand configuring backups or exclusions, contact Noiz support through your client area and the team will assist.
# How to Export a Database Backup in Plesk
Source: https://docs.noiz.ie/plesk/how-to-export-a-database-backup-in-plesk/
Plesk can generate a full backup (a "dump") of a single database and download it straight to your computer. A dump is a plain-text `.sql` file that contains both the structure (tables, indexes) and the data of the database, so it can be used to restore the database later or to move it to another server. This guide shows you how to export and download a database dump from Plesk on Noiz hosting.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (see **Websites & Domains โ Databases** for exporting and importing database dumps).
## Prerequisites
- Access to your Plesk account on Noiz hosting.
- The database you want to back up already exists in Plesk.
- Enough free space on your Plesk subscription for the dump file, which is created on the server before it is downloaded.
## Export and Download the Database Dump
**1.** Log in to your Plesk account.
**2.** Open **Databases** from the left sidebar menu. Depending on your Plesk view, you may find it under **Websites & Domains** instead.

**3.** In the **list of databases**, find the database you want to back up.

**4.** Select the database, then click **Export Dump**. A dialogue box opens.

**5.** Choose the server directory where the dump will be stored. Tick **Automatically download the dump after creation** so that the file is sent to your browser once it is ready, then confirm with **OK**.

Once the dump has been generated, your browser prompts you to download it. Save the `.sql` file somewhere safe on your computer.
## Good to Know
- **One database per dump.** Export Dump backs up a single database at a time. Repeat the steps above for each database you need.
- **The dump is stored on the server first.** Even with the automatic download ticked, Plesk writes the file into the chosen server directory before sending it to your browser. On a large database this uses temporary disk space, so make sure your subscription has room. You can delete the server copy afterwards if you only need the local download.
- **Restoring is the reverse.** To bring a dump back in, use **Import Dump** in the same Databases screen and upload the `.sql` file. Importing into an existing database can overwrite its current data, so restore into an empty or freshly created database if you are unsure.
- **Prefer a browser tool instead?** You can also export a database from **phpMyAdmin** (reachable via the database's management link in Plesk), which gives you finer control over which tables and formats are exported.
## Need a Hand?
If a dump fails to generate, downloads as an empty file, or you are not sure which database powers your site, Noiz support can help. Open a ticket from your [Noiz client area](https://www.noiz.co.za) and the team will assist with the export or take a backup on your behalf.
# How to Fix HTTP 413 'Request Entity Too Large' Upload Errors in Plesk
Source: https://docs.noiz.ie/plesk/how-to-fix-http-413-request-entity-too-large-upload-errors-in-plesk/
*Last reviewed: 27 July 2026, against Plesk Obsidian 18.0.x, nginx, and ModSecurity 2.9.x (Imunify360 ruleset).*
**Official documentation:**
- [Plesk: Upload of a big file fails: client intended to send too large body](https://support.plesk.com/hc/en-us/articles/12377537186711)
- [Plesk: Unable to upload a file when Imunify is present (ModSecurity request-body limit)](https://support.plesk.com/hc/en-us/articles/12377014188951)
- [ModSecurity v2 Reference Manual: SecRequestBodyLimit / SecRequestBodyNoFilesLimit](https://github.com/owasp-modsecurity/ModSecurity/wiki/Reference-Manual-(v2.x))
## Applies to
Any website on a Plesk server running nginx in front of Apache, where large file uploads (media, backups, recordings, documents) fail. It applies equally to PHP sites and to application sites such as Node.js, Python, or Ruby served through Phusion Passenger.
## Symptom
An upload fails and the browser or application reports:
```
413 Request Entity Too Large
```
The application may dress this up in its own wording ("the file is too large", "the server rejected this file"), but the underlying HTTP status is 413. The upload is being rejected by the server before it reaches the application.
## Why this happens
On a Plesk site with nginx in front, a 413 can be produced at two independent layers, each with its own limit. Raising one does not raise the other, which is why an upload can still fail after the first limit is increased. Read the logs, identify which layer is rejecting the request, then raise that layer.
| Log signature | Layer | Go to |
| --- | --- | --- |
| `client intended to send too large body: N bytes` | nginx (reverse proxy, the front door) | Step 2 |
| `Request body (Content-Length) is larger than the configured limit (134217728)` | ModSecurity / Imunify360 WAF, total request body | Step 3 |
| `Request body no files data length is larger than the configured limit (1048576)` | ModSecurity / Imunify360 WAF, non-file request body | Step 3 |
## Step 1: Read the logs
Open **Domains > (domain) > Logs** in Plesk, or read the log files directly over SSH. The nginx rejection appears in the domain's proxy error log:
```
grep "too large body" /var/www/vhosts/system/*/logs/proxy_error_log 2>/dev/null | grep example.com | tail -20
```
ModSecurity rejections appear in the domain's Apache error log. The number in the message is the limit that was hit, in bytes. For example, 134217728 = 128 MB, which is the default `SecRequestBodyLimit`.
## Step 2: Raise the nginx limit
1. Go to **Domains > (domain) > Apache & nginx Settings**.
2. Set **Maximum allowed HTTP request body size** to a value comfortably above the largest upload you need to support (for example, 1 GB). This configures the nginx `client_max_body_size` directive and applies only to this domain.
3. Click **OK**. Plesk validates the configuration and reloads nginx automatically, so no manual restart is required.
## Step 3: Raise the ModSecurity limit (per domain)
If the log shows a ModSecurity rejection, the WAF is refusing the request body. On this platform the request-body limit ships at 128 MB (via the Imunify360 ruleset). It can be raised for a single domain without affecting any other site or the server default.
Go to **Domains > (domain) > Apache & nginx Settings** and add the following to **Additional directives for HTTPS** (uploads are almost always over TLS). Add the same block to **Additional directives for HTTP** as well, so it applies regardless of protocol:
```
SecRequestBodyLimit 1073741824
```
This overrides the server-wide 128 MB limit for this domain only. It is placed in the domain's own `` block (the only Apache context in which `SecRequestBodyLimit` is valid), and it survives Imunify360 ruleset updates because it lives in the subscription's configuration, not the server-level WAF config. The value shown is 1 GB in bytes (1073741824); set it to match the nginx limit from Step 2.
If, after raising `SecRequestBodyLimit`, the log then shows `Request body no files data length is larger than the configured limit (1048576)`, the application is sending the upload as a raw or base64-encoded body rather than a multipart file field. Add `SecRequestBodyNoFilesLimit` to the same block at the same value:
```
SecRequestBodyLimit 1073741824
SecRequestBodyNoFilesLimit 1073741824
```
Click **OK**. Plesk validates and reloads Apache automatically. If the configuration is accepted without an error, the change is live.
## Step 4: PHP sites: allow the upload through PHP as well
Skip this step for Node.js, Python, or other application sites, because there is no PHP in the request path, so PHP settings have no effect. For PHP sites, the limits above stop the 413, but PHP will still discard the upload body unless its own limits are raised. Go to **Domains > (domain) > PHP**, set `post_max_size` and `upload_max_filesize` to match or exceed the nginx value, and click **Apply**. Keep nginx, `post_max_size`, and `upload_max_filesize` aligned, because the lowest of the three wins.
## Step 5: Verify
Retry the upload. If it succeeds, the matter is resolved. If it still returns 413, re-read the log, because the signature will tell you which remaining layer is rejecting the request, and you return to the corresponding step above.
## Notes
- **The application has its own limit too.** Even with every server-side limit raised, the application (for example, a Node.js body parser or a PHP framework) may impose its own upload ceiling. If the logs show no server-side rejection but the upload still fails, the limit is in the application and must be raised there.
- **Shared and reseller subscriptions.** The ModSecurity directive requires the Additional Apache directives field, which is an administrator-controlled setting. On a shared or reseller subscription without that access, the change must be requested from Noiz. Sites with recurring large-upload requirements are better placed on a dedicated or standalone package where these limits can be tuned directly.
- **Large limits and server resources.** Raising these limits does not consume proportional memory, because ModSecurity streams large uploads to disk rather than buffering them in RAM. The cost is temporary disk space during inspection.
# How to Generate a Full Backup in Plesk
Source: https://docs.noiz.ie/plesk/how-to-generate-a-full-backup-in-plesk/
A full backup captures everything in your Plesk subscription in one archive: your website files, databases, mail, DNS records and the subscription configuration. This guide shows you how to generate a full backup in Plesk and download a copy to your own computer, so you always have a restore point you control.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable line). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (see the Backing Up and Restoration section)
## Prerequisites
- Access to your Plesk account for the subscription you want to back up.
- Enough free disk space on your account if you store the backup on the server (see the notes at the end).
## Generate a Full Backup in Plesk
1. Log in to your Plesk account.
2. Go to **Websites & Domains**, then under the domain you want to back up, open **Backup & Restore**. This opens the **Backup Manager**. If you do not see the option straight away, expand the domain's tools using its pull-down (chevron) arrow. 
3. In the Backup Manager, click **Back Up**. 
4. Set the backup **Type** to **Full**. For **Store in**, choose **Server storage** if you want to download the backup afterwards. Choose **FTP(S) storage** only if you have already configured a remote storage location and want the copy kept off the server. 
5. If you want to be told when the backup finishes, tick **When a backup task is completed, send a notification email to** and confirm the address. 
6. Confirm with **OK**. The backup starts generating in the background, so you can navigate away and carry on working. Larger accounts take longer to complete.
## Download Your Backup
1. Go to **Websites & Domains** > **Backup & Restore** to return to the Backup Manager.
2. In the backup list, click the **download** icon next to the backup you created. 
3. To secure the archive, tick **Use password protection** and set a password, then confirm with **OK**. This is recommended, because a full backup contains your databases and mail. 
4. Your browser prompts you to download the file. Save it somewhere safe on your computer.
## Good to Know
- A **Full** backup is a complete, standalone copy. An **Incremental** backup only records what changed since the last full backup and depends on it, so keep the full backup it was based on.
- Backups kept in **Server storage** use your account's disk allocation. Once you have downloaded a backup, remove the copies you no longer need from the Backup Manager to free space.
- **FTP(S) storage** keeps the archive off the server, which is safer for long-term retention, but you must configure the remote location under **Remote Storage Settings** before it can be selected.
- On managed Noiz hosting, Noiz also keeps its own server-level backups. Generating your own backup gives you a personal copy you can download, archive or restore from selectively.
## Troubleshooting
- **FTP(S) storage is greyed out or empty**: no remote repository has been set up yet. Add one under **Remote Storage Settings**, or use **Server storage** instead.
- **The backup fails or stops part way**: this is usually low disk space. Free up space (or remove old backups) and try again, or exclude very large content and back it up separately.
If you are on a managed Noiz hosting plan and need a hand creating, downloading or restoring a backup, open a support ticket from your Noiz client area and the team will assist.
# How to Log In to Plesk
Source: https://docs.noiz.ie/plesk/how-to-log-in-to-plesk/
Plesk is one of the most versatile and stable web hosting control panels available to shared hosting customers. It provides access to a comprehensive range of tools including a file manager, DNS editor, PHP settings, email account management, spam filters, and much more.
This tutorial outlines the different ways to access your Plesk control panel on Noiz hosting.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Customer Guide (Obsidian)](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Log in to Plesk via the Client Area (Recommended)
**Step 1:** Log in to the [Noiz Client Area](https://www.noiz.co.za/clientarea.php) using the 'Login' button at the top right of the website.
If you don't know your login details, use your billing email address. A [Password Reset](https://www.noiz.co.za/password/reset) option is available below the login form.

**Step 2:** From the Client Area Dashboard, click on the 'Services' tile, or select 'My Services' from the Services dropdown menu.

**Step 3:** Find your website hosting plan from the list and click anywhere in the tile area (not on the domain name itself, as that will open the website).

**Step 4:** Click the 'Log in to Plesk' button in the 'Actions' section of the left-hand sidebar.
You can also access common Plesk features directly from the 'Quick Shortcuts' section on the same page.

**Done.** A new window will open and you'll be logged into Plesk for your selected subscription. Consider selecting the 'Take the tour' option to familiarise yourself with the interface.
## Log in to Plesk Directly (Advanced)
Every shared hosting subscription includes control panel access via a web browser. You can log in to Plesk directly using your domain name, IP address, or the server hostname.
Your Plesk login details (IP address, URL, and hostname) are sent to you by email when you sign up. If you can't find the email, contact Noiz support.
### Using Your Domain Name
**Step 1:** Open your web browser.
**Step 2:** Navigate to `https://yourdomain.com:8443/` (replace `yourdomain.com` with your actual domain). Plesk always listens on port `8443`, so the port number is required.
You may see a security warning stating "Potential Security Risk Ahead". This is expected. The SSL certificate is issued to the Plesk server hostname rather than to your domain, so the browser flags the name mismatch. Click 'Advanced', then 'Accept the Risk and Continue'.
**Step 3:** Enter your Plesk username (or email address) and password. These credentials were sent to you when you signed up. If you've forgotten them, use the 'Forgot your password?' link or contact Noiz support.

**Tip:** The SSL certificate is valid for the server hostname. Logging in via that hostname instead of your domain avoids the security warning altogether.
### Using Your IP Address
The process is identical to above, but use your hosting IP address instead:
`https://your_IP_address:8443/`
The login form will display the server hostname, which you can use for future logins to avoid SSL warnings.
Your IP address is included in your signup email, or you can contact Noiz support to obtain it.
## Summary
You can access Plesk in two ways: through the Client Area (recommended for most users), or directly via your browser using your domain, IP address, or server hostname.
Login details are sent to your admin email when you sign up. If you need assistance, contact Noiz support.
# How to Password-Protect a Backup in Plesk
Source: https://docs.noiz.ie/plesk/how-to-password-protect-a-backup-in-plesk/
Password protection encrypts a Plesk backup so that the sensitive data stored inside it, including your database user passwords and mail account credentials, cannot be read by anyone who obtains the backup file. This guide shows you how to turn password protection on for backups of your Noiz Plesk hosting account. In the Plesk interface this feature is labelled **Password Protection**; you may also see it referred to as backup encryption.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Documentation and Help Portal](https://docs.plesk.com/) (Obsidian, Customer Guide: Backing Up and Restoring Websites)
## Prerequisites
- A Noiz hosting account on Plesk, and your login details for the Plesk control panel.
- A password manager or another safe place to store the protection password. Noiz cannot recover it for you.
## Turn On Password Protection for Backups
### 1. Log in to Plesk
Sign in to your Plesk control panel with your account credentials.
### 2. Open Backup & Restore
Go to **Websites & Domains**. On the domain you want to back up, open the expand (pull-down) icon to show the full list of tools, then choose **Backup & Restore**.

### 3. Open Remote Storage Settings
In the Backup Manager, click **Remote Storage Settings**.

### 4. Edit the Password Protection setting
Find **Password Protection**. If it shows **Disabled** on the right, click **Change**.

### 5. Set a password and apply
Tick **Use password protection**, enter a password, and click **Apply**. From now on, new backups are encrypted with this password.

## Why This Matters, and the One Thing Not to Forget
Store the password somewhere safe, because you will need the exact same password to restore a protected backup. Noiz does not hold a copy of it and cannot reset it, so if it is lost the encrypted contents of that backup cannot be recovered.
The password protects more than the files themselves. It also protects the credentials Plesk stores inside the backup. If you restore a backup and either enter the wrong password or the backup was created without password protection, Plesk cannot decrypt the stored database credentials, so it restores your databases with newly generated random passwords instead. Any application that connects to those databases, such as a WordPress or other CMS configuration, would then need its connection password updated to match. Keeping the correct password to hand avoids this.
## Need a Hand?
If you are on a Noiz managed plan, or you are unsure about your backup and restore setup, contact Noiz support and the team will help you configure and verify it.
# How to Redirect a Subdomain to an External URL in Plesk
Source: https://docs.noiz.ie/plesk/how-to-redirect-a-subdomain-to-an-external-url-in-plesk/
This guide shows you how to redirect a subdomain to an external web address in Plesk on your Noiz hosting. Redirecting (also called *forwarding*) sends anyone who visits the subdomain straight to a different URL, which is useful when you want `shop.yourdomain.com` to point at a third-party store, a landing page, a social profile, or another site you run. The subdomain keeps no website of its own; it simply forwards every request to the destination you choose.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (see the **Websites & Domains** chapter for hosting types and forwarding).
## Prerequisites
- A Noiz hosting subscription that uses the **Plesk** control panel, with login access.
- The subdomain already created in Plesk under **Websites & Domains**. If it does not exist yet, add it first using **Add Subdomain**, then return here.
- The destination URL you want visitors to land on, for example `https://www.example.com/promo`.
## Redirect the Subdomain
1. Log in to your Plesk account.
2. Click **Websites & Domains** in the sidebar menu. 
3. In the list of domain names, find the row for your subdomain and click the  **Hosting Settings** icon in that row. 
4. Next to **Hosting Type** (shown beside **Website**), click **Change**. 
5. Set the following: 
- **Hosting type**: choose **Forwarding** from the drop-down menu.
- **Destination address**: enter the full URL you want the subdomain to redirect to, including `https://`.
- **Forwarding type**: choose the option that suits your needs (see the explanation below).
6. Click **OK**. Plesk warns you that changing the hosting type affects the subdomain; read the warning and confirm with **Yes**.
The change takes effect within moments. Visit the subdomain in a fresh browser tab to confirm it now forwards to the destination.
## Which Forwarding Type to Choose
Plesk offers three forwarding behaviours. The right choice depends on whether the move is permanent and whether you want the subdomain to stay visible in the address bar:
- **Moved permanently (301)**: the recommended default. It tells search engines the subdomain has permanently moved, so link authority and rankings transfer to the destination. The visitor's address bar shows the destination URL, and browsers cache the redirect.
- **Moved temporarily (302)**: use this only when the redirect is genuinely temporary, for example during a short campaign, after which you will point the subdomain elsewhere. Search engines keep the subdomain indexed rather than passing authority to the destination.
- **Frame forwarding**: the visitor's address bar keeps showing your subdomain while the destination loads inside a frame. It hides the real URL, but it weakens SEO, breaks bookmarking and, importantly, will not work for destinations that block being framed (many modern sites send an `X-Frame-Options` or `Content-Security-Policy` header that prevents it). Avoid it unless you have a specific reason.
## Troubleshooting
- **The subdomain still shows the old site or a directory listing**: your browser or a proxy has cached the previous response. Clear the cache or test in a private/incognito window. A **301** redirect in particular is cached aggressively by browsers.
- **The subdomain does not load at all**: confirm the subdomain's DNS resolves to your Noiz Plesk server. If you have only just created the subdomain, DNS may still be propagating, which can take up to a few hours.
- **Frame forwarding shows a blank page or a "refused to connect" error**: the destination site blocks being displayed in a frame. Switch the forwarding type to **Moved permanently (301)** instead.
- **The destination redirects back to your subdomain**: check that the destination address does not itself point back at the subdomain, which creates a redirect loop.
If the subdomain will not forward correctly after these checks, Noiz support can inspect the subscription and DNS for you. Open a ticket from your Noiz client area and include the subdomain name and the destination URL you are trying to redirect to.
# How to Remove a Database User in Plesk
Source: https://docs.noiz.ie/plesk/how-to-remove-a-database-user-in-plesk/
This guide shows you how to remove a database user from your hosting account in Plesk. A database user is the login (a username and password) that a website or application uses to connect to a MySQL or MariaDB database. Removing a user deletes only that login: the database and its data stay in place. Deleting the database itself is a separate action.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation.
## Before you remove a user
Removing a database user is immediate and cannot be undone, so check that the user is not still in use:
- If a live website or application still connects with this user's credentials, it will lose access to the database and is likely to show a connection error until you point it at a different user.
- Removing the user does not delete the database or any of its tables. Your data remains, but nothing can connect to it until at least one user is assigned.
- If you are unsure which user a site relies on, check the database connection details in the application's configuration file (for example `wp-config.php` for WordPress) before removing anything.
## Remove a database user in Plesk
**1.** Log in to your Plesk account.
**2.** Click **Databases** in the sidebar menu.

**3.** Click **User Management** in the right sidebar.

**4.** Under **Database Users**, tick the box next to the user you want to remove, then click **Remove**.

**5.** A confirmation box appears. Click **Yes** to remove the user.
## Troubleshooting
**A website stopped working after removing the user**: the site was almost certainly connecting with the credentials you removed. Create a new database user for that database, update the application's configuration with the new username and password, then reload the site.
**The Remove button is greyed out or missing**: your hosting plan or access level may not allow removing that user. Contact Noiz support if you need it removed.
If you would like Noiz to handle database changes for you, or you are on a managed plan, contact the Noiz support team and they will take care of it.
# How to Remove a Domain in Plesk
Source: https://docs.noiz.ie/plesk/how-to-remove-a-domain-in-plesk/
This guide shows you how to remove a website (domain) from your hosting subscription in Plesk on your Noiz hosting. Use it when you no longer need to host a particular domain or subdomain, for example after moving a site elsewhere or retiring a project.
**Removing a website is permanent.** It deletes the domain's hosting configuration and content from the server, so read the **Before You Begin** section and take a backup first.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/). See the *Websites and Domains* section for the full domain management reference.
## Before You Begin
When you remove a website, Plesk deletes everything tied to that domain on the server. That typically includes:
- All files in the domain's document root (its `httpdocs` folder and any subfolders).
- Databases used only by that website.
- Email accounts and their mailbox contents for the domain.
- Subdomains, DNS records, and any SSL/TLS certificates issued for the domain.
There is no undo, so **download a backup** of anything you may want to keep before you continue. If you only want to take the site offline temporarily rather than delete it, suspend the subscription instead of removing the website.
**Main domain versus additional domain.** The steps below remove an **additional domain** or subdomain from a subscription. The primary domain that a subscription was created under cannot be removed on its own. To remove that, you delete the whole subscription from the **Subscriptions** page, or contact Noiz support.
## Prerequisites
- Access to your Plesk control panel for the subscription that holds the domain.
- A current backup of any files, databases, or email you want to keep.
## Remove a Domain in Plesk
1. Log in to your Plesk account.
2. Click **Websites & Domains** in the sidebar menu. 
3. In the **list of domains**, click the **More** icon  next to the domain you want to remove, then choose **Remove Website**. 
4. Confirm with **Yes** to remove the domain. Plesk deletes the website and its associated content from the server.
## Good to Know
- Removing a website in Plesk only removes the **hosting** for the domain. It does not cancel the domain **registration**. If you also want to give up the domain name, manage that separately with your domain registrar.
- If the domain kept live email, update your MX and other DNS records after removal so mail is no longer routed to a server that no longer hosts the domain.
- If **Remove Website** is greyed out or missing, the domain is likely the subscription's primary domain. In that case, remove the subscription from the **Subscriptions** page instead, or ask Noiz support to handle it.
If you are on a managed Noiz plan and would prefer the team to remove a domain, migrate its data first, or delete a full subscription, contact Noiz support through your client area and the team will assist.
# How to Remove a Subdomain Redirect in Plesk
Source: https://docs.noiz.ie/plesk/how-to-remove-a-subdomain-redirect-in-plesk/
A subdomain redirect (also called forwarding) sends every visitor who requests your subdomain straight to another address, so the subdomain never serves its own content. When you no longer need that behaviour, you remove the redirect by switching the subdomain's hosting type back to standard website hosting. This guide shows you how to do that in Plesk. It is the reverse of setting up a redirect, so use it whenever a subdomain should serve its own files again instead of forwarding elsewhere.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (website and domain management)
## Prerequisites
- A Noiz Plesk hosting account you can sign in to.
- A subdomain that is currently configured as a redirect or forwarding (its hosting type shows **Forwarding**).
## Remove the redirect
**1.** Sign in to your Plesk account.
**2.** Click **Websites & Domains** in the sidebar menu.

**3.** Find the subdomain in the list of **Domain names**, then click the  **Hosting Settings** icon in that subdomain's row.

**4.** Next to **Hosting type** (currently showing **Forwarding**), click the **Change** link.

**5.** Under **Hosting type**, select **Website hosting** from the drop-down menu, then click **OK** to confirm.

The redirect is now gone. The subdomain will serve content from its own document root instead of forwarding visitors to the previous destination.
## After you switch to website hosting
- **Empty subdomain?** If the subdomain was only ever a redirect, its document root will have no website in it yet. Upload your files (or install an application) so visitors see content rather than a default placeholder page.
- **Caching:** Browsers and intermediate caches often remember redirects aggressively. If you still land on the old destination, clear your browser cache or test in a private window before assuming the change did not take.
- **DNS unchanged:** Removing the redirect only changes how Plesk handles requests for the subdomain. It does not alter your DNS records, so the subdomain keeps pointing at the same server.
## Troubleshooting
**The subdomain still redirects after the change**: this is almost always browser or DNS caching. Retest in a private window or a different browser. If it persists, confirm in Plesk that the hosting type now reads **Website hosting** and not **Forwarding**.
**No Change link next to Hosting type**: make sure you opened the subdomain's **Hosting Settings** and not the parent domain. Each subdomain has its own hosting type.
Need a hand? If you are on a Noiz managed plan, contact Noiz support and the team will remove the subdomain redirect for you.
# How to Remove a Subdomain in Plesk
Source: https://docs.noiz.ie/plesk/how-to-remove-a-subdomain-in-plesk/
A subdomain is a separate, self-contained section of your primary domain, such as `blog.yourdomain.com` or `shop.yourdomain.com`, with its own document root. When you no longer need one, you can remove it from Plesk in a few clicks. This guide shows you how to do that on your Noiz Plesk hosting.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Customer Guide: Subdomains](https://docs.plesk.com/en-US/obsidian/customer-guide/websites-and-domains/subdomains.71339/)
## Before you start
**Removing a subdomain is permanent and cannot be undone.** When you remove it, Plesk deletes the subdomain's files, its document root and the DNS records that belong to it. Any website served from that subdomain will stop working immediately, so make sure you have a current backup of anything you still need before you continue.
- If a mailbox or a database is still in use, move or back it up first, as it may no longer be reachable once the subdomain is gone.
- After removal the subdomain can still appear to resolve for a short while because of DNS caching in browsers and resolvers. This clears on its own once the cached records expire.
## Remove a subdomain in Plesk
1. Log in to your Plesk account.
2. Click **Websites & Domains** in the sidebar menu. 
3. In the list of **Domain names**, find the subdomain you want to remove, click the **More** icon  next to it, and select **Remove Subdomain**. 
4. When Plesk asks you to confirm, click **Yes** to remove the subdomain.
The subdomain is now removed from your Plesk hosting. If you cannot see the subdomain in the list, or you need help recovering content from one you have already removed, the Noiz support team is available to assist.
# How to Remove an FTP Account in Plesk
Source: https://docs.noiz.ie/plesk/how-to-remove-an-ftp-account-in-plesk/
Every FTP account on a subscription is a separate login into your website's files, so unused accounts are extra attack surface worth clearing out. If you have created more FTP users than you need, this guide shows you how to remove the ones you no longer use in Plesk, the control panel Noiz runs on its South African hosting.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (see the Websites & Domains and FTP access sections).
## Prerequisites
- A Plesk login for the subscription that holds the domain whose FTP accounts you want to manage.
- Confirmation of which FTP accounts are safe to remove. If an account is still used by an application, deployment script, or scheduled transfer, removing it will break that connection.
## Removing an FTP Account in Plesk
1. Log in to your Plesk control panel.
2. Click **Websites & Domains** in the sidebar menu. 
3. In the list of domain names, click the domain you want to work with. 
4. Under **Files & Databases**, click **FTP Access**. 
5. Tick the checkbox next to each FTP account you want to delete, then click **Remove**. 
6. Confirm with **Yes** to remove the selected FTP accounts.
## Good to Know
- **Removing an FTP account revokes login access only.** It does not delete your website files. The account can no longer connect, but everything it could previously reach stays in place.
- **The subscription's main system user is not in this list.** Only the additional FTP accounts you created appear here, so you cannot accidentally remove the primary login that Plesk ties to the hosting subscription.
- **Update anything that depended on the account.** If a removed account was used by a backup job, an automated deployment, or a third-party service, give that tool fresh credentials for a remaining account so its transfers do not start failing.
If you are on a Noiz managed hosting plan and are unsure which FTP accounts are safe to remove, open a support ticket from your Noiz client area and the team will confirm before anything is deleted.
# How to Rename an Email Address in Plesk
Source: https://docs.noiz.ie/plesk/how-to-rename-an-email-address-in-plesk/
Renaming an email address in Plesk changes the part of the address before the @ sign (the local part, sometimes called the mailbox name or username) while keeping the same mailbox, its stored messages, and its settings. This guide shows you how to rename an address on Noiz Plesk hosting, and explains what the rename does and does not change so you are not caught out by mail delivery or by email clients that suddenly stop connecting.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (see the Mail section for creating and managing email accounts)
## Prerequisites
- Access to your Plesk account for the subscription that hosts the mailbox.
- The email address you want to rename already exists under your domain.
## Rename the email address
1. Log in to your Plesk account.
2. Click **Mail** in the sidebar menu. 
3. In the **Email Addresses** list, click the email account you want to rename. 
4. In the **Email address** field, type the new name for the part before the @ sign. Leave the domain unchanged unless you also want to move the mailbox to another domain on the same subscription. 
5. Scroll down and click **OK**.
## What the rename changes, and what it does not
- **The mailbox and its messages are kept.** Renaming edits the existing account in place, so stored mail, folders, filters, and any auto-reply stay with the new address. You are not creating a fresh, empty mailbox.
- **The password does not change.** The existing password stays in place unless you set a new one on the same screen.
- **Mail clients need updating.** The username for webmail, IMAP, POP3, and SMTP is the full email address, so any desktop or phone app configured with the old address will stop connecting until you change its account username to the new address. The password is unchanged.
- **Mail sent to the old address will no longer arrive.** Once renamed, the old address no longer exists. If people still write to it, add the old address back as an email alias: open the renamed account, add the old address in the **Email Aliases** section, and click **OK**. Messages to the old address then land in the renamed mailbox.
## Troubleshooting
**Symptom:** **OK** is greyed out, or Plesk reports that the email address already exists. **Fix:** the name you chose is already in use on that domain. Choose a different local part.
**Symptom:** webmail or your mail app stops working straight after the rename. **Fix:** update the account username in the client to the new full email address. The password is unchanged, so nothing else needs to be re-entered.
If you are on a managed Noiz plan and would rather Noiz rename a mailbox or set up an alias for you, open a support ticket from your client area and the team will take care of it.
# How to Rename an FTP Username in Plesk
Source: https://docs.noiz.ie/plesk/how-to-rename-an-ftp-username-in-plesk/
This guide shows you how to rename an existing FTP account in Plesk, changing the username you use to sign in over FTP or SFTP without deleting the account and creating a new one. Only the login name changes: the account keeps the same home directory, permissions, and password. In the Plesk interface this login name is labelled the **FTP account name**.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Documentation and Help Portal](https://docs.plesk.com/en-US/obsidian/) (see the Customer Guide, under Website Management > FTP Access, for the full reference on FTP accounts).
## Prerequisites
- Access to your Plesk account for the subscription that holds the FTP account.
- An existing additional FTP account to rename. If you have not created one yet, add it first on the same **FTP Access** screen.
## Rename the FTP Account
1. Log in to your Plesk account.
2. Click **Websites & Domains** in the sidebar menu. 
3. Under the list of domain names, click the domain the FTP account belongs to. 
4. Under **Files & Databases**, click **FTP Access**. 
5. Click the FTP account you want to rename. 
6. Type the new name in the **FTP account name** field, then click **OK** to confirm. 
## After You Rename the Account
- The old username stops working the moment you save the change. Update every saved connection that uses it: FTP clients such as FileZilla, WinSCP, or Cyberduck, plus any deployment scripts, CI pipelines, or applications that upload over FTP.
- Renaming does not touch the password. If you want to reset it at the same time, change it on this same screen before clicking **OK**.
- Renaming does not move the account's home directory, so your files stay exactly where they were.
## Troubleshooting
**The account you want is not listed under FTP Access**: the main login tied to the subscription is its system user rather than an additional FTP account. Change that login name under **Websites & Domains** > your domain > **Web Hosting Access**, not on the FTP Access screen.
**Plesk reports that the name is already in use**: FTP account names must be unique across the server, not just within your subscription. Choose a different name, ideally one that is easy to trace back to the site, such as `yourdomain-uploads`.
If you are on a managed Noiz hosting plan and would prefer Noiz to make the change for you, open a support ticket from your client area and the team will rename the account and confirm once it is done.
# How to Reset Your Plesk Password
Source: https://docs.noiz.ie/plesk/how-to-reset-your-plesk-password/
If you have forgotten your Plesk password, or you simply want to change it, you can reset it yourself from the Plesk login page. This guide walks you through requesting a reset link by email and setting a new password. It applies to any Plesk account hosted with Noiz.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/)
## Prerequisites
- Your Plesk login URL. For a Noiz-hosted account this is usually your server hostname on port `8443`, for example `https://yourserver.noiz.co.za:8443`, or the address shown in your Noiz welcome email.
- Access to the email address registered on your Plesk account, because the reset link is sent there and nowhere else.
- Your Plesk username, if you prefer to request the reset by username rather than by email.
## Reset Your Plesk Password
1. Open your Plesk login URL in your browser.
2. Click **Forgot your password?** below the login form. 
3. On the **Reset password** page, enter your **email address**. Alternatively, choose the **Username** option, type your username, then click **Send**. 
4. Check the inbox of your registered email address for the password reset message, then open it and click the reset link. If nothing arrives within a few minutes, check your spam or junk folder.
5. Enter a new password, or click **Generate** to have Plesk create a strong one for you. Click the **view password** (eye) icon to reveal the value so you can copy and store it safely. 
6. Click **Save**.
Once the password is saved, return to the Plesk login page and sign in with your username and the new password.
## Troubleshooting
**No reset email arrives**: the message is sent only to the email address registered on the account, so confirm you entered the correct address or username. Check your spam or junk folder, and allow a few minutes for delivery before requesting the link again.
**The reset link says it is invalid or has expired**: Plesk password reset links are single use and time limited. Request a fresh link from the login page and use the most recent email, ignoring any earlier ones.
**Plesk rejects the new password as too weak**: the server enforces a password strength policy. Use a longer password that mixes upper and lower case letters, numbers and symbols, or click **Generate** to let Plesk produce a compliant one.
**You no longer have access to the registered email address**: the self-service reset cannot be completed without it. Contact Noiz support so the team can verify your identity and restore access.
## Need a Hand?
If you cannot reset your password yourself, or you are on a managed Noiz plan and would prefer the team to handle it, open a support ticket from your Noiz client area. Noiz support can verify your account and reset your Plesk password for you.
# How to Set Up Email Forwarding in Plesk
Source: https://docs.noiz.ie/plesk/how-to-set-up-email-forwarding-in-plesk/
This guide shows you how to **forward email** from one mailbox to another using the Plesk hosting control panel on your Noiz hosting account. When forwarding is switched on, every message that arrives at the chosen mailbox is automatically sent on to a destination address you specify.
**Terminology:**
- A **mailbox** is sometimes called an **email address**, an **email account** or a **domain mailbox**.
- Forwarding email is also described as setting up an **email forwarder**.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (see the **Mail** section for account-level mail settings).
## Prerequisites
- An active Plesk subscription on your Noiz hosting account.
- The mailbox you want to forward **from** must already exist. If you have not created it yet, follow [How to Create an Email Address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/) first.
- Login access to Plesk. If you are unsure how, see [How to Log In to Plesk](/plesk/how-to-log-in-to-plesk/).
## Table of contents
- [Watch the video: How to set up email forwarding in Plesk](#video).
- [Steps for forwarding mail from one mailbox to another](#text-guide).
- [Troubleshooting](#troubleshooting).
- [Conclusion](#conclusion).
## Watch the video: How to set up email forwarding in Plesk
## Steps for forwarding mail from one mailbox to another
**1.** Log in to the Plesk hosting control panel for your subscription. If you are not sure how to do this, follow [How to Log In to Plesk](/plesk/how-to-log-in-to-plesk/).
**2.** Once logged in, click the **Mail** tab in the sidebar menu of the Plesk control panel.

**3.** In the main content area, under the **Email address** column, click the email address **from** which you want to forward incoming mail.

**Note:** This guide uses `sales@yourdomain.com` as the example mailbox. Replace it with your own email address as you follow the steps. Placeholders such as `yourdomain.com` are examples only.
**4.** From within the settings for that email address, select the **Forwarding** tab, located between the **General** tab and the **Email Aliases** tab.

**5.** Tick the **Switch on mail forwarding** checkbox to enable the forwarding service. This reveals two further options:
- **Do not deliver copies of forwarded emails to the Plesk mailbox.** When ticked, this forwards mail to the destination address and does not keep a local copy in the Plesk mailbox, which saves disk space. Leave it unticked if you want a copy to remain in the original mailbox as well.
- **Forward incoming messages to the following email address.** This is the destination, the address your mail is forwarded **to**. It can be any address except the forwarding mailbox itself, which prevents a mail loop. In the example below, mail is forwarded from `sales@yourdomain.com` to `destination@example.com`, with local delivery switched off. Set this according to your own needs.

**6.** When your settings are correct, click **Apply** or **OK** to save the forwarder and activate it.
## Troubleshooting
**Symptom:** Forwarded mail never arrives at the destination. Confirm the destination address is spelled correctly, check the destination mailbox spam or junk folder, and make sure the destination provider is not silently rejecting forwarded mail (some providers treat forwarded messages more strictly because the original sender is preserved).
**Symptom:** Messages stop being delivered to the original mailbox. This is expected when **Do not deliver copies of forwarded emails to the Plesk mailbox** is ticked. Untick it if you also want to keep a copy in the Plesk mailbox.
**Symptom:** A bounce or loop warning appears. Make sure the destination address is not the same as the forwarding mailbox, and that two mailboxes are not forwarding to each other.
## Conclusion
That is it. Your forwarder is now active, and any email received at the Plesk mailbox will be forwarded to the destination address you set.
Browse the Noiz knowledgebase for more tutorials, or contact the Noiz support team if you get stuck.
# How to Set Up an Email Autoresponder in Plesk
Source: https://docs.noiz.ie/plesk/how-to-set-up-an-email-autoresponder-in-plesk/
This guide shows you how to set up an email autoresponder on a mailbox in Plesk, so that anyone who writes to you receives an automatic reply while you are away. The feature is called **Auto-Reply** in Plesk, but you will also hear it described as an autoresponder, a vacation message or an out-of-office reply. They all mean the same thing: a message the mail server sends back on your behalf, without you lifting a finger, until you switch it off. It is written for Noiz email clients whose mailbox lives on the Noiz Plesk mail platform.
Because the auto-reply runs on the server, it works no matter how you normally read your mail. You do not need to leave your computer on, keep webmail open, or sign in from anywhere. Once it is enabled, Plesk answers your incoming mail around the clock until the day you tell it to stop.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below. Plesk updates regularly and the exact wording of one or two Auto-Reply fields (for example the reply-frequency label) can differ slightly between versions, so if a field name on your screen reads a little differently from this guide, the setting it controls is the same one described here.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/): the official user-facing manual for Plesk, including the Mail chapter that covers mailboxes and their settings.
- [Plesk documentation portal](https://docs.plesk.com/): the index to every current Plesk guide, kept in step with the latest release.
- [RFC 3834: Recommendations for Automatic Responses to Electronic Mail](https://www.rfc-editor.org/rfc/rfc3834): the open email standard that describes how a well-behaved autoresponder should work, and why the loop-prevention rules covered below exist.
## Prerequisites
- You can [log in to Plesk](/plesk/how-to-log-in-to-plesk/).
- The mailbox you want the auto-reply on already exists. If you have not created it yet, do that first: see [How to create an email address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/). An auto-reply can only be attached to a mailbox that has already been set up.
- You have decided, before you start, what the reply should say and the date you expect to be back. Having the wording and the return date ready makes the setup a two-minute job.
## Open the Auto-Reply Tab for Your Mailbox
1. Log in to Plesk.
2. In the left-hand menu, click **Mail**. The list of email addresses on your subscription appears.
3. Click the email address you want to set the auto-reply on, for example `you@yourdomain.com`. The mailbox settings open across a row of tabs.
4. Click the **Auto-Reply** tab.

## Switch On the Auto-Reply and Compose Your Message
1. Tick **Switch on auto-reply**. The rest of the fields on the tab become editable once this is ticked.
2. In **Auto-reply message subject**, type the subject line the sender will see on your reply, for example `Out of office`. Keep it short and self-explanatory so it is clear at a glance that the answer is automatic.
3. Leave **Message format** as **Plain text** unless you specifically need bold text or links, in which case choose **HTML**. Plain text is delivered reliably everywhere and is the right choice for a simple away message. If an encoding option is shown, leave it as **UTF-8** so accented characters and symbols display correctly.
4. In the message text box, write the body of your reply. There is a suggested example, and etiquette to follow, in [Write a Good Out-of-Office Message](#write-a-good-message) further down this page.

## Optional Settings: Forwarding, Attachments and Reply Frequency
The remaining fields on the tab are optional. You can safely leave them at their defaults for a straightforward away message, but each one is useful in the right situation.
### Forward Incoming Mail to a Colleague
Use **Forward requests to the address** when you want someone to actually deal with mail while you are away, not just to have the sender told you are out. Enter a colleague's full email address, for example `cover@yourdomain.com`, and Plesk sends a copy of each incoming message to that address at the same time as it sends the automatic reply. Leave this field empty if you only want the auto-reply and no forwarding. Whoever you forward to should know they are covering your mailbox, so nothing is missed.
### Attach a File to the Reply
Use **Attach a file to the automatic reply message** when every reply should carry the same document, such as a price list, a contact sheet or a holiday-schedule PDF. Upload the file and it is sent with each automatic reply. Keep attachments small and few: a large attachment sent to every single sender wastes their inbox space and yours, and can trip spam filters. For most away messages, no attachment is the better choice.
### Limit How Often Each Sender Is Answered
Plesk limits how many times it will send the automatic reply to the same sender within a single day. This is the single most important setting for good behaviour, and it exists to stop your mailbox firing off a fresh reply to every message in a long back-and-forth thread. Set a low number here; answering each unique sender **once a day** is almost always the right choice. A person who emails you five times in one afternoon then receives one courteous away message, not five identical ones. This same limit is part of how Plesk prevents reply loops, explained in [How Plesk Prevents Auto-Reply Loops](#loops) below.

## Set an End Date so the Auto-Reply Switches Itself Off
An auto-reply that you forget to turn off is the classic mistake: it keeps telling people you are on leave weeks after you are back at your desk. Plesk solves this for you.
1. Find the **Switch off auto-reply on** date field.
2. Set it to the day you return, for example the first working day back. Plesk turns the automatic reply off by itself on that date, so you do not have to remember.
There is no separate start-date field: the auto-reply begins working the moment you save it with **Switch on auto-reply** ticked. So enable it on the day you actually leave, not days in advance, and let the end date take care of switching it off. If your plans change and you return early, you can turn it off by hand at any time, as shown in [Turn the Auto-Reply Off](#turn-off).

## Save and Test
1. Click **OK** (or **Apply**) at the bottom of the tab to save the auto-reply.
2. From a different email account, such as a personal address, send a short message to the mailbox you have just set up.
3. Within a minute or two the automatic reply should arrive back at that other account. Read it as your correspondents will, and check the subject line, the wording and the return date all read correctly.
4. Send a second test message from the same account to confirm the reply-frequency limit is doing its job: with a once-a-day limit, the second message should *not* produce a second automatic reply.
## Write a Good Out-of-Office Message
The wording of an away message is what your customers and colleagues actually read, so it is worth getting right. A good one is brief, tells the reader what they need to know, and gives them a way forward. Cover these points:
- **That you are away, and until when.** A specific return date is far more useful than a vague "I am currently unavailable".
- **Who to contact instead, for anything urgent.** Give a name and a monitored email address, or a phone number, so time-critical matters are not stranded in your inbox.
- **What will happen to their message.** Say whether you will reply on your return, so the sender knows they do not need to chase or resend.
A short, professional example you can adapt:
```
Subject: Out of office until 5 August
Thank you for your email. I am out of the office until
Monday 5 August and will not be reading messages during
this time.
For anything urgent, please contact Sam Nkosi at
sam@yourdomain.com or on 021 000 0000.
I will reply to your message when I return.
Kind regards,
Your Name
```
Two etiquette points worth keeping in mind. First, keep it professional even for an internal address, because you cannot control who ends up writing to you. Second, remember that an auto-reply confirms to *every* sender that the address is live and monitored, including spammers who mail it at random. Plesk's loop protection stops it answering mail that clearly looks automated, but the more you can keep the message plain and free of personal detail such as your exact travel dates or your mobile number, the better. For an address that receives a lot of unwanted mail, weigh up whether an auto-reply is worth switching on at all; the article on [how to determine the source of spam and reduce it](/email/how-to-determine-the-source-of-spam-and-reduce-it/) is a useful companion.
## How Plesk Prevents Auto-Reply Loops
An autoresponder that simply replied to everything would be dangerous. Picture two mailboxes, both on holiday auto-reply, that happen to email each other: the first replies, which triggers the second to reply, which triggers the first again, and the two servers bounce identical messages back and forth thousands of times. This is a mail loop, and in the early days of email it was a real way to fill up mailboxes and overload servers.
The open email standard [RFC 3834](https://www.rfc-editor.org/rfc/rfc3834) sets out how a responsible autoresponder should behave to avoid this, and Plesk follows those rules for you:
- **It never answers the same sender more than the daily limit you set.** This is the reply-frequency field described above. Even if two auto-replies did somehow reach each other, the per-day cap breaks the loop almost immediately, which is exactly why keeping that number low (once a day) matters.
- **It does not reply to mail that looks automated.** Newsletters, mailing-list messages, delivery-failure notices and other autoresponders are generally marked as bulk or automatic in their headers, and a well-behaved responder, including Plesk's, leaves them alone. That also means your holiday reply will not flood the mailing lists you are subscribed to.
You do not have to configure any of this; it is built in. The one part that is in your hands is the daily reply limit, so set it sensibly and the rest is taken care of.
## Turn the Auto-Reply Off
If you set an end date, Plesk switches the auto-reply off on that day automatically and there is nothing more to do. To turn it off by hand, for example if you return early:
1. Go to **Mail**, click the email address, and open the **Auto-Reply** tab.
2. Untick **Switch on auto-reply**.
3. Click **OK** or **Apply** to save. Your reply text and settings are kept, so you can switch the same message back on next time you are away without retyping it.
## Troubleshooting
- **Symptom: the automatic reply is not being sent.** Open the **Auto-Reply** tab and confirm **Switch on auto-reply** is still ticked and that the settings were saved. Check the **Switch off auto-reply on** date has not already passed, as Plesk will have turned the reply off on that day. Remember too that Plesk only answers each sender up to the daily limit, so if you are testing from the same address more than once a day, you will not see a second reply; test from a fresh address to confirm.
- **Symptom: I set it up but I am back and it is still replying.** Either no end date was set, or the date was set later than the day you actually returned. Open the tab and untick **Switch on auto-reply** to stop it now, and set a correct **Switch off auto-reply on** date next time.
- **Symptom: senders receive several identical replies.** The reply-frequency limit is set too high. Lower it so each unique sender is answered no more than once a day.
- **Symptom: the reply text shows strange characters or question marks.** The encoding does not match the characters you used. If an encoding option is available, set it to **UTF-8**, then re-save; UTF-8 handles accented letters, currency symbols and punctuation correctly.
- **Symptom: the Auto-Reply tab is missing.** Some mailbox types, such as a plain forwarding-only address with no mailbox storage, do not have their own auto-reply. Make sure the address is a full mailbox rather than a forwarder or alias. If you are unsure, the Noiz support team can confirm how the address is configured.
- **Symptom: mail sent to me while I am away is not being kept.** The auto-reply does not stop your normal mail being delivered; incoming messages still arrive in your mailbox to read on your return. If you also want a colleague to handle mail meanwhile, set **Forward requests to the address** as described above.
If your auto-reply still does not behave as you expect, open a support ticket with the Noiz support team. Include the mailbox address, what you set on the **Auto-Reply** tab, and, if a reply went astray, the sending address and roughly when it was sent. On Noiz managed plans the support team can check how the mailbox and its autoresponder are configured on the server side and put it right for you.
# How to Suspend, Disable, and Activate a Subscription in Plesk
Source: https://docs.noiz.ie/plesk/how-to-suspend-disable-and-activate-a-subscription-in-plesk/
This guide is for administrators and resellers who manage hosting subscriptions in Plesk and need to control whether a subscription is live or turned off. It explains what it really means to **suspend**, **activate**, and (in the sense some billing panels use the word) **disable** a subscription, when to reach for each one, and exactly how to do it in the Plesk interface. Just as important, it sets out what happens to the websites, mailboxes, files and databases inside a subscription while it is suspended, so you can act with confidence and without surprising a client.
A quick word on terminology, because it causes most of the confusion. Plesk itself uses only two labels for the on and off states of a subscription: **Active** and **Suspended**. Other tools, including billing systems and older control panels, describe the same off state as "disabled" or "deactivated". Throughout this guide, treat "disable" and "deactivate" as everyday words for suspending, and treat "activate" as the same thing as "unsuspend" or "enable". None of these are the same as removing or terminating a subscription, which deletes it and its data for good. That distinction is the single most important thing on this page.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below. Plesk receives frequent updates and the exact position or wording of a button can shift between releases; where that happens the action and its effect stay the same even if a control moves.
### Official Documentation Reference
- [Managing Subscriptions (Plesk Obsidian Administrator Guide)](https://docs.plesk.com/en-US/obsidian/administrator-guide/managing-subscriptions.65125/): the authoritative reference for suspending, activating, renewing and removing subscriptions, including the exact interface steps.
- [Relationship Between Plans and Subscriptions](https://docs.plesk.com/en-US/obsidian/administrator-guide/relationship-between-plans-and-subscriptions.65118/): how a subscription stays in sync with its service plan, which explains why a manual change can be undone by synchronisation.
- [Managing Customers](https://docs.plesk.com/en-US/obsidian/administrator-guide/managing-customers.65124/): suspending a whole customer account, which suspends every subscription that customer owns at once.
## Prerequisites
- You can [log in to Plesk](/plesk/how-to-log-in-to-plesk/) as the administrator, or as a reseller who owns the subscription. Only the account that owns a subscription, or an administrator above it, can change its status.
- You know which subscription you are acting on. In the **Subscriptions** list a subscription is identified by its primary domain name, for example `yourdomain.com` (replace this with the real domain). Acting on the wrong subscription takes a live site offline, so confirm the domain before you click.
- You understand the client relationship. If the subscription belongs to a client on a Noiz managed plan, coordinate with the client and with Noiz support before suspending, because suspension interrupts their mail and website.
## The Three States, and When to Use Each
Every subscription sits in one of two states in Plesk, with a third, destructive action alongside them that is easy to confuse with disabling. Knowing the difference is what keeps a routine pause from becoming an accidental deletion.
| State or action | What it means | Effect on the subscription | Reversible? |
| --- | --- | --- | --- |
| **Active** | The normal, running state. | Websites serve visitors, mail is delivered, FTP and databases work. | Not applicable |
| **Suspended** (also called disabled or deactivated) | A deliberate, temporary switch-off by the owner or an administrator. | Websites, FTP and mail stop being available to the public; all files, mailboxes and databases are kept intact. | Yes, by activating it again. |
| **Removed** (terminated) | Permanent deletion of the subscription. | Websites, mailboxes, files and databases are deleted from the server. | No, only a backup can bring the data back. |
**Suspend** when you want to take a subscription offline for a while and put it back later untouched. Common reasons are an overdue account, a compromised or spam-sending website that needs containing quickly, a client winding a site down before deciding whether to keep it, or planned work where you want the public locked out but the data preserved. Suspension is the safe, reversible tool.
**Activate** to reverse a suspension and return everything to normal. Nothing is rebuilt or restored because nothing was ever deleted; the same files, mail and databases simply become reachable again.
Do not reach for **Remove** when you mean to suspend. Removing is how a subscription is decommissioned for good, and it deletes the client's data. If there is any chance the subscription will be needed again, suspend it instead.
One more distinction worth knowing: Plesk separates a subscription you *manually* suspended from one that became suspended on its own, for example an expired subscription. Both look switched off, but you clear a manual suspension by activating it, whereas an expired subscription is brought back by renewing it. The steps below cover the manual case, which is the one an administrator controls directly.
## What Suspension Actually Does
Before you suspend anything on a live account, it helps to know precisely what a visitor, a mailbox and a database experience. This is where suspension differs from simply "the site is down".
### Websites
A suspended subscription stops serving its websites to the public. Instead of the site, a visitor receives an error or a suspension notice rather than the pages themselves. The website's files are never touched; they sit exactly where they were and reappear the instant you activate the subscription. Plesk can also keep a specific website in an **Active** state even while the rest of the subscription is suspended, which is useful when you want to freeze management and mail but leave the public site online. That per-website control varies by Plesk version, so check the current option in the subscription's hosting settings if you need it.
### Mail
Mail for a suspended subscription pauses. The mailboxes and all their existing messages are preserved, but the mail service stops accepting and delivering new mail for the domain while it is suspended. In practice a sender may receive a delayed or bounced message during that window, so treat mail as the most sensitive part of a suspension: a client who is merely a few days overdue may still be relying on email. If your only aim is to take a website offline, consider whether you truly need to interrupt mail as well.
### Databases and files
Nothing is deleted. Databases, their contents, and every file in the subscription are preserved on the server throughout a suspension. What changes is reachability: because the websites are not being served, database-driven pages will not load, and the database management tools for that subscription are paused along with it. Activate the subscription and the databases are immediately available again, unchanged. Suspension is never a data-loss event; only **Remove** deletes data.
## Suspend a Single Subscription
This is the everyday case: one subscription, taken offline deliberately.
1. In the left menu, open **Subscriptions**. You see the list of subscriptions on the server, each shown by its primary domain with a status column.
2. Click the subscription you want to suspend, identified by its domain such as `yourdomain.com`.
3. In the right sidebar, under **Hosting**, click **Suspend**.
The subscription's status changes to **Suspended** and its websites, FTP and mail go offline as described above. The data stays put.
## Activate a Suspended Subscription
Reversing a manual suspension is the mirror image of the step above.
1. Open **Subscriptions** from the left menu.
2. Click the suspended subscription you want to bring back.
3. In the right sidebar, under **Hosting**, click **Activate**.
The status returns to **Active** and the websites, mail, FTP and databases start working again straight away. Remember that an *expired* subscription is restored by renewing it rather than activating it; if the Activate action does not fully restore service, check whether the subscription is expired rather than manually suspended.
## Suspend or Activate Several Subscriptions at Once
When you need to act on more than one subscription, use the list rather than opening each in turn.
1. Open **Subscriptions**. To narrow the list, click the filter control and choose **Active** (when suspending) or **Suspended** (when activating).
2. Tick the checkbox beside each subscription you want to change.
3. Click **Change Status**, then choose **Suspend** or **Activate**.
Every selected subscription switches together. Take extra care here, because a single click acts on all the ticked rows; confirm the selection before you apply it.
## Suspend a Whole Customer Account
Suspending an individual subscription only affects that subscription. If you need to switch off everything a customer owns at once, for example an account under review, suspend the customer instead.
1. Open **Customers** from the left menu.
2. Click the customer's name, or tick the checkbox beside one or more customers.
3. Click **Change Status**, then **Suspend**. Use **Activate** to reverse it.
Suspending a customer suspends every subscription that customer owns and blocks their access to the Plesk Customer Panel. Resellers work the same way one level up: if an administrator suspends a reseller, all of that reseller's customers and their subscriptions are suspended too. Reach for the customer-level or reseller-level switch only when you genuinely intend to take down everything beneath it.
## Disabling Only Part of a Subscription
Suspension is deliberately all-or-nothing at the subscription level, but you do not always need that big a hammer. If your real goal is narrower, Plesk lets you turn off individual services inside a subscription while leaving the rest running:
- **Turn off mail for a domain** while the website keeps serving, using the domain's mail settings. This is the right tool when a single domain's mail is being abused but the website is fine.
- **Disable a single website** within a subscription that hosts several, rather than suspending the whole subscription and taking the others down with it.
- **Suspend an individual mailbox** from the mail settings, leaving every other mailbox on the domain working.
These finer controls are what people often mean when they say "disable" rather than "suspend". Use them when you want surgical, not total, control.
## Troubleshooting
- **Symptom: you activated the subscription but the website still will not load.** First confirm the subscription really shows **Active** and not **Suspended** or expired. If it is Active, the delay is usually the visitor's browser or a network cache still holding the suspension response; a hard refresh, or a check from a different device or connection, normally clears it. If the subscription had expired rather than being manually suspended, renew it rather than only activating it.
- **Symptom: a suspension you applied comes back as Active on its own, or the reverse.** Subscriptions are kept in step with their service plan and, on billed accounts, with the Noiz billing system. A status set manually in Plesk can be overridden the next time the subscription synchronises with its plan or its billing record. For subscriptions that are billed, change the status through the billing workflow so both systems agree, rather than only inside Plesk. See the Relationship Between Plans and Subscriptions reference above for how synchronisation decides the final state.
- **Symptom: mail is still flowing after you suspended.** Check whether a specific website or service inside the subscription was left in the **Active** state, or whether you suspended a single subscription while mail for the domain lives under a different one. Confirm the status on the exact subscription that owns the mail domain.
- **Symptom: you suspended the wrong subscription.** Activate it again immediately. Because suspension preserves all data, no files, mail or databases are lost; service resumes as soon as the status returns to Active and any client-side cache clears.
- **Symptom: the Suspend or Activate option is missing.** You are probably signed in as a reseller or customer without rights over that subscription, or the subscription is owned by another account. Only the owning account or an administrator above it can change the status.
## Managed Plans and Noiz Support
Everything above assumes you hold administrator or reseller access to the Plesk server. Clients on Noiz managed plans do not manage subscription status themselves; if you are a managed client and need a subscription suspended, activated, or checked, open a ticket with the Noiz support team and they will handle it and confirm the effect on your sites and mail.
For resellers and administrators, Noiz support can help when a status will not behave as expected, for example when a subscription keeps re-synchronising to the wrong state, when an expired subscription needs restoring, or when you need a suspended site's data recovered from backup. When you open a ticket, include the subscription's primary domain, whether you were suspending or activating, and what you saw happen, so the team can match the Plesk status against the billing record and put the two back in step.
# How to Train Your Spam Filter in Plesk
Source: https://docs.noiz.ie/plesk/how-to-train-your-spam-filter-in-plesk/
If your hosting plan runs on Plesk, you can filter spam using Apache SpamAssassin, the open-source anti-spam engine built into the panel. Out of the box it catches a lot, but the real gains come from tuning its sensitivity and, above all, **training** it on the mail you actually receive. This guide shows you how to switch spam filtering on, set a sensible threshold, understand how the scoring works, and train the filter so it keeps improving.
Note: Many of these steps are the same regardless of the control panel you use, but the exact menus below are written for Plesk.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** and Apache SpamAssassin. This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk and SpamAssassin documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian documentation portal](https://docs.plesk.com/): customer, hosting-provider and developer guides.
- [Apache SpamAssassin project](https://spamassassin.apache.org/): the upstream anti-spam engine, including how scoring and Bayesian learning work.
## Prerequisites
- A hosting plan on a Noiz Plesk server, and the ability to [log in to Plesk](/plesk/how-to-log-in-to-plesk/).
- At least one mailbox to configure.
- If you collect mail over POP rather than IMAP, access to [Plesk webmail](/plesk/how-to-access-email-from-plesk-webmail/), because POP does not sync the Spam folder your training relies on.
## Enable Spam Filtering
Note: By default your spam filter should already be enabled. Follow along anyway in case it is not.
1. Start by [logging in to Plesk](/plesk/how-to-log-in-to-plesk/). If you have more than one hosting account on the same server, select the correct subscription using the drop-down at the top-right of the page.
2. Go to the **Mail** tab on the left.
3. Select the mail account you wish to configure from the list. Do this by clicking the mailbox link under the column marked **Email address**.
4. Choose the **Spam Filter** tab.
5. Select the option to **Switch on spam filtering for this email address**.
6. Choose what happens to spam when it is detected. The recommended option is **Move spam to the Spam folder**, which keeps your inbox clean while leaving anything flagged in reach for recovery.
7. Click **OK** and your spam filter is now enabled.
Note: Apache SpamAssassin is configured per mailbox, not per domain, so you repeat this for each address you want protected.
Watch out for mislabelled spam folders. Many mail apps create a folder called "Junk" or "Junk E-Mail" instead of **Spam**. Because those folders are not named exactly "Spam", messages you file there will not be picked up for training. To fix this, delete the other folders and create a single folder named **Spam**. If you use POP accounts, do this through your [webmail](/plesk/how-to-access-email-from-plesk-webmail/).
## Configure Filter Sensitivity
Follow steps 1 to 8 above, then expand the **Show Advanced Settings** section. Here you can set your spam filter threshold. Although 7 is the default, it is extremely conservative in practice.
**If you want Gmail or Hotmail-level filtering**, where the occasional legitimate message may land in Spam but very little spam reaches your inbox, **enter a value of 1.5**.
**If you want a balanced setup**, where some spam might reach your inbox but legitimate email is unlikely to be filtered, **enter a value of 3**.
A lower threshold is more aggressive. Whichever value you pick, pair it with training (below) so the filter learns your particular mail rather than relying on the threshold alone.
## How Does It Work?
If you have configured Plesk to mark the message (change the subject), then when an incoming email is believed to be spam its subject is prepended with `*****SPAM*****`, or whatever text you specify.
If you have configured Plesk to move spam to the **Spam** folder, it does exactly that. Note that the Spam folder is only visible [via webmail](/plesk/how-to-access-email-from-plesk-webmail/) or if you connect to the mail server over **IMAP**. If you want to train your spam but connect over POP, do your training in webmail.
The spam filter checks every incoming email against a large database of attributes commonly found in spam. Each attribute carries a weight indicating how strongly it points to spam. For example, if messages containing the word "Dating" turn out to be spam 90% of the time, that attribute carries a high weight; a phrase that is only spam 30% of the time carries a much lower weight. This also works in reverse: attributes that appear in your legitimate mail but rarely (or never) in confirmed spam are given a negative weight.
All of these scores are added together to give the message its final spam score. The lower the score, the less likely the message is spam. If the score breaches the threshold you set in the sensitivity section, the message is moved to the Spam folder or marked as spam, according to your configuration.
You can adjust the threshold at any time by returning to the Spam Filter settings and selecting **Show Advanced Settings**.
### Clever Spammers Can Get Around This
There is one major weakness in this approach. Because the spammy attributes are public knowledge, all a spammer has to do to slip past the filter is avoid those attributes.
As an example, say most of the spam you receive is trying to sell you premium software. The spammer avoids the obvious spammy attributes, so the messages only score 1.0 against your threshold of 3. Every time they send, the message is never marked as spam and the clutter starts collecting in your inbox. How is this fixed? **Training**.
## Training Your Spam Filter
By training SpamAssassin, you give it information about the kinds of spam, and the kinds of legitimate mail, that you personally receive. This lets it detect patterns specific to **your** spam and non-spam, rather than relying on general rules alone.
### Classify Spam
All you have to do is move any spam you receive into the folder called **Spam**. Every message in the Spam folder is automatically scanned and trained nightly. This means you must leave spam messages in the Spam folder for 24 hours before deleting them, otherwise the classification will not happen.
### Classify Non-Spam
This also works the other way round. To teach the filter that a message which went to Spam is not actually spam, move it back to the inbox and leave it there for 24 hours; the filter will learn that you consider the message legitimate. It may take classifying several similar messages before future ones like them stop going to Spam, so this does not apply instantly to all future mail. You can, however, use the whitelist function in Plesk to make a specific sender clear the filter immediately.
If you connect over POP, you cannot train from your mail application because it does not see the Spam folder. You can instead [train via webmail](/plesk/how-to-access-email-from-plesk-webmail/) or switch to an **IMAP** connection.
## Troubleshooting
[Learn the best way to troubleshoot ongoing spam problems](/email/how-to-determine-the-source-of-spam-and-reduce-it/), after you have completed at least a week of training as described above.
Each Plesk email account has its own login to Plesk, limited to managing that mailbox's own settings. You can send your email users to your server's Plesk URL and have them log in with their email address and email password so they can train their own spam. Your Plesk URL appears in your address bar once you are logged in; on Noiz shared servers it looks something like `https://neo.noiz.co.za:8443`.
## Enterprise Option
Noiz also offers an enterprise spam filter that uses machine learning and a cloud relay to train against a much larger sample of incoming email. To enable it, open the add-on from the client area on your hosting plan under **Actions** > **Upgrade/Downgrade Options**.
If you would rather Noiz handle spam tuning for you, the Noiz support team can advise on the right threshold and set up the enterprise filter on your account.
# How to Update a Plesk Account's Email Address
Source: https://docs.noiz.ie/plesk/how-to-update-a-plesk-accounts-email-address/
This guide shows you how to update the contact email address on your Plesk account. This is the address Plesk uses to identify your account and to send you service notifications. You can update both the **primary email address** and the **external email address** that is used for password recovery.
If you instead need to change your name, company, telephone number or postal address, see [How to Change the Plesk Account's Contact Details](/plesk/how-to-change-your-plesk-account-contact-details/).
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable line). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/): account management and personal settings.
## Before You Start
- You need to be able to log in to Plesk. If you cannot sign in, reset your password from the Plesk login page or contact Noiz support.
- Know the difference between the two fields you can change here:
- **Email address**: the primary contact address on the account. Plesk sends service and account notifications to this address.
- **External email address**: a separate address used for password reset links. Keep this on a different mail provider from your Noiz-hosted mailboxes so that you can still recover access if your hosted mail is unavailable.
## Update Your Plesk Contact Email Address
1. Log in to your Plesk account.
2. Click **Account** in the sidebar menu. 
3. Click **My Profile**. 
4. Enter the new address in the **Email address** field. If you have more than one domain, choose the appropriate domain from the drop-down menu. You can also update the **External email address** used for password resets. 
5. Click **Apply**. 
Plesk displays a confirmation message once your contact email address has been updated.
## Good to Know
- Changing your Plesk contact email address does not create or rename a mailbox. It only updates the address linked to your panel account. To create an actual email account, use the **Mail** section of Plesk.
- If you rely on the external email address for password recovery, double-check that it is an address you can still access. Losing access to both the primary and external addresses makes self-service password resets much harder.
If the change will not save, or you no longer have access to the current contact address, the Noiz support team can update it for you. Open a ticket from your [Noiz client area](https://www.noiz.co.za) and Noiz will make the change on your behalf.
# How to Update the Email Address of a Scheduled Task in Plesk
Source: https://docs.noiz.ie/plesk/how-to-update-the-email-address-of-a-scheduled-task-in-plesk/
This guide shows you how to change the notification email address on a Scheduled Task (also called a Cron Job) in Plesk. Update it whenever the person who should receive a task's output or error alerts changes, for example when a team member leaves or a shared mailbox is retired, so important run reports do not go to an address nobody reads.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation.
### Official Documentation Reference
- [Plesk Obsidian documentation portal](https://docs.plesk.com) (see the Scheduling Tasks section)
## Prerequisites
- Access to your Plesk account for the subscription that owns the task.
- At least one existing Scheduled Task to edit.
## Update the notification email address
1. Log in to your Plesk account.
2. Open **Scheduled Tasks** from the sidebar menu. 
3. Under the **Command** list, find your task and click it to open it. 
4. Scroll down to **Send notifications**, choose **other users**, and enter the new email address. 
5. Click **OK** to save the change.
**Note:** If the **Send notifications to** option is not available, set **Notify** to **Every time** or **Errors only** first. Notifications are off by default, so the recipient field only appears once notifications are switched on.
## Need a hand?
If you are on a Noiz managed hosting plan and would like the change made for you, or the Scheduled Tasks area does not look as described above, open a support ticket from your Noiz client area and the team will assist.
# How to Upload Files via the Plesk File Manager
Source: https://docs.noiz.ie/plesk/how-to-upload-files-via-the-plesk-file-manager/
This guide shows you how to upload files to your website using the Plesk File Manager on your Noiz hosting. The File Manager is a built-in tool that lets you manage the files and folders on your hosting space straight from your web browser, with no separate FTP program to install. It is the quickest way to add one or a handful of files, such as an `index.html` page, an image, or a configuration file.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) covers managing your website content, including the File Manager.
## Prerequisites
- A Plesk account on your Noiz hosting service, with your login details to hand.
- The files you want to upload, saved on the computer you are working from.
## Upload Files with the Plesk File Manager
1. Log in to your Plesk account.
2. Click **Files** in the sidebar menu. 
3. Under **File Manager**, open the **httpdocs** directory. This is the document root for your main domain, so anything you place here is served on your website. If you are uploading to a subdomain or an additional domain, open its own document root folder instead. 
4. Click the **plus (+)** icon and choose **Upload**. Then select the file you want to upload from your computer. 
5. Click **Open**. The file uploads into the folder you are currently viewing and appears in the list once it has finished.
Your file has now been uploaded and, if it sits in the document root, is live on your website.
## Good to Know
- **You can upload several files at once.** In the file selection window, hold down the `Ctrl` key (or `Cmd` on a Mac) and click each file you want, then click **Open** to upload them together.
- **Uploading a file with an existing name replaces it.** Plesk overwrites the current file without keeping a copy, so double-check the name before you upload if you do not want to lose the old version.
- **For a whole website or many files, upload a single archive.** Compress the files into a `.zip` on your computer, upload that one archive, then select it in the File Manager and use **Extract Files**. This is far faster and more reliable than uploading hundreds of files one by one.
- **Very large files may hit the upload limit.** Browser-based uploads are capped by the web server and PHP settings on the account. If a large file fails to upload through the File Manager, use an SFTP or FTP client instead, which has no such browser limit.
## Troubleshooting
**The file uploaded but does not show on your website:** confirm it is in the correct document root (**httpdocs** for your main domain) and that the file name and extension are exactly what your site expects. Browsers also cache pages, so clear your cache or open the page in a private window to see the latest version.
**The upload fails or stalls on a large file:** this is usually the upload size limit. Try an SFTP or FTP client, or upload the content as a compressed archive and extract it in place.
If you are on a Noiz managed hosting plan, or you would like a hand getting your files in place, contact the Noiz support team through the client area and they will take care of it for you.
# Outlook IMAP Login Fails with Correct Password (DIGEST-MD5 on Plesk)
Source: https://docs.noiz.ie/plesk/outlook-imap-login-fails-with-correct-password-digest-md5-on-plesk/
## Summary
Some Microsoft Outlook clients (for example Office 2021 and Office 2024 LTS) fail to log in to a mailbox over **IMAP** even though the password is correct. Outlook shows a "check your credentials" or "cannot connect" error, yet webmail and Thunderbird sign in to the same mailbox without trouble. The cause is not the password: the mail server is advertising the legacy `DIGEST-MD5` authentication mechanism, Outlook tries it first, and it fails without reliably falling back to a mechanism that works.
This guide shows you how to confirm the diagnosis from the mail log and how to remove the offending mechanism cleanly on a Noiz Plesk mail server. The same fix applies to the matching SMTP submission errors, because Plesk uses Dovecot for SASL authentication.
**Last reviewed:** 27 July 2026, against Dovecot **2.3.x** as shipped with Plesk (current stable in the Plesk repositories). This guide is written for Noiz hosting and is kept current against Dovecot and Plesk. It complements, and does not replace, the official Dovecot documentation linked below.
### Official Documentation Reference
- [Dovecot: Authentication Mechanisms](https://doc.dovecot.org/configuration_manual/authentication/authentication_mechanisms/) (what `plain`, `login`, `digest-md5`, `cram-md5` and `apop` are)
- [Dovecot: Core settings reference](https://doc.dovecot.org/settings/core/) (the `auth_mechanisms` setting)
## Prerequisites
- Root (or `sudo`) SSH access to the Noiz Plesk mail server. This is a server-wide change, so it is normally carried out by Noiz support rather than from the client area.
- The affected mailbox address, so you can filter the log for it.
- All commands below assume Plesk on Debian, where the mail log is `/var/log/maillog`. On some builds it is `/var/log/mail.log`.
Throughout, replace `user@yourdomain.com` with the affected mailbox and `mail.yourdomain.com` with the mail host. These are examples to substitute, not literal values.
## Why Outlook fails when Thunderbird and webmail work
When a client connects, the server advertises a list of authentication mechanisms it will accept. Outlook picks `DIGEST-MD5` from that list before it tries anything else, and its DIGEST-MD5 implementation does not interoperate cleanly with Dovecot. Instead of falling back to `PLAIN` over the already-encrypted TLS connection, Outlook reports a credentials failure. Thunderbird and webmail go straight to `PLAIN` or `LOGIN` over TLS, so they are never exposed to the broken path. That is why the same, correct password works everywhere except Outlook.
## Diagnosis
### 1) Show all IMAP authentication activity for the user
```
grep -F "imap-login" /var/log/maillog | grep -F "user="
```
Compare failures against successes and look for the `method=` field on each line.
### 2) Highlight only the failing attempts
```
grep -F "imap-login" /var/log/maillog | grep -F "user=" | grep -i "auth failed"
```
A typical failing line looks like this:
```
dovecot: imap-login: Disconnected: Connection closed (auth failed, 1 attempts ...): user=, method=DIGEST-MD5, ...
```
### 3) Summarise which mechanisms are being attempted
```
grep -F "imap-login" /var/log/maillog | grep -F "user=" | grep -o "method=[^,)]*" | sort | uniq -c
```
If you see a count for `method=DIGEST-MD5` alongside a working `method=PLAIN`, the Outlook/DIGEST-MD5 problem is confirmed.
### 4) Watch the log live while the user retries from Outlook
```
tail -f /var/log/maillog | grep -F "user="
```
### 5) Confirm what the server currently advertises
```
doveconf -n | grep -i "^auth_mechanisms"
```
On a stock Plesk build this typically returns a list that still includes the legacy mechanisms, which is what triggers Outlook's bad path:
```
auth_mechanisms = plain login digest-md5 cram-md5 apop
```
## Resolution
The fix is to restrict Dovecot to the modern mechanisms that Outlook, Thunderbird and webmail all use safely over TLS: `plain` and `login`. Do this with an override drop-in file so a future Plesk update to the default Dovecot configuration does not clash with your change.
### 1) Create an override drop-in
Write a file in `/etc/dovecot/conf.d/` whose name sorts **after** Plesk's own auth configuration. Dovecot reads the files in this directory in alphabetical order and the **last** assignment of a setting wins, so a high-numbered prefix such as `99-` is what guarantees your value overrides the default. A `00-` prefix would load first and could be silently overwritten by Plesk's own `10-auth.conf`.
```
echo "auth_mechanisms = plain login" > /etc/dovecot/conf.d/99-noiz-auth-mechanisms.conf
```
Do not edit the Plesk-managed default files directly; a package update can replace them and undo your change. The drop-in keeps the override out of harm's way.
### 2) Reload Dovecot
```
systemctl reload dovecot
# or, if reload does not pick up the change:
systemctl restart dovecot
```
Existing sessions are unaffected; new logins use the restricted list.
### 3) Confirm the change took effect
```
doveconf -n | grep -i "^auth_mechanisms"
```
Expected output:
```
auth_mechanisms = plain login
```
This step is the real proof. If the line still shows `digest-md5`, your drop-in did not win the ordering. Rename it to a later-sorting name (a higher number prefix) and reload again.
### 4) Optionally verify the advertised capabilities over TLS
```
openssl s_client -connect mail.yourdomain.com:993 -crlf
a CAPABILITY
b LOGOUT
```
The pre-authentication capability line should no longer advertise `AUTH=DIGEST-MD5`.
### 5) Retest Outlook
Ask the user to retry. Outlook should now authenticate using `PLAIN` over TLS and connect normally. No client-side reconfiguration is needed.
## Notes and context
- This is a server-wide change affecting every mailbox on the host, for both IMAP/POP (Dovecot) and SMTP submission. Because Plesk uses Dovecot for SMTP SASL, submission errors that mentioned `DIGEST-MD5` also disappear once the override is in place.
- Using `PLAIN` or `LOGIN` over TLS is the recommended modern approach. The credentials are protected by the TLS session, so there is no security downgrade in dropping the challenge-response mechanisms. The legacy `DIGEST-MD5`, `CRAM-MD5` and `APOP` mechanisms are obsolete and are the source of the Outlook interoperability problem.
- Recent Dovecot releases (2.4 and later) have removed `DIGEST-MD5` and other legacy mechanisms entirely. If a future Plesk update moves the server onto Dovecot 2.4 or newer, this failure can no longer occur and the override simply becomes redundant, not harmful.
## Troubleshooting
- **doveconf still shows digest-md5 after reload**: the drop-in file is being overridden. Confirm it sorts alphabetically after every other file in `/etc/dovecot/conf.d/` that sets `auth_mechanisms` (use a higher number prefix), then reload Dovecot again.
- **Outlook still fails after the change**: this points to a different cause. Rerun the diagnosis in step 3 and check the `method=` now being used. If `method=PLAIN` is failing, the password really is wrong or the mailbox is locked; if Outlook cannot connect at all, check the client is using SSL/TLS on port 993 for IMAP and 465 for SMTP.
- **No lines match in the log**: the user may be connecting to a different server, or the log path is `/var/log/mail.log` on this build. Confirm the mail host against the account settings first.
## Need Noiz to make this change?
This override is applied at server level, so it is not something you can set from the client area. If your Outlook clients are hitting this DIGEST-MD5 login failure on Noiz hosting, open a ticket from your [Noiz client area](https://www.noiz.co.za/clientarea.php) with the affected mailbox address and Noiz support will apply and verify the fix on the mail server for you.
# Plesk Backup Overview
Source: https://docs.noiz.ie/plesk/plesk-backup-overview/
Backups are one of the most important safeguards for your websites, mail, and databases. Plesk includes flexible backup tools that let you create on-demand snapshots, set up automatic schedules, and store your backups either locally on the server or remotely on external storage. This overview explains the options at a glance and points you to the step-by-step guide for each storage method.
This article is for Plesk subscription owners on Noiz hosting who want to understand how Plesk backups work before configuring one. On Noiz, Plesk runs on the `neo.noiz.co.za` platform, and every subscription includes its own backup manager inside the control panel.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below.
### Official Documentation Reference
- [Plesk Customer Guide: Backing Up and Restoring Data](https://docs.plesk.com/en-US/obsidian/customer-guide/backing-up-and-restoring-data.73349/)
- [Plesk Customer Guide: Using Remote Storage](https://docs.plesk.com/en-US/obsidian/customer-guide/backing-up-and-restoring-data/using-remote-storage.73351/)
## Why Backups Matter
- Protects against accidental file deletion or corruption
- Helps you recover quickly from software errors or a failed update
- Provides a fallback in case of server or hardware failure
- Supports good practice for security and disaster recovery
A backup is only useful if it exists *before* something goes wrong, so the goal is to have a recent copy ready at all times, kept somewhere that survives the event you are recovering from.
## Backup Types in Plesk
Plesk supports two main backup types:
- **Full backups**: include all selected data, meaning configuration, files, mail, and databases.
- **Incremental backups**: include only the changes since the last full backup, which saves space and time. Databases are always backed up in full, even in an incremental job.
You can also choose **what** each backup contains. A backup can cover configuration only, configuration plus mail, or the whole subscription including web content and databases. Backing up configuration only produces a much smaller file and is handy before you make a settings change you might want to undo.
## On-Demand and Scheduled Backups
- **On-demand backups** run once, when you click to create them. Use these before a risky change such as a plugin update, a theme swap, or a PHP version change.
- **Scheduled backups** run automatically on a repeating schedule (for example nightly or weekly) and are the safety net you rely on day to day. Plesk lets you set how many copies to keep so that older backups are pruned automatically.
## Backup Storage Options
You can choose where Plesk stores your backups:
- **Local backups**: stored on the same server where your Plesk subscription runs.
- **Remote backups**: stored off-site for greater resilience, using one of the following methods:
- **FTP(S) storage**: connect to your own remote FTP or FTPS server.
- **SFTP storage**: connect to your own remote SFTP server (secure and encrypted).
- **Dropbox storage**: connect to your Dropbox account.
**Important:** local backups are stored on the same server and count towards your subscription's disk usage. If the server itself fails, a local-only backup can be lost along with the live data it was meant to protect. For true disaster recovery, keep at least one copy in remote storage that is independent of the hosting server. FTPS and SFTP both encrypt the transfer, so prefer them over plain FTP when your remote server supports them.
## Guides for Configuring Backups
- [How to Configure Local Backups in Plesk for a Subscription](/plesk/how-to-configure-local-backups-in-plesk-for-a-subscription/)
- [How to Configure Remote Backups in Plesk Using FTP(S) Storage](/plesk/how-to-configure-remote-backups-in-plesk-using-ftps-storage/)
- [How to Configure Remote Backups in Plesk Using SFTP Storage](/plesk/how-to-configure-remote-backups-in-plesk-using-sftp-storage/)
- [How to Configure Remote Backups in Plesk Using Dropbox Storage](/plesk/how-to-configure-remote-backups-in-plesk-using-dropbox-storage/)
## Best Practices for Using Backups
- Keep a regular schedule that fits how often your content changes.
- Use both local and remote backups for redundancy, keeping the remote copy off the hosting server.
- Test a restore from your backups periodically so you know they actually work when you need them.
- Keep an eye on available storage space, both locally (against your disk quota) and on your remote target.
- Set a sensible retention count so old backups are pruned and do not fill your storage.
With these tools and practices, you can be confident your websites, mail, and databases are protected against unexpected events.
## Need a Hand?
If you are on a Noiz managed plan, or you are unsure which backup strategy fits your subscription, the Noiz support team can help you set up and verify your backups. Open a ticket from your client area and the team will guide you through it.
# Why Plesk System Mail (MAILER-DAEMON, root) Goes to Spam and How to Fix It
Source: https://docs.noiz.ie/plesk/why-plesk-system-mail-mailer-daemon-root-goes-to-spam-and-how-to-fix-it/
## Overview
System mails generated by your Plesk server, such as bounce notices from `MAILER-DAEMON@hostname.example.com`, cron output from `root@hostname.example.com`, or Plesk notifications, often land in the spam folder, even though normal user mailboxes (e.g. `info@example.com`) deliver fine.
This happens because your server's hostname is a subdomain of your main domain, and your main domain's DMARC policy is silently inherited by every subdomain that does not publish its own. Without dedicated authentication for the hostname, self-generated system mail fails DMARC alignment and is quarantined by your own authentication stack.
This article walks through the root cause, the one-DNS-record fix that solves the visible symptom for most admins, and the full authentication setup for getting non-bounce system mail to genuinely pass DMARC.
**Last reviewed:** 27 July 2026, against Plesk Obsidian **18.0** (latest stable line). This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk and standards documentation linked below.
### Official Documentation Reference
- [Plesk Obsidian Administrator Guide: DKIM, SPF, and DMARC Protection and ARC Support](https://docs.plesk.com/en-US/obsidian/administrator-guide/mail/antispam-tools/dkim-spf-and-dmarc-protection-and-arc-support.59433/)
- [RFC 7489: Domain-based Message Authentication, Reporting, and Conformance (DMARC)](https://datatracker.ietf.org/doc/html/rfc7489)
- [RFC 6376: DomainKeys Identified Mail (DKIM) Signatures](https://datatracker.ietf.org/doc/html/rfc6376)
- [RFC 7208: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email](https://datatracker.ietf.org/doc/html/rfc7208)
- [RFC 5321 ยง4.5.5: the SMTP null reverse-path used by bounce messages](https://datatracker.ietf.org/doc/html/rfc5321#section-4.5.5)
## Prerequisites
- Administrator access to your Plesk server (needed only for the complete fix, not the quick fix).
- The ability to publish TXT records in the authoritative DNS for your domain (the Noiz DNS zone, Cloudflare, or your registrar).
- Your server hostname and its public IPv4 and IPv6 addresses.
## Why it happens: subdomain DMARC inheritance
Your server has a hostname like `hostname.example.com`. When Postfix generates mail from MAILER-DAEMON, cron, or Plesk itself, it uses that hostname in the `From:` header, producing addresses like `MAILER-DAEMON@hostname.example.com` or `root@hostname.example.com`.
If your apex domain `example.com` has a DMARC record with a strict policy (`p=quarantine` or `p=reject`) and no explicit subdomain policy override (`sp=` tag), RFC 7489 specifies that the apex `p=` policy is inherited by every subdomain that lacks its own DMARC record. Your server's hostname inherits the strict policy, even though there is no DKIM key or dedicated SPF for the hostname, and even though self-generated bounces cannot pass SPF or DKIM alignment in a default Plesk setup.
Your own server's mail gets quarantined by your own authentication stack.
## Why bounces can never pass DMARC in a default setup
Before the fix, one technical point that most guides get wrong:
Bounces generated by Postfix use a null envelope sender (`<>`), per RFC 5321 ยง4.5.5. DMARC evaluation (RFC 7489 ยง3.1.1) derives its SPF-authenticated identifier from the RFC5321.MailFrom domain, not the HELO identity. With a null MailFrom there is no SPF identifier to align against the `From:` header, so SPF alignment is impossible no matter what SPF record you publish for the hostname.
In a default Plesk setup, Postfix-generated bounces are also not DKIM-signed.
The combination of these two facts means bounces produce `dmarc=fail` every time. The question receivers face is not whether to pass or fail, but what *action* to take on the failure. If the DMARC policy is strict, the mail is quarantined. If the policy is permissive (`p=none`), it is delivered normally.
## The quick fix: override subdomain inheritance
Add a dedicated DMARC record for your server hostname with `p=none`:
```
_dmarc.hostname.example.com. IN TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com"
```
This overrides apex inheritance for the hostname subdomain only. Your main domain DMARC policy stays strict, your user mailboxes stay protected, but system mail from the hostname stops being quarantined.
This single record solves the symptom for most admins. No Plesk changes are required. No server configuration is required.
Verify the record is live:
```
dig +short TXT _dmarc.hostname.example.com
```
If you also want cron output and Plesk notifications (not just bounces) to *genuinely* pass DMARC, continue to the complete fix below. If you just want your system mail out of spam, you can stop here.
## The complete fix: authenticate non-bounce system mail
The quick fix makes bounces deliverable, but they still technically fail DMARC (with action "none"). For non-bounce system mail (cron job output, Plesk notifications, and anything else sent from `root@hostname` or similar), the mail has a real envelope sender and *can* pass DMARC. Treating the hostname as a first-class mail domain with its own DKIM key and SPF record gets these messages properly authenticated.
### Step 1: Add the hostname as a Plesk domain
1. In Plesk, go to **Websites & Domains โ Add Domain โ Add Domain Without Hosting**.
2. Enter your server hostname (e.g. `hostname.example.com`).
3. Enable the **Mail service**. Do **not** enable web hosting.
4. If your authoritative DNS is external (the Noiz DNS zone, Cloudflare, your registrar, etc.), disable Plesk's local DNS service for this domain. You will copy the TXT records manually.
5. Do not create any mailboxes and do not enable incoming mail. You only need Plesk to recognise the hostname as a managed mail domain so it can generate a DKIM keypair.
### Step 2: Enable DKIM for the hostname
In the hostname domain's **Mail Settings**, enable *Use DKIM spam protection system to sign outgoing email messages*.
Plesk generates the keypair under `/etc/domainkeys/` and displays the public DKIM TXT record in **DNS Settings**. Copy it to your authoritative DNS:
```
default._domainkey.hostname.example.com. TXT "v=DKIM1; p=MII..."
```
### Step 3: Publish SPF for the hostname
Also in your authoritative DNS:
```
hostname.example.com. TXT "v=spf1 ip4:your.server.ipv4 ip6:your:server::ipv6 -all"
```
This authorises the server itself to send mail on behalf of the hostname.
### Step 4: Leave the hostname DMARC at p=none
Keep the hostname DMARC record at `p=none` permanently:
```
_dmarc.hostname.example.com. TXT "v=DMARC1; p=none; rua=mailto:dmarc-reports@example.com; fo=1"
```
Even after DKIM and SPF are live, bounces from the hostname cannot align SPF (null envelope) and DKIM signing of Postfix bounces is not guaranteed across every Plesk configuration. Keeping `p=none` on the hostname ensures bounces still reach your inbox. The downside is minimal: no user mailboxes live at `@hostname.example.com`, so there is little phishing surface to protect.
## Testing
Verify all records are live:
```
dig +short TXT hostname.example.com
dig +short TXT default._domainkey.hostname.example.com
dig +short TXT _dmarc.hostname.example.com
```
Trigger a real bounce to confirm the quick fix is working. Sending to a non-existent external domain reliably generates a bounce back to the sender:
```
sendmail -f youraccount@example.com test@nonexistent-test-domain-xyz.invalid <`). There is nothing for SPF to align against. The SPF record is useful for non-bounce mail from the hostname but cannot help bounces.
### Do I need to enable web hosting for the hostname domain?
No. Set it to "No web hosting" when adding the domain. Web hosting is unnecessary and can cause SSL conflicts if the apex domain points elsewhere.
### Should I enable incoming mail on the hostname domain?
No. In almost all cases you do not want to accept mail at `@hostname.example.com`. Leaving incoming mail disabled avoids creating mailboxes for the hostname. Outgoing system mail will still send correctly.
### Does disabling Plesk's local DNS for the hostname break anything?
No, as long as your authoritative DNS is managed externally (the Noiz DNS zone, Cloudflare, your registrar, etc.) and you publish the SPF, DKIM, and DMARC records there manually. If Plesk is your authoritative DNS, leave its local zone enabled so Plesk can publish the records automatically.
### Which SSL certificate is used for mail?
The SSL certificate bound to the server hostname (`hostname.example.com`) is the one used by Postfix and Dovecot for SMTP, IMAPS, and POP3S. Keep Let's Encrypt enabled for the hostname. Certificates bound to your main domain's web hosting do not affect mail delivery.
### Can I tighten the hostname DMARC policy once everything is authenticated?
Not safely. Bounces from the hostname cannot align SPF, and DKIM signing of bounces is not guaranteed across Plesk configurations. Tightening the hostname DMARC policy risks re-quarantining your own bounces. Leave it at `p=none` permanently.
### Why do some system mails still land in spam even after full authentication?
Addresses like `root@` and `MAILER-DAEMON@` are historically abused and treated with low trust regardless of authentication status. Passing SPF, DKIM, and DMARC establishes the foundation, but inbox placement also depends on domain and sender reputation. Aliasing system mail to a trusted mailbox (see above) is the most effective mitigation.
## Conclusion
Plesk's default advice to "change the From field" on notifications only masks the symptom. The proper fix is layered:
1. **Publish a permissive DMARC record for your server hostname** to override the apex subdomain-inheritance rule. This alone solves the visible symptom.
2. **For non-bounce system mail, add the hostname as a Plesk mail domain and enable DKIM**, so cron output and Plesk notifications genuinely pass DMARC.
3. **Alias `root` to a trusted mailbox on your main domain** to sidestep the historically low reputation of system-mail addresses.
Bounces from the hostname will always fail DMARC by design in a default Plesk setup. The goal is not to make them pass. It is to ensure the DMARC action for the hostname is "none", so legitimate bounces reach your inbox.
Noiz manages the mail authentication stack on its Plesk hosting. If your site is on a Noiz managed plan and system mail is still landing in spam after applying the quick fix, open a support ticket from the client area and the Noiz team will review the hostname's DNS, SPF, and DKIM configuration for you.
# How to Access Email from cPanel Webmail
Source: https://docs.noiz.ie/cpanel/how-to-access-email-from-cpanel-webmail/
Webmail lets you read and send email straight from a browser, without setting up a mail app on your device. This guide shows you how to open cPanel Webmail for any email address on your hosting account, sign in, and start reading your mail.
**Last reviewed:** 27 July 2026, against current cPanel & WHM (v108 and later, which ships **Roundcube** as the webmail application). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [The Webmail Interface](https://docs.cpanel.net/webmail/the-webmail-interface/)
- [Webmail Clients (Roundcube)](https://docs.cpanel.net/webmail/webmail-clients/)
- [cPanel Email Accounts](https://docs.cpanel.net/cpanel/email/email-accounts/)
## Prerequisites
- An email address already created on your cPanel hosting account.
- The full email address (for example `you@yourdomain.com`) and its password. Webmail uses the address as the username, not just the part before the @.
## Ways to Open Webmail
You can reach the Webmail login page in any of these ways. Replace `yourdomain.com` with your own domain.
- Go to `https://yourdomain.com/webmail` in your browser.
- Go to `https://webmail.yourdomain.com`.
- If your domain is not yet pointed at Noiz, browse to the server directly on the secure Webmail port: `https://your-server-hostname:2096`. Ask Noiz support for the correct hostname if you are unsure.
- If you are already signed in to cPanel, open **Email Accounts**, find the address, and click **Check Email**.
## Sign In and Read Your Mail
1. Open one of the addresses above. At the login page, enter your **full email address** in the username field and your **password**, then click **Log in**. 
2. After you sign in, cPanel opens the webmail application. On current cPanel servers this is **Roundcube**, the modern webmail client that ships with cPanel. If a chooser appears, click **Open** under Roundcube to start reading your mail. 
Roundcube gives you a full inbox: read, reply, compose, manage folders, and search. Your webmail changes stay in sync with any mail app you also use on the same account, because both read the same mailbox on the server.
## Skip the Chooser Next Time
If you would rather land in your inbox immediately instead of seeing the application page each time, set Roundcube as your default. From the Webmail interface, open the account menu (top right, shown by your email address) and choose **Set as Default** for Roundcube, or tick the option to open the default application automatically. After that, signing in takes you straight to your inbox.
## Troubleshooting
- **Login fails with correct password**: make sure you entered the *full* email address as the username, including the domain after the @. Passwords are case-sensitive.
- **Only Roundcube is offered, no Horde**: this is expected. Horde was retired from cPanel and no longer ships with current versions, so Roundcube is the webmail client on your account.
- **Browser warns the connection is not private on port 2096**: this happens when you reach the server by its raw hostname before your own domain's certificate applies. Continue, or use `https://yourdomain.com/webmail` once your domain points at the server.
- **The Webmail page will not load**: confirm your domain resolves to your Noiz hosting and that you are using `https://`. If it still fails, contact Noiz support.
If you get stuck, Noiz support can confirm your mailbox settings and the correct server hostname for your account. Open a ticket from your client area and include the email address you are trying to reach.
# How to Access cPanel Web Disk
Source: https://docs.noiz.ie/cpanel/how-to-access-cpanel-web-disk/
Web Disk lets you open the files in your hosting account as if they were a folder on your own computer. It uses the WebDAV standard, so once it is set up you can drag files into your website, open a document straight from the server, and save it back without touching an FTP client or the cPanel File Manager. cPanel provides a small configuration script that sets the connection up for you, and this guide shows you how to download and run it, how to connect manually if you prefer, and what to check when the connection refuses to mount.
Your **Main Web Disk Account** is created automatically with your hosting account. It uses your cPanel username and password and it can reach your entire home directory. If you need to give someone access to a single folder instead, create a restricted account first, as described in [How to Create an Additional Web Disk Account in cPanel](/cpanel/how-to-create-an-additional-web-disk-account-in-cpanel/).
**Last reviewed:** 27 July 2026, against the current cPanel **Jupiter** interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: Web Disk](https://docs.cpanel.net/cpanel/files/web-disk/)
- [cPanel Documentation: File Manager](https://docs.cpanel.net/cpanel/files/file-manager/)
## Prerequisites
- An active Noiz cPanel hosting account and your cPanel login details.
- Permission to run a downloaded script on your computer. On a managed work laptop you may need your IT administrator to allow this.
- Outbound access to port `2078` (secure) or `2077` (insecure) from your network. Some corporate and public Wi-Fi networks block both.
## Open Web Disk in cPanel
1. Log in to your cPanel account.
2. In the **Files** section, click **Web Disk**.

3. Under **Main Web Disk Account**, click **Configure Client Access**.

## Download and Run the Configuration Script
1. Select your operating system from the drop-down menu, then click **Download Configuration Script**. cPanel builds a script that already contains the correct server address, port and account name, so there is nothing for you to type in.

2. Open the downloaded script. It can take a minute or two to finish, because the operating system has to reach the server and negotiate the connection before it will show you anything.
3. When you are prompted, enter your Web Disk username and password. For the main account this is your cPanel username and password. For a restricted account it is the full username, including the domain.

Once authentication succeeds, your hosting account appears as a mapped drive on Windows, a mounted volume in Finder on macOS, or a network location on Linux. Your website files live under `public_html`.
## Connect Manually Instead
The script is only a convenience. If it will not run on your machine, or you want to add the connection to a different device, you can set it up by hand with these details:
- **Address:** `https://yourdomain.com:2078` for a secure connection, or `http://yourdomain.com:2077` for an insecure one. Replace `yourdomain.com` with your own domain.
- **Username:** Your cPanel username for the main account, or the full `user@yourdomain.com` username for a restricted account.
- **Password:** The matching account password.
On Windows, use **Map network drive** in File Explorer and tick **Connect using different credentials**. On macOS, use **Go** then **Connect to Server** in Finder. On Linux, most file managers accept a `davs://` address in their **Connect to Server** box.
Always prefer the secure option. On port `2077` your username and password cross the network unencrypted, and so does every file you open.
## Windows Notes
- **Use the SSL script.** Modern versions of Windows refuse to send credentials over an unencrypted WebDAV connection by default, so the secure option on port `2078` is the one that works without extra fiddling.
- **Digest Authentication.** Older Windows clients connecting without SSL need **Digest Authentication** enabled on the Web Disk account. The option, when your cPanel version offers it, sits on the same **Web Disk** page. If you cannot see it, use the secure script instead rather than hunting for it.
- **The WebClient service.** Windows mounts WebDAV through a service called **WebClient**. If it is disabled, the mapped drive silently fails to appear. Set it to **Automatic** in **Services** if you hit that.
- **The file size limit.** Windows caps WebDAV transfers at roughly 50 MB out of the box, which is the most common reason a large upload fails halfway with a vague error. Use FTP, SFTP or the cPanel File Manager for anything bigger, or raise the limit in the registry if your IT policy allows it.
- **Firewall.** Port `2078` must be allowed outbound in your computer's firewall and on your network.
## Understand What Web Disk Is Not
Web Disk is a live network connection, not a sync tool. Nothing is stored on your computer, so every file you open is pulled across the internet at that moment and every save is pushed straight back. That has two practical consequences worth knowing before you rely on it:
- Working directly on large files, or on a folder with thousands of items, feels slow compared with a local disk. Copy the file down, work on it, then copy it back.
- There is no offline copy and no version history. Deleting a file over Web Disk deletes it on the server. Keep your own backups, and take a copy before editing anything on a live site.
## Troubleshooting
- **The script runs but nothing appears**: On Windows, check that the **WebClient** service is running. On macOS, look in Finder under **Locations** in the sidebar rather than on the desktop.
- **The login prompt keeps reappearing**: The password is being rejected. For a restricted account you must enter the full username including the domain, for example `user@yourdomain.com`. If you have recently changed your cPanel password, the main Web Disk account uses the new one.
- **Connection times out**: Port `2077` or `2078` is blocked. Test from a different network, such as a mobile hotspot, to confirm. Corporate networks frequently block non-standard ports.
- **Certificate warning on connecting**: You are connecting to a hostname the certificate does not cover. Use the exact address the configuration script generated, or connect to the server hostname from your Noiz welcome email.
- **Large uploads fail**: See the Windows file size limit above. This is a client-side limit, not a limit on your hosting account.
- **Files upload but the website does not change**: Check where you saved them. Web Disk opens at your home directory, and website files must go into `public_html` or the correct subfolder beneath it.
## Related Articles
- [How to Create an Additional Web Disk Account in cPanel](/cpanel/how-to-create-an-additional-web-disk-account-in-cpanel/)
If the connection will not mount, or you are not sure whether your network allows the required ports, open a ticket from your Noiz client area with your operating system and the exact error message. The Noiz support team will confirm the settings from the server side and help you get connected.
# How to Add a CNAME Record in cPanel Zone Editor
Source: https://docs.noiz.ie/cpanel/how-to-add-a-cname-record-in-cpanel-zone-editor/
A **CNAME** (Canonical Name) record is a DNS alias. It tells the internet that one hostname is really just another name for a different hostname, and that resolvers should go and look up that other name instead. CNAME records are how you point `www.yourdomain.com` at your main site, hand a subdomain over to a third-party service such as a help desk or status page, or satisfy a vendor's domain-verification requirement.
This guide shows you how to add a CNAME record in the cPanel **Zone Editor**, what to type into each field, and the rules that cause most CNAME records to silently fail. Replace `yourdomain.com` throughout with your own domain name.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the current STABLE and LTS tier). This guide is written for Noiz hosting customers and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Zone Editor](https://docs.cpanel.net/cpanel/domains/zone-editor/) (full interface reference)
- [CNAME record type reference](https://docs.cpanel.net/cpanel/domains/zone-editor/#cname)
- [The ALIAS DNS record](https://docs.cpanel.net/knowledge-base/dns/the-alias-dns-record/) (what to use when a CNAME is not legal)
- [RFC 1912: Common DNS Operational and Configuration Errors](https://www.rfc-editor.org/rfc/rfc1912)
## Prerequisites
- Your cPanel username and password.
- The exact target hostname supplied by whoever you are pointing the record at. A CNAME target is always a hostname, never an IP address.
- Confirmation that the cPanel server is authoritative for the domain. See the section below, because this is the single most common reason a correctly typed CNAME record does nothing.
## First, Check That cPanel Actually Controls the Zone
The Zone Editor edits the DNS zone file stored on the cPanel server. Those edits only reach the wider internet if the domain's nameservers are the cPanel server's nameservers. If the domain's nameservers point somewhere else, the zone file you are editing is ignored and nothing changes in public DNS.
Check your nameservers at your domain registrar, or from a terminal:
```
dig NS yourdomain.com +short
```
If the answer is a set of nameservers belonging to the cPanel server, carry on. If the answer is a DNS provider such as a CDN, a registrar's own DNS, or the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za`, then the CNAME record must be created there instead, and editing the cPanel zone will have no effect at all.
## Adding a CNAME Record
### 1. Log in to cPanel
Sign in to your cPanel account.
### 2. Open the Zone Editor
In the **Domains** section of the cPanel home screen, click **Zone Editor**. If you cannot see it, type `zone` into the search box at the top of the page.

### 3. Find your domain in the list
The Zone Editor lists every domain and subdomain on the account. Each row carries quick-add buttons under **Actions** for the record types people add most often, plus a **Manage** button that opens the full record list for that zone.

Make sure you are working on the correct row. If the account holds several domains, a CNAME added to the wrong zone will appear to succeed and then do nothing useful.
### 4. Click CNAME Record and fill in the two fields
Click **CNAME Record** on your domain's row. A small dialogue box opens with two fields.

- **Name:** the alias you are creating, entered as the short label only. Type `www` and cPanel stores it as `www.yourdomain.com.` for you. Do not type `www.yourdomain.com` here, because cPanel appends the zone name again and you end up with the broken record `www.yourdomain.com.yourdomain.com.`
- **CNAME:** the destination hostname, entered fully qualified and ending with a full stop, for example `yourdomain.com.` or `ghs.googlehosted.com.` The trailing full stop is what stops cPanel treating the value as relative to your zone. An IP address is not valid here.
### 5. Save the record
Click **Add A CNAME Record**. A green confirmation message appears at the top of the page when the zone has been written successfully.
Click **Manage** on the same domain and check the stored record. This takes five seconds and catches the trailing-full-stop mistake immediately: a target that reads `ghs.googlehosted.com.yourdomain.com.` is wrong and needs editing.
## CNAME Rules That Catch People Out
- **A CNAME must be the only record at that name.** This is a hard rule of the DNS specification, not a cPanel limitation. If `www` already has an A record, you must delete the A record before the CNAME can work. Leaving both in place produces inconsistent results depending on which resolver a visitor uses.
- **Never put a CNAME on the bare domain.** Your root domain `yourdomain.com` already carries the mandatory SOA, NS and usually MX records, so a CNAME there is illegal and will break your email. If a provider asks you to point the root domain at a hostname, use cPanel's **ALIAS** record type instead, available under **Manage** then **Add Record**.
- **A CNAME cannot point to an IP address.** If all you have been given is an IP, you need an A record (IPv4) or AAAA record (IPv6).
- **Subdomains created in cPanel already have an A record.** If you created `shop.yourdomain.com` as a subdomain and now want to point it at an external service, remove or edit the existing record rather than stacking a CNAME on top of it.
- **Pointing a hostname off the server breaks its SSL certificate issuance.** Once a subdomain resolves elsewhere, the cPanel server can no longer prove control of it, so AutoSSL will stop renewing that name. The destination service becomes responsible for serving a valid certificate.
- **Chained CNAMEs are legal but slow.** A CNAME pointing at another CNAME resolves, but every hop is an extra lookup. Point at the final hostname where you can.
## Verifying the Record
Query the record directly rather than trusting a browser, which caches aggressively:
```
dig CNAME www.yourdomain.com +short
nslookup -type=cname www.yourdomain.com
```
To confirm the change reached the authoritative server before caches expire, ask that server directly:
```
dig CNAME www.yourdomain.com @ns1.yourdomain-nameserver.tld +short
```
If the authoritative server returns the new value but public resolvers do not, the record is correct and you are simply waiting on caching.
## TTL and Propagation
Propagation is not a delay in publishing your change. The change is live on the authoritative nameserver the moment cPanel confirms it. What takes time is the expiry of the **old** answer that resolvers around the world cached before you made the change, and that period is governed by the TTL that record had previously.
The quick-add dialogue box does not expose a TTL field, so a new record inherits the zone default, commonly 14400 seconds (4 hours). To set a shorter TTL, open **Manage**, edit the record and adjust the value.
Practical guidance: if you know a change is coming, drop the TTL on the existing record to 300 seconds a day beforehand, then make the change and restore a sensible TTL afterwards. For a brand new name that has never been queried, the record is usually usable within minutes. In the worst case, allow up to 24 hours, because a minority of networks and devices hold cached answers longer than the TTL asks them to.
## Troubleshooting
- **Symptom: the record saves but public DNS never changes.** The domain's nameservers are not the cPanel server's nameservers. Run `dig NS yourdomain.com +short` and make the change wherever those nameservers are hosted.
- **Symptom: cPanel refuses to save, or reports a conflict.** Another record already exists for that exact name. Open **Manage**, delete or edit the conflicting A, AAAA or TXT record, then add the CNAME.
- **Symptom: the destination reads yourtarget.com.yourdomain.com.** The trailing full stop was missing from the **CNAME** field. Edit the record and re-enter the target ending in a full stop.
- **Symptom: email stopped working after the change.** A CNAME was added at a name that also carries MX records, most likely the bare domain. Delete it and use an ALIAS record or an A record instead.
- **Symptom: the browser still shows the old site.** Test with `dig` first. If DNS is correct, clear the browser cache and flush the local resolver cache before assuming the record is wrong.
- **Symptom: certificate warnings on the new hostname.** The name now resolves to a third-party service, so that service must issue the certificate. Complete its SSL setup, and expect AutoSSL on the cPanel server to stop covering the name.
## Need a Hand?
DNS is unforgiving about detail, and a single misplaced full stop can take a site or a mailbox offline. If a CNAME is not behaving as expected, or you are not sure whether a change belongs in cPanel or at your DNS provider, open a ticket from the Noiz client area with the domain name and the exact record you are trying to create. The Noiz support team will confirm where the zone is authoritative and make the change with you.
# How to Add a User to a MySQL Database in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-add-a-user-to-a-mysql-database-in-cpanel/
Creating a MySQL database and creating a database user are two separate steps in cPanel. A new user has no access to any database until you explicitly grant it. This guide shows you how to add an existing user to a database and assign the privileges that let the user read and write data.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable release, Jupiter theme). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: MySQL Databases](https://docs.cpanel.net/cpanel/databases/mysql-databases/)
- [cPanel Documentation: Manage MySQL Database Users](https://docs.cpanel.net/cpanel/databases/manage-mysql-database-users/)
## Prerequisites
- Access to your Noiz cPanel account.
- An existing MySQL database. If you have not created one yet, use the **Create New Database** section at the top of the same **MySQL Databases** page first.
- An existing MySQL user. If you have not created one yet, use the **Add New User** section on the same page and note the username and password.
cPanel automatically prefixes both database names and usernames with your account username, for example `youracct_shop` for a database and `youracct_appuser` for a user. Always use the full prefixed names when you configure an application.
## Add a User to a Database
1. Log in to your cPanel account.
2. In the **Databases** section, click **MySQL Databases**. 
3. Scroll down to the **Add User to Database** section. Select a user from the **User** drop-down list, then select the target database from the **Database** drop-down list.
4. Click **Add**. 
5. On the **Manage User Privileges** page, tick **ALL PRIVILEGES**, then click **Make Changes**. 
The user is now linked to the database with the privileges you selected. Most content management systems and web applications, such as WordPress, expect the database user to hold **ALL PRIVILEGES** on their database, so this is the usual choice during installation.
## Granting Narrower Privileges
If an application does not need full control, you can tick only the specific privileges it requires instead of **ALL PRIVILEGES**. Common individual privileges include `SELECT`, `INSERT`, `UPDATE` and `DELETE` for day-to-day data access, plus `CREATE`, `ALTER`, `DROP` and `INDEX` for schema changes. Granting only what is needed reduces the impact if the credentials are ever exposed.
## Troubleshooting
**The user does not appear in the drop-down list**: the user must exist before you can add it. Scroll up to **Add New User**, create the user, then return to **Add User to Database**.
**Your application reports an access-denied error after linking the user**: confirm the application is configured with the full prefixed database name and username, that the password matches the one you set, and that the database host is set to `localhost`.
**You changed the privileges but the application still cannot write data**: re-open **MySQL Databases**, click the user under the relevant database to reach **Manage User Privileges**, confirm the required boxes are ticked, and click **Make Changes** again.
## Need a Hand?
If you are on a managed Noiz hosting plan and would like the Noiz team to set up or check a database user for you, open a support ticket from your client area and include the database and username involved.
# How to Add an A Record in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-add-an-a-record-in-cpanel/
An **A record** is the DNS entry that points a domain or a subdomain at an IPv4 address. It is what tells the rest of the internet which server answers for `yourdomain.co.za` or `blog.yourdomain.co.za`. This guide shows you how to add one from the **Zone Editor** in cPanel, and explains the details that decide whether the record actually works: which nameservers are in charge, how cPanel expands the **Name** field, and how long the change takes to reach visitors.
**Last reviewed:** 27 July 2026, against cPanel & WHM **136** (Jupiter theme, the current default). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Zone Editor](https://docs.cpanel.net/cpanel/domains/zone-editor/): the vendor reference for every record type the Zone Editor supports, including the advanced **Manage** view.
- [RFC 1035](https://www.rfc-editor.org/rfc/rfc1035): the DNS specification that defines record types, names and TTL behaviour, if you want the underlying detail.
## Prerequisites
- A hosting account with cPanel access, and your cPanel login details.
- The IPv4 address you want the record to point at. If it is the server your site is already hosted on, you can read it in cPanel from the right-hand sidebar under **General Information** > **Shared IP Address**, or from your Noiz welcome email.
- The domain's DNS must be answered by the nameservers of this cPanel server. See the check below before you change anything.
## Before You Start: Confirm Who Controls the DNS
This is the single most common reason an A record appears to do nothing. cPanel only edits the DNS zone stored *on that server*. If the domain's authoritative nameservers point somewhere else, for example a registrar's own DNS or a CDN provider, the zone you edit in cPanel is never consulted and your change has no effect.
For Noiz client hosting, the nameservers on the domain should be:
```
ns1.noiz.co.za
ns2.noiz.co.za
```
Check what the domain is actually using from any terminal:
```
dig +short NS yourdomain.co.za
```
On Windows, use `nslookup -type=ns yourdomain.co.za` instead. If the answer is not the nameservers of the server hosting your cPanel account, change the nameservers at your registrar first, or add the A record in whichever DNS service is authoritative. Nameserver changes themselves take time to settle, so allow for that before you judge the result.
## Step 1: Log in to cPanel
Sign in to your cPanel account. If your control panel does not look like the screenshots below, your hosting may run a different control panel, in which case DNS is edited elsewhere. Open a ticket with Noiz support and the team will point you at the right place.
## Step 2: Open the Zone Editor
1. Find the **Domains** section on the cPanel home screen.
2. Click **Zone Editor**. 
**Tip:** the quickest route is the search box at the top of the cPanel home screen. Type `zone` and the Zone Editor appears immediately.
## Step 3: Find the Domain You Want to Edit
The Zone Editor lists every domain on the account: your main domain, plus any addon domains, subdomains and aliases. Each row has a set of actions on the right.

The quick-add buttons (**+ A Record**, **+ CNAME Record**, **+ MX Record**) create a single record with the zone's default settings. **Manage** opens the full zone, where you can see every existing record, edit or delete entries, and set a custom TTL. For a straightforward A record, the quick-add button is all you need.
Make sure you are working on the correct row. Each domain on the account has its own zone, and adding the record to the wrong one is an easy mistake to make when several domains share a screen.
## Step 4: Add the A Record
1. On the row for your domain, click **+ A Record**. A dialogue box opens.
2. Complete the two fields: 
- **Name:** the hostname the record is for. Enter just the label, for example `blog`, and cPanel appends the domain automatically to produce `blog.yourdomain.co.za`. To create a record for the domain itself, enter the full domain with a trailing full stop, for example `yourdomain.co.za.`
- **Address:** the IPv4 address the hostname should resolve to, for example `203.0.113.25`.
3. Click **Add An A Record**.
The record is written to the zone straight away and appears in the **Manage** view for that domain.
### The Trailing Full Stop Gotcha
cPanel treats a name without a trailing full stop as *relative* to the zone. Typing `blog.yourdomain.co.za` (no trailing stop) therefore creates `blog.yourdomain.co.za.yourdomain.co.za`, which resolves for nobody. Either enter the short label on its own (`blog`), or enter the complete name with the trailing full stop (`blog.yourdomain.co.za.`). If a new record refuses to resolve, this is the first thing to check in the **Manage** view.
### What the Record Does and Does Not Do
- **A records are IPv4 only.** For an IPv6 address, add an **AAAA** record instead. The Zone Editor accepts both, but not in the same record.
- **An A record does not create a website.** It only answers a DNS question. If you want a subdomain to serve files from your own hosting account, create it under **Domains** in cPanel so that the document root and the DNS entry are made together. Use a bare A record when you are pointing a name at something that already exists elsewhere, such as a separate application server or a third-party service.
- **A name cannot have both an A record and a CNAME.** If the hostname already has a CNAME, delete it in **Manage** before adding the A record, otherwise resolution is undefined and cPanel may reject the entry.
- **Two A records with the same name are legal.** DNS will hand out both addresses in rotation, which is rarely what you intended. If you are repointing a name, edit the existing record rather than adding a second one.
- **Some records are managed by the server.** System entries in the zone are locked and cannot be edited from the Zone Editor. If you need one of those changed, ask Noiz support.
### TTL and Planned Moves
The quick-add button uses the zone's default TTL, commonly `14400` seconds (four hours). The TTL is how long resolvers around the world are allowed to cache the answer, so it sets the pace of any future change to that record. If you know you are moving a site to a new IP address soon, open **Manage** a day beforehand, lower the TTL on the record to `300` (five minutes), let the old value expire, and then make the switch. The cutover will then be near-instant for most visitors. Raise the TTL again once the move is settled.
## Step 5: Verify the Record
Do not wait for propagation to find out whether you typed it correctly. Query the authoritative nameserver directly, which skips every cache in between:
```
dig +short blog.yourdomain.co.za A @ns1.noiz.co.za
```
If that returns your IP address, the record is correct and everything from here is caching. To see what the wider internet is currently getting, query a public resolver:
```
dig +short blog.yourdomain.co.za A @1.1.1.1
```
## How Long Propagation Takes
A brand new hostname that has never been looked up before is usually live within minutes, because there is no old answer cached anywhere. Changing an existing record takes longer: resolvers keep serving the previous address until the TTL expires. In practice most of the world updates inside a few hours, and the traditional advice to allow up to 24 to 48 hours covers the slowest resolvers and any device holding its own cache.
Your own machine is often the last to notice. Flush the local DNS cache (`ipconfig /flushdns` on Windows, `sudo resolvectl flush-caches` on most Linux systems) and restart the browser before concluding that the change has failed.
## Troubleshooting
- **The record saves but nothing resolves:** the domain is almost certainly using different authoritative nameservers. Run the `dig +short NS yourdomain.co.za` check from the top of this guide.
- **The hostname resolves to a doubled name:** the trailing full stop was missing when the record was created. Delete the record in **Manage** and add it again using just the short label.
- **cPanel refuses to add the record:** a conflicting CNAME usually exists for the same name. Open **Manage**, filter for the hostname, and remove the conflicting entry first.
- **Old visitors still land on the previous server:** the previous answer is still cached. Wait out the TTL that was in force before the change, not the new one.
- **The website shows the wrong site or a default page after the change:** DNS is now correct but the destination server is not configured to answer for that hostname. The A record gets traffic to the server; the server still needs a matching site or virtual host.
- **Email stops working after repointing the domain:** mail follows the **MX** records, not the A record, but MX records often point at a hostname that you have just moved. Check the MX entries in **Manage** after any change to the root record.
If you are on a Noiz managed plan, or you are unsure which nameservers your domain should be using, open a support ticket with the hostname and the IP address you want it to point at, and the Noiz team will set the record up and confirm it resolves.
# How to Add an MX Record in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-add-an-mx-record-in-cpanel/
An **MX record** (short for *mail exchanger record*) is the DNS record that tells the rest of the internet which server accepts email for your domain. When somebody sends a message to `you@yourdomain.com`, their mail server looks up the MX records for `yourdomain.com` and hands the message to the host named there. No MX record, or a wrong one, and inbound mail either bounces or lands somewhere you never look.
This guide shows you how to add an MX record in cPanel's **Zone Editor**, and covers the two things that decide whether the change actually takes effect: whether cPanel is serving your live DNS at all, and how cPanel routes mail for the domain internally. You may also see this task described as adding a *mail exchanger record*, an *MX entry* or *pointing your domain at a mail provider*. They all mean the same thing. In older cPanel releases MX records had their own **MX Entry** interface; that tool was retired and its job moved into Zone Editor.
**Last reviewed:** 27 July 2026, against cPanel & WHM **136** (current RELEASE tier). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [Zone Editor](https://docs.cpanel.net/cpanel/domains/zone-editor/): the reference for every button and field on the screen used below, including the Manage Zone view.
- [Email Routing](https://docs.cpanel.net/cpanel/email/email-routing/): what Local, Backup and Remote Mail Exchanger actually do, in cPanel's own words.
- [Email Deliverability](https://docs.cpanel.net/cpanel/email/email-deliverability-in-cpanel/): the SPF, DKIM and PTR checks you should run after changing where your mail lives.
- [RFC 5321, section 5.1](https://www.rfc-editor.org/rfc/rfc5321#section-5.1): the standard that defines how a sending server resolves MX records, and why an MX must not point at a CNAME or an IP address.
- [RFC 7505 (Null MX)](https://www.rfc-editor.org/rfc/rfc7505): the correct way to declare that a domain receives no mail at all.
## Prerequisites
- Login details for the cPanel account that holds the domain.
- The mail server hostnames supplied by your mail provider, together with the priority number for each one. A provider will normally give you something like `mx1.mailprovider.example` at priority `10` and `mx2.mailprovider.example` at priority `20`. Use the values in front of you, not the examples in this article.
- Confirmation that this server is the one answering DNS queries for the domain. The next section shows you how to check.
- The **Zone Editor** icon visible in cPanel. If it is missing, the feature has been switched off for the hosting package rather than removed from cPanel.
## First, Check You Are Editing the Live Zone
This one check prevents the most common wasted afternoon. cPanel edits the zone file held on the server cPanel is running on. If the domain's nameservers point anywhere else, that zone file is never consulted, and the record you add will look perfectly correct while changing nothing at all.
Look up the domain's current nameservers before you touch anything. From a terminal:
```
dig NS yourdomain.com +short
```
Compare the answer with the nameservers cPanel shows you under **Domains > Zone Editor**, or in the **General Information** panel on the cPanel home screen. If they do not match, the domain's DNS is being served by your registrar, a CDN, or a separate DNS platform, and that is where the MX record belongs. Editing it in cPanel as well is harmless but pointless, and it leaves a stale copy that confuses whoever looks next.
Two related traps are worth knowing about:
- A domain proxied through a CDN or a third-party DNS service keeps its DNS there permanently, not just during setup. MX records for such a domain are always edited at that service.
- If the domain is an addon domain, an alias or a subdomain on the account, make sure you pick the right entry in the Zone Editor list. Adding an MX to `yourdomain.com` does nothing for mail addressed to `mail.otherdomain.com`.
## Add the MX Record
1. Log in to your cPanel account.
2. In the **Domains** section, click **Zone Editor**. 
3. Zone Editor lists every domain on the account. Each row carries a set of quick actions: **+ A Record**, **+ CNAME Record**, **+ MX Record**, **DNSSEC** and **Manage**. The quick actions add one record type without leaving the list; **Manage** opens the full record table for that domain, where you can see and filter everything the zone already contains. 
4. Before adding anything, click **Manage** and filter the table by **MX** to see which MX records already exist. Almost every cPanel account is created with an MX record pointing at itself, and leaving that in place alongside a new external record is the single biggest cause of mail going missing after a migration.
5. Click **+ MX Record** beside the domain. A small form opens with two fields. 
- **Priority**: a whole number that sets the order in which sending servers try your mail hosts. **The lowest number wins.** A value of `0` is the highest priority available. Enter exactly the number your mail provider specifies.
- **Destination**: the fully qualified hostname of the mail server, for example `mx1.mailprovider.example`. This must be a hostname that resolves to an IP address. It must not be an IP address itself, must not point at a CNAME, and must not include a protocol, a port or a trailing slash. cPanel adds the trailing dot for you.
6. Click **Add an MX Record**. A success message confirms the record has been written to the zone.
7. Repeat for every mail host your provider lists. Most providers publish two or more, and a domain with only the first of them has no fallback if that host is unreachable.
The new records now appear in the **Manage** table for the domain. To change or delete one later, see [How to Edit or Remove an MX Record in cPanel](/cpanel/how-to-edit-or-remove-an-mx-record-in-cpanel/). The same Zone Editor screen handles the other common record types: [A records](/cpanel/how-to-add-an-a-record-in-cpanel/) and [CNAME records](/cpanel/how-to-add-a-cname-record-in-cpanel-zone-editor/).
## How Priority Actually Works
Priority is the field people most often get backwards, because the intuitive reading is wrong. It is a preference number, not a score, so a *lower* value means a *more* preferred server.
A sending server collects every MX record for the domain, sorts them by priority ascending, and tries the lowest first. If that host refuses the connection or times out, it moves on to the next. A typical two-host set looks like this:
- `10 mx1.mailprovider.example`: tried first, handles all mail under normal conditions.
- `20 mx2.mailprovider.example`: tried only when the first host cannot be reached.
Points worth knowing:
- The actual numbers carry no meaning of their own, only their order relative to each other. `10` and `20` behave identically to `1` and `2`. Conventional spacing of 10 simply leaves room to insert a host later without renumbering everything.
- Two records sharing the same priority are treated as equals, and sending servers spread traffic across them. Use this deliberately for load sharing, never by accident.
- A backup MX only helps if that host is genuinely configured to queue and forward your mail. An unconfigured backup MX is worse than none, because it accepts messages and then has nowhere to send them.
- Never run MX records for two different mail providers side by side while you decide. Mail will split unpredictably between them and neither mailbox will hold the full picture.
## Tell cPanel Where to Deliver Local Mail
This step is not optional when you are moving mail to an external provider, and it is missing from most MX guides. cPanel does not work out your intentions from the zone file alone.
The server keeps a separate routing decision for each domain it hosts. If that decision still says the server itself handles the mail, then anything sent *from* an account on that same server to your domain is delivered into a local mailbox and never leaves the machine. Externally the change looks perfect; internally, half your mail quietly disappears. Contact form messages from your own website are the classic casualty.
1. Go to **Email > Email Routing** in cPanel.
2. Select the domain from the list.
3. Choose the correct setting:
- **Automatically Detect Configuration**: the sensible default. The server reads the MX records in the zone and routes accordingly.
- **Local Mail Exchanger**: the server always accepts mail for the domain and delivers it to local mailboxes. Correct when mailboxes live on this server, including when an external filtering or gateway service sits in front of it.
- **Backup Mail Exchanger**: the server queues mail and holds it until a lower-numbered mail exchanger is reachable again.
- **Remote Mail Exchanger**: the server refuses to deliver locally and forwards everything to the lowest-numbered mail exchanger. This is what you want when mailboxes now live with an external provider.
4. Click **Change**.
Automatic detection only reads the local zone file, and it does not perform a live DNS lookup. So if you have added an external MX but left the original self-pointing MX in place, automatic detection sees a local mail exchanger and keeps mail on the server. Remove the old record first, then set routing.
One more consequence to plan for: once routing is remote, any cPanel mailbox for that domain stops receiving new mail, but the messages already in it stay on the server. Export or forward anything you still need before you cut over, because turning the domain remote does not migrate a single message for you.
## Do Not Stop at the MX Record
Moving where mail is received usually means moving where mail is sent from too, and the sending side has its own records. If you change MX and nothing else, your outbound mail starts failing authentication checks at the recipient and lands in spam folders.
- **SPF**: update the TXT record so it authorises the new provider's sending servers, and remove any provider you no longer use. Publish exactly one SPF record for the domain.
- **DKIM**: publish the selector record your new provider gives you. This is normally a TXT or CNAME record at a name such as `selector1._domainkey`.
- **DMARC**: a TXT record at `_dmarc.yourdomain.com`. Start at `p=none` with reporting enabled, read the reports for a week or two, and only then tighten the policy.
- **Autodiscover and autoconfig**: many providers ask for CNAME or SRV records so that mail clients configure themselves. Skipping these does not break mail, but it does mean every user has to type server settings by hand.
cPanel's **Email > Email Deliverability** screen will report on SPF and DKIM for domains it still handles, which makes it a useful sanity check before and after a move.
## Propagation and TTL
An MX change is not instant, and the delay is governed by the TTL (time to live) on the records, not by any fixed waiting period. Resolvers that already have your old MX cached keep using it until that cache entry expires.
- Typical zone TTLs run from 5 minutes to 4 hours. Allow up to 24 hours for the last stragglers, particularly resolvers that ignore short TTLs.
- If the move is planned, lower the TTL on the existing MX records to `300` seconds at least a day beforehand, using **Manage** in Zone Editor. Cut over, confirm it works, then put the TTL back to something sensible such as `3600`.
- Leave the old mailboxes reachable for a few days after the switch. Mail that was already queued for the old server will still be delivered there.
To check what the world currently sees, rather than what your own machine has cached:
```
dig MX yourdomain.com @1.1.1.1 +short
```
The output lists each priority and hostname. If it still shows the old values, the record has either not been written or has not yet expired from cache.
## Troubleshooting
**Symptom**: the record saved without error, but `dig` still returns the old MX. Either the TTL has not expired yet, or the domain's DNS is not served by this server. Re-run the nameserver check at the top of this article before changing anything else.
**Symptom**: mail from outside arrives at the new provider, but messages sent from your own website or from another account on the same server never turn up. Email Routing is still set to **Local Mail Exchanger**, or a self-pointing MX record was left in the zone. Fix both, in that order.
**Symptom**: cPanel rejects the destination as invalid. You have entered an IP address, a URL, or a hostname with a trailing slash. The destination must be a bare fully qualified hostname that resolves to an A or AAAA record.
**Symptom**: senders receive *"550 relay not permitted"* or *"no such user here"* from a server you have just moved away from. The MX has moved but the old server still believes it owns the domain. Set that domain to **Remote Mail Exchanger**, or remove the domain from it entirely once the migration is complete.
**Symptom**: mail loops back and forth and eventually bounces with a message about too many hops. Two servers each believe the other is responsible. This is almost always an MX pointing at a host that has itself been configured to forward to the same domain.
**Symptom**: the **+ MX Record** button is missing from Zone Editor. The *Email Routing (MX Records and Zone Editor)* feature is disabled on the hosting package. Contact your provider to have it enabled rather than editing zone files by hand.
**Symptom**: you want a domain to receive no mail at all, for example a domain used only for redirects. The correct approach is a null MX as defined in RFC 7505: a single record with priority `0` and a destination of `.` (a lone dot). Zone Editor's quick-add form may refuse the bare dot, in which case use **Manage** to add the record, or ask Noiz support to place it for you. Deleting all MX records is not equivalent, because senders then fall back to the domain's A record and try to deliver mail to your web server.
## Getting Help
If your Noiz hosting account uses a different control panel, the record itself is identical and only the screen you type it into changes. The priority and destination values from your mail provider apply exactly as written here.
Changing MX records affects live mail delivery, and a mistake usually shows up as messages that silently go somewhere else rather than as an obvious error. If you are migrating a busy domain, are unsure which records to remove, or have already made the change and mail has stopped arriving, contact Noiz support with the domain name and the details your mail provider gave you. The team will check the zone, the routing and the authentication records together, and can carry out the cutover for you.
# How to Block an IP Address in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-block-an-ip-address-in-cpanel/
cPanel's built-in **IP Blocker** (older builds and some documentation call it the **IP Deny Manager**) lets you deny web access to your site from a single visitor, a range of addresses, or an entire network block. It is the quickest way to shut out an abusive visitor without editing any files by hand. If you would rather write the deny rules yourself, or you need to block an IPv6 address, see [How to Block Any IP Address via an htaccess Rule](/security/how-to-block-an-ip-address-using-an-htaccess-rule/).
**Last reviewed:** 27 July 2026, against cPanel & WHM with the **Jupiter** interface (current default). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel & WHM Documentation: IP Blocker](https://docs.cpanel.net/cpanel/security/ip-blocker/)
## Prerequisites
- The cPanel login details for the account that hosts the website you want to protect.
- The IP address or range you want to block, taken from a reliable source rather than guessed. See **Find the Address to Block** below.
## Find the Address to Block
Block the wrong address and you either achieve nothing or you shut out real customers, so confirm the address before you add it. Inside cPanel, the two most useful sources are:
- **Metrics > Visitors**, which lists recent requests to a domain along with the address that made them. This is the fastest way to spot a single address hammering one URL.
- **Metrics > Raw Access**, which downloads the full web server log. Use this when you need to see the pattern over hours or days rather than the last few hundred hits.
Application logs help too. WordPress security plugins, for example, record the address behind failed logins. Whatever the source, check your own current address first at a service such as [whatismyip.com](https://www.whatismyip.com/) so you do not block yourself.
## Block an IP Address
1. Log in to your cPanel account.
2. In the **Security** section, click **IP Blocker**. 
3. Under **Add an IP or Range**, enter the address you want to block. Any of the formats listed in the next section is accepted. 
4. Click **Add**.
The entry then appears under **Currently-Blocked IP Addresses** and takes effect immediately. There is no cache to clear and no service to restart. A blocked visitor receives a `403 Forbidden` response.
## Accepted Address Formats
The **Add an IP or Range** field takes more than a single address, so you can block a whole network in one entry:
- **Single address:** `192.168.0.1`
- **Range:** `192.168.0.1-192.168.0.40`
- **Implied range:** `192.168.0.1-40`, which is shorthand for the range above
- **CIDR notation:** `192.168.0.0/24`
- **Partial address:** `10.` blocks everything in `10.0.0.0` to `10.255.255.255`, and `192.168.` blocks everything in `192.168.0.0` to `192.168.255.255`
The addresses above are private ranges used here purely as examples. Replace them with the real address you want to block.
Partial addresses are powerful and easy to over-apply. A single trailing dot can cover more than sixteen million addresses, so use the narrowest entry that solves the problem.
## Remove a Block
To unblock an address, return to **IP Blocker**, find the entry under **Currently-Blocked IP Addresses**, and click **Delete**. Confirm the removal when prompted. Access is restored straight away.
## Good to Know
- **It only covers the website.** IP Blocker denies HTTP and HTTPS requests to the sites in that cPanel account. It does not block email, FTP, SSH or any other service, because it works by writing deny rules into the `.htaccess` file in your document root rather than at the server firewall.
- **The request still reaches the server.** A blocked visitor is turned away by the web server, not before it. That is fine for a nuisance visitor, but it will not shield you from a large flood of traffic, because the connection is still accepted and answered.
- **IPv4 only.** The IP Blocker interface works with IPv4 addressing. If the traffic you want to stop arrives over IPv6, which shows up in logs as an address containing colons, block it with an `.htaccess` rule instead.
- **Check for a proxy or CDN first.** If your site sits behind a reverse proxy or content delivery network, the address the web server sees can be the proxy's rather than the visitor's. Blocking the address in your logs may then either do nothing or block every visitor at once. Where a CDN is in front of the site, block the visitor in the CDN's own dashboard.
- **Dynamic addresses move.** Most home and mobile connections are reassigned an address regularly, so blocking one address may only stop a determined visitor for a few hours. A range is more durable but risks catching innocent visitors on the same network.
- **Do not block search engines.** Before blocking a range, check who owns it with a WHOIS lookup. Blocking a crawler's range can remove your site from search results, and the damage is not obvious until traffic falls.
- **The list is per account.** Entries you add apply to every domain and subdomain in that cPanel account, not just the one you had in mind.
## Troubleshooting
**You have blocked yourself by mistake:** connect from a different network, such as mobile data or a phone hotspot, log in to cPanel and delete the entry. Your hosting control panel is reached on a different port from the website, so in many cases the panel still loads even when the site does not.
**The blocked visitor still gets through:** the address has almost certainly changed, or the traffic is arriving through a proxy or VPN. Recheck the logs for the address in use now, and consider blocking the wider range that the address belongs to.
**Your site returns a 500 Internal Server Error after adding an entry:** this points to a conflict in the `.htaccess` file in your document root, usually where another tool has written overlapping rules. Remove the entry from IP Blocker, then open a support ticket and Noiz will sort out the file.
**Everyone is blocked, not just the visitor:** a partial address or CIDR entry is broader than intended. Delete it and add a single address instead.
## Need a Hand?
On a Noiz managed hosting plan you do not have to deal with repeat offenders alone. If you are seeing sustained abuse, unusual traffic or a suspected attack, open a support ticket from your Noiz client area and the team will identify the source and put the right blocks in place, including firewall-level blocks that reach beyond the website itself.
# How to Change an Email Account's Password in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-change-an-email-accounts-password-in-cpanel/
Changing an email account's password is one of the first things to do if a mailbox has been compromised, if the password has been shared too widely, or simply as part of good routine security. This guide shows you how to change the password for an email account hosted on your cPanel account with Noiz. Note that this is the password for the **mailbox itself** (the one you use to send and receive mail, and to sign in to webmail), not the password for your cPanel account.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM Jupiter interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Docs: Email Accounts](https://docs.cpanel.net/cpanel/email/email-accounts/)
- [cPanel Docs: Manage an Email Account](https://docs.cpanel.net/cpanel/email/manage-an-email-account/)
## Prerequisites
- Your cPanel sign-in details, which are in your Noiz hosting welcome email or available from your [Noiz client area](https://www.noiz.co.za/clientarea.php).
- The email address whose password you want to change, for example `you@yourdomain.com` (replace this with your own address).
- A note of every device and program that currently checks this mailbox, because you will need to update the password in each one afterwards. See the warning below.
## Change the Password
1. Log in to your cPanel account.
2. In the **Email** section, click **Email Accounts**. 
3. Find the account you want to change in the list of email accounts on the page. Its full address (for example `you@yourdomain.com`) is shown on the left.
4. On the right of that account's row, click **Manage**. 
5. Under **Security**, in the **New Password** field, type a new password, or click **Generate** to have cPanel create a strong one for you. cPanel shows a strength meter and will not accept a password it considers too weak, so aim for a long mix of upper and lower case letters, numbers and symbols. 
6. Scroll down to the bottom of the page and click **Update Email Settings**.
The password is changed straight away. You can now sign in to webmail and your email programs with the new password.
## Important: Update the New Password Everywhere
A mailbox password change takes effect immediately on the server, but nothing else knows about it. Any phone, tablet, laptop or program that was set up to collect this mailbox is still trying to log in with the old password and will start failing to send and receive as soon as you save the change.
After changing the password, go to every place the mailbox is configured and enter the new password, including:
- Desktop mail programs such as Outlook, Apple Mail and Thunderbird.
- The Mail app on your phone and tablet (check every device).
- Any website contact forms, shop or application that sends mail through this account.
Until you do this, those devices keep retrying the old password in the background. Repeated failed logins from the same connection can trigger the server's automatic protection and temporarily block your address, which then makes even the correct password appear to fail. Updating every device promptly avoids this.
## No cPanel Access? Change It from Webmail
If you can already sign in to the mailbox but do not have cPanel access, you can change the password from within webmail instead. Log in to webmail with the current password, open the account menu (usually via your address in the top corner), choose **Password & Security**, and set a new password there. The effect is exactly the same, and the same warning about updating your other devices applies.
## Troubleshooting
**The password is rejected as too weak**: cPanel enforces a minimum password strength. Make it longer and add a wider mix of upper and lower case letters, numbers and symbols, or click **Generate** and copy the strong password cPanel suggests.
**Email stopped working on your phone or in Outlook after the change**: those devices are still using the old password. Open the account's settings on each device and enter the new password for both incoming and outgoing (SMTP) mail.
**The correct new password keeps being refused**: a device left retrying the old password may have triggered a temporary block on your connection. Update or switch off that device, wait a short while, then try again. If it persists, contact Noiz support and mention the address and your current network so the block can be cleared.
## Need a Hand?
If you are on a Noiz managed hosting plan and would like an email password reset for you, or you have lost access to both cPanel and the mailbox, open a support ticket from your [Noiz client area](https://www.noiz.co.za/clientarea.php) and the support team will sort it out and confirm it is done.
# How to Change an FTP Account Password in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-change-an-ftp-account-password-in-cpanel/
Every cPanel account has a main FTP login plus any number of additional FTP accounts you create for specific folders or users. This guide shows you how to reset the password on an additional FTP account. To change the main FTP login, change your cPanel account password instead, because the main FTP login and your cPanel account share the same credentials.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM Jupiter interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel FTP Accounts](https://docs.cpanel.net/cpanel/files/ftp-accounts/): the full reference for creating, editing and removing FTP accounts.
## Prerequisites
- Access to your cPanel account, reached from the Noiz client area or the link in your hosting welcome email.
- An existing additional FTP account whose password you want to change.
- A strong replacement password ready, or use the built-in generator described below.
## Change an FTP account password
1. Log in to your cPanel account.
2. In the **Files** section, click **FTP Accounts**. 
3. Under the list of **FTP Accounts**, find the account you want to update and click **Change Password**. Type a new password, or click the password generator to create a strong one. 
4. Click **Change Password** to save.
The new password takes effect immediately. Update it everywhere that account is used, including your FTP client, any upload scripts, and any scheduled backup or deployment jobs, or those connections will start to fail.
## A note on FTP security
Plain FTP sends your username and password across the network in clear text. Where your plan and FTP client support it, choose **FTP over TLS** (FTPS) or connect over **SFTP** instead, so your credentials and files are encrypted in transit.
## Troubleshooting
- **You cannot see FTP Accounts**: the tile may be hidden on your plan. Confirm your plan includes FTP, or ask Noiz support to enable it.
- **The password is rejected as too weak**: cPanel enforces a minimum password strength score. Use the password generator, or lengthen the password and mix upper and lower case, digits and symbols.
- **You still cannot connect after changing the password**: check that you are using the full username (usually `user@yourdomain.com`), the correct host and port, and that your FTP client is not reconnecting with a saved copy of the old password.
Now you can access FTP with the new password. If you would rather not do this yourself, or you want help switching an account to a secure connection method, open a ticket from your Noiz client area and support will assist.
# How to Change the FTP User Quota in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-change-the-ftp-user-quota-in-cpanel/
An FTP account's quota sets the maximum amount of disk space that account is allowed to use inside its home directory. This guide shows you how to change that quota, or remove the limit entirely, from within cPanel. You will need your cPanel login details to begin.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel & WHM. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [FTP Accounts (docs.cpanel.net)](https://docs.cpanel.net/cpanel/files/ftp-accounts/)
## Prerequisites
- Access to your cPanel account.
- At least one FTP account already created.
## Change the FTP Quota
1. Log in to your cPanel account.
2. In the **Files** section, click **FTP Accounts**. 
3. Under the **FTP Accounts** list, find the account you want to adjust and click **Change Quota**. 
4. Set the **FTP Quota**: enter the limit as a number in megabytes (for example, type `500` for a 500 MB limit), or select **Unlimited** to remove the limit.
5. Click **Change Quota** to save your choice.
## Good to Know
- The quota is measured in **megabytes (MB)**, so enter a plain number such as `250` or `1000`. Setting the value to **Unlimited** lets the account use as much space as your overall hosting package allows.
- An FTP quota never grants more space than your hosting plan provides. It only caps how much of that space a single FTP account may fill, which is useful when you hand out an account to a third party and want to keep their usage in check.
- The main FTP account tied to your primary cPanel login shares your account's total disk space and does not take a separate quota here. The **Change Quota** option applies to the additional FTP accounts you create.
If you are on a managed Noiz plan and would prefer the quota adjusted for you, contact Noiz support and the team will take care of it.
# How to Change the Language of Your cPanel Account
Source: https://docs.noiz.ie/cpanel/how-to-change-the-language-of-your-cpanel-account/
cPanel ships with dozens of interface languages. Changing the language sets how the cPanel control panel is displayed for your account, so the section headings, icons, buttons, and menu labels appear in the language you prefer. This guide shows you how to switch it in a few clicks.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM **Jupiter** interface (cPanel's default theme). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel & WHM: Change Language interface](https://docs.cpanel.net/cpanel/preferences/change-language/)
- [cPanel & WHM: Preferences section overview](https://docs.cpanel.net/cpanel/preferences/)
## Change your cPanel account language
1. Log in to your cPanel account.
2. In the **Preferences** section, click **Change Language**. 
3. Choose the language you want from the drop-down menu, then click **Change**. 
cPanel reloads and the interface is now displayed in the language you selected.
## What the language setting does and does not change
It is worth knowing the scope of this setting before you switch, so the result matches what you expect:
- The choice affects **only the cPanel interface** for your account. It does not translate your website, your emails, or anything your visitors see on your public site.
- Webmail is a separate application with its own language option, set from inside the webmail interface. Changing the cPanel language does not change the webmail language.
- The setting is saved **per cPanel user**. Any additional users you create under **User Manager** choose their own language independently, so changing yours does not affect theirs.
- Several languages are community-contributed and may be only partly translated. If a translation is incomplete, some labels can still appear in English until that language pack is finished.
If the language you need is not listed, or the interface still shows English after you switch, the [Noiz support team](https://www.noiz.co.za/knowledgebase.html) can confirm which language packs are installed on your server and add one if required.
# How to Change the PHP Version on Your Domain in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-change-the-php-version-on-your-domain-in-cpanel/
Some applications need a specific version of PHP: an older shopping cart that has not been updated in years, a plugin that has not caught up with the latest release, or a modern framework that refuses to install on anything below a certain version. In cPanel you can set the PHP version separately for each domain on the account, so one site can run an older build while another runs the newest, without either affecting the other.
The tool that does this is called **MultiPHP Manager**. You may also see it referred to as the PHP version switcher or the PHP version manager. It is not the same thing as the CloudLinux **PHP Selector**, which is a separate tool that some accounts have instead; there is a note further down on telling them apart.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the current STABLE and LTS tier) and PHP **8.5**. This guide is written for Noiz hosting and is kept current against cPanel and PHP. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: MultiPHP Manager for cPanel](https://docs.cpanel.net/cpanel/software/multiphp-manager-for-cpanel/)
- [cPanel Documentation: MultiPHP INI Editor for cPanel](https://docs.cpanel.net/cpanel/software/multiphp-ini-editor-for-cpanel/) (where the settings for each version live)
- [cPanel Documentation: EasyApache 4](https://docs.cpanel.net/ea4/) (how the server builds the PHP versions the list offers you)
- [PHP: Supported Versions](https://www.php.net/supported-versions.php) (the authoritative end-of-life dates)
- [PHP Manual: Migrating from PHP 8.4.x to PHP 8.5.x](https://www.php.net/manual/en/migration85.php) (backward incompatible changes to check before you switch)
## Prerequisites
- A hosting plan that uses cPanel, and the cPanel login for the account that holds the domain. If your control panel looks nothing like the screenshots below, you are probably on a Plesk or DirectAdmin plan, where the equivalent setting sits elsewhere; contact Noiz support and the team will point you at the right screen.
- The domain already added to the account, whether as the main domain, an addon domain or a subdomain.
- A recent backup of the site files and database. Changing the PHP version is reversible in seconds, but the errors an incompatible version throws are much easier to investigate from a known good copy.
- Some idea of which version your application actually needs. The next section covers how to decide.
## Choose the Version Before You Change It
The list cPanel offers you will usually include several versions that are no longer maintained. Only the branches PHP still supports receive security fixes, and everything else is a liability on a public website. As at the review date above:
- **PHP 8.5** and **PHP 8.4** are in active support and receive both bug fixes and security fixes. One of these is the right target for anything actively maintained.
- **PHP 8.3** and **PHP 8.2** receive security fixes only. They are acceptable as a temporary landing spot, but 8.2 leaves security support at the end of December 2026, so treat it as a short-term position rather than a destination.
- **PHP 8.1 and everything older**, including the whole of PHP 7 and PHP 5, are end of life. No security patches are issued for them at all. If an application still requires one of these, the application is the thing that needs attention, not the PHP version.
Newest is not automatically best. Each major and minor release removes functions and changes behaviour, so an application written for PHP 7.4 can fail outright on 8.4. The sensible order is: check what the application vendor says it supports, move up one branch at a time, test the site properly after each move, and only then go further. For WordPress specifically, **Tools** then **Site Health** flags plugins and themes that are known to be incompatible before you switch.
## Change the PHP Version for a Domain
### 1. Log In to cPanel
Sign in to the cPanel account that holds the domain. If you reach cPanel from the Noiz client area, make sure you have opened the right hosting package, since each package is a separate cPanel account with its own list of domains.
### 2. Open MultiPHP Manager
In the **Software** section of the cPanel home screen, click **MultiPHP Manager**. The quickest way to find it is to type `multiphp` into the search box at the top of the page.

### 3. Select the Domain
Scroll to the **Set PHP Version per Domain** table at the bottom of the page. Every domain, addon domain and subdomain on the account is listed there with the PHP version it currently runs. Tick the box beside the domain you want to change. The counter above the table confirms how many domains are selected.
### 4. Pick the Version and Apply
Choose the version you want from the **PHP Version** drop-down above the table, then click **Apply**. A green confirmation appears and the table refreshes with the new value.

The screenshot is there to show you where the controls sit. The versions in your own drop-down will differ, because the list is built from whatever PHP builds the server administrator has installed, and those change over time.
The change itself takes a few seconds. Domains running PHP-FPM can take a minute or two longer, because the server has to rebuild and reload the pool configuration for that domain.
## What "inherit" Means in That List
Alongside the numbered versions, the drop-down offers **inherit**, and domains set that way are tagged **Inherited** in the table. Inherit means the domain does not pin a version of its own; it follows the default PHP version set for the server.
That distinction matters more than it looks:
- **Left on inherit**, the domain moves automatically whenever the server default moves. That is usually what you want for a well maintained site, because it keeps you on a supported version without any effort.
- **Pinned to a specific version**, the domain stays exactly where you put it and ignores changes to the server default. That is what you want for an application with a hard version requirement, but it also means the domain can quietly end up on an unsupported version months later while nothing appears to be wrong.
If a domain's PHP version has changed on its own, inherit is almost always the reason. To put a pinned domain back on the default, select **inherit** and click **Apply**; the full walkthrough is in [How to Reset the PHP Version to the Default Version in cPanel](/cpanel/how-to-reset-the-php-version-to-the-default-in-cpanel/).
## Changing Several Domains at Once
The table is built for bulk changes. Tick as many domains as you like before clicking **Apply**, and the selected version is set on all of them in one pass. The tick box in the table header selects everything, and the search box filters the list, which is useful on an account with dozens of subdomains.
One thing to watch: on a long list the table is paginated, and the header tick box only selects the rows on the page you are looking at. Check the **Selected** counter against the number of domains you meant to change before you apply.
## Confirm the Change Took Effect
The value in the table tells you what cPanel has recorded, not necessarily what the website is serving. It is worth confirming independently, especially on a site that was moved in from another host.
- **A phpinfo page.** Create a file called `info.php` in the document root of the domain containing nothing but ``, then open `https://yourdomain.com/info.php` in a browser, replacing `yourdomain.com` with your own domain. The version is at the very top. **Delete the file as soon as you have read it.** A phpinfo page publishes your server paths, loaded modules and configuration to anyone who finds it, and automated scanners look for exactly that filename.
- **WordPress.** Go to **Tools** then **Site Health** then **Info**, and open the **Server** panel. The PHP version is listed there, along with the memory limit and the maximum upload size.
- **Not `php -v` over SSH.** That command reports the version of the command-line PHP binary in your path, which is a different thing entirely from the version Apache uses to serve the website. The two are frequently different, and mistaking one for the other wastes a great deal of time.
## What Changes Behind the Scenes
Knowing where the setting is stored explains most of the odd behaviour people run into.
For a domain served through the Apache PHP handler, cPanel writes a small block into the `.htaccess` file in the domain's document root. It looks like this:
```
# php -- BEGIN cPanel-generated handler, do not edit
AddHandler application/x-httpd-ea-php84 .php .php8 .phtml
# php -- END cPanel-generated handler, do not edit
```
For a domain running **PHP-FPM**, the version lives in that domain's FPM pool configuration on the server instead, and no handler block is written to `.htaccess`. PHP-FPM is generally the better performing option, and it is what most current cPanel setups use.
Two consequences follow from this, and both catch people out:
- **Each version has its own settings.** Values such as `memory_limit`, `upload_max_filesize`, `post_max_size` and `max_execution_time` are configured per PHP version, so a limit you raised on the old version does not follow you to the new one. Re-apply anything custom in **MultiPHP INI Editor** after switching.
- **Extensions are per version too.** An extension the site depends on, such as an encoder loader, `imagick` or `soap`, is compiled separately for each PHP build. If it was never installed for the version you have just moved to, the site will break in a way that has nothing obvious to do with PHP versions.
## Gotchas Worth Knowing
- **Domains that share a document root cannot have different versions.** A parked or alias domain serves the same files as the domain it is aliased to, and the handler block sits in the shared `.htaccess`. Setting one to PHP 8.4 and the other to PHP 8.2 will not do what you expect, because they are reading the same file. Addon domains and subdomains with their own directories are unaffected by this.
- **A per-directory setting beats the domain setting.** If a handler line has been placed in an `.htaccess` file inside a subfolder, that folder keeps running its own version regardless of what MultiPHP Manager says for the domain. See [How to Set the PHP Version per Directory in cPanel](/cpanel/how-to-set-the-php-version-per-directory-in-cpanel/).
- **Cron jobs do not follow the change.** Scheduled tasks run the command-line PHP binary, not the web one. If a cron job needs a particular version, call it by full path, for example `/opt/cpanel/ea-php84/root/usr/bin/php /home/username/public_html/script.php`, substituting your own account username and path.
- **The version you need may not be listed.** The drop-down only offers the PHP builds installed on that server. If the version you require is missing, it has not been installed rather than being unavailable in principle; raise a ticket with Noiz support and ask.
- **MultiPHP Manager missing from the Software section?** Some accounts use the CloudLinux **PHP Selector** instead, which does the same job through a different interface and also lets you switch extensions on and off yourself. In that case follow [How to Change the PHP Version via CloudLinux Selector in cPanel](/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/). If neither tool is present, the server is running a single PHP build and the version can only be changed by the administrator.
- **Test on a copy first for anything important.** On a busy or revenue-generating site, clone it to a staging subdomain, switch the clone, and check the checkout, the contact forms and the admin area before touching the live domain.
- **Reverting is instant.** If the site misbehaves, go straight back into MultiPHP Manager and select the previous version. Nothing about your files or database has been altered by the switch itself.
## Troubleshooting
**Symptom**: 500 Internal Server Error immediately after applying the change. The most common cause is a second, older handler line left in `.htaccess` by a previous host or a manual edit, sitting outside the cPanel-generated block and now conflicting with it. Open `.htaccess` in the document root using File Manager and remove any `AddHandler` or `AddType` line that mentions a PHP version and is not inside the cPanel block.
**Symptom**: the browser downloads the `.php` file, or shows the PHP source code as plain text. The handler is not matching, so the web server is treating the script as a static file. Re-apply the version in MultiPHP Manager, which rewrites the handler block, and check that `.htaccess` is writable rather than locked at 0444.
**Symptom**: clicking **Apply** reports success, but the table still shows the old version after a reload. This is nearly always file permissions on `.htaccess` in the document root, or an immutable flag left behind by a security plugin. Fix the permissions and apply again.
**Symptom**: a fatal error mentioning a missing class or function, such as `Call to undefined function`. An extension the application relies on is not installed for the version you moved to. Confirm which one from the error message, then either move back to the previous version or ask Noiz support to have the extension enabled for the new one.
**Symptom**: "The encoded file requires a loader" or a similar encoder message. Files protected with ionCube or SourceGuardian need a loader built for that exact PHP version. Revert to the previous version, then ask your software vendor for files encoded for the version you want to run.
**Symptom**: a white screen with no error at all. PHP is failing before it can display anything. Turn on error display temporarily for that domain in **MultiPHP INI Editor**, or read the domain's error log through **Metrics** then **Errors** in cPanel, which will name the file and line.
**Symptom**: the site still reports the old version after the change. Something is caching. Purge any caching plugin, purge a CDN if one sits in front of the domain, and reload with a hard refresh. If a phpinfo page shows the new version but the application does not, the application is caching its own environment check.
**Symptom**: the version changed by itself some time later. The domain is set to **inherit** and the server default moved. Pin it explicitly if the application requires a fixed version.
## Related Guides
- [How to Set the PHP Version per Domain in cPanel](/cpanel/how-to-set-a-different-php-version-per-domain-in-cpanel/)
- [How to Set the PHP Version per Directory in cPanel](/cpanel/how-to-set-the-php-version-per-directory-in-cpanel/)
- [How to Reset the PHP Version to the Default Version in cPanel](/cpanel/how-to-reset-the-php-version-to-the-default-in-cpanel/)
- [How to Change the PHP Version via CloudLinux Selector in cPanel](/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/)
- [Fix PHP Error: Allowed Memory Size of X Bytes Exhausted](/server-administration/fix-php-error-allowed-memory-size-of-x-bytes-exhausted/)
## Need a hand?
Switching PHP version is a two-click job when the application is ready for it, and a long afternoon when it is not. If you are unsure which version a site can safely run, if the version you need is not in the drop-down, or if the site broke the moment you applied the change, open a ticket in the Noiz client area with your domain name and the exact error you are seeing, and the support team will sort it out with you.
# How to Change the cPanel Theme or Style
Source: https://docs.noiz.ie/cpanel/how-to-change-the-cpanel-theme-or-style/
If you are looking for where to change how your **cPanel** interface looks, this guide explains the current position. The short version is that cPanel no longer offers individual users a theme or style picker. Since cPanel and WHM version 110 (released March 2023), the older **paper\_lantern** theme and its per-user style switching were removed, and **Jupiter** is now the single standard cPanel interface. The overall look is set on the server by your hosting provider, so there is no drop-down inside your account for choosing a different theme.
Older tutorials (including earlier versions of this article) described a **Theme** drop-down in a **General Information** panel, or a **Change Style** tile under Preferences. Those belonged to paper\_lantern and no longer appear in current cPanel.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel and WHM. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Preferences interfaces (docs.cpanel.net)](https://docs.cpanel.net/cpanel/preferences/)
- [cPanel and WHM version 110 change log, documenting the paper\_lantern removal (docs.cpanel.net)](https://docs.cpanel.net/changelogs/110-change-log/)
## Why the theme switcher is gone
For years cPanel shipped two interfaces: the older **paper\_lantern** theme, which let each user pick a colour "style", and the newer **Jupiter** theme. In version 110, cPanel removed paper\_lantern entirely, along with the style routing that powered the old switcher. Jupiter became the only theme, which means every cPanel account now presents the same, consistent interface.
The screenshot below shows the retired paper\_lantern **Theme** drop-down. It is kept here only so you can recognise it in old tutorials; this control no longer exists in current cPanel.

## How your cPanel looks now
Your account uses the Jupiter theme. Its appearance, including any branding or colour styling, is configured at the server level by Noiz rather than per account, so there is no user setting to change it. If your cPanel looks different from a screenshot in an old article, that is almost always because the article predates Jupiter.
## What you can still personalise
You cannot swap the theme, but a couple of genuine per-user options remain in the **Preferences** section of cPanel:
- **Change Language** displays the whole interface in a different language.
- **Account Preferences** and **Contact Information** control notification and contact settings. They adjust behaviour rather than appearance, but they are the other user-editable preferences.
Beyond those, the way to influence how your cPanel is presented is a request to your host.
## Troubleshooting
**A guide tells me to open a Theme or Change Style menu, but I cannot find it**: that menu belonged to the paper\_lantern theme, which cPanel removed in version 110. There is no replacement picker in Jupiter, so the guide is out of date.
**I want a different look for cPanel on my Noiz hosting**: theme and branding are set on the server, so raise it with Noiz support rather than looking for an in-account option.
## Need a hand?
If you have a specific requirement for how cPanel is presented on your Noiz hosting, contact the Noiz support team through the client area and the team will advise on what is possible.
# How to Check Disk and Bandwidth Usage in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-check-disk-and-bandwidth-usage-in-cpanel/
If cPanel shows a disk space warning, or you want to know what is eating into your monthly bandwidth, cPanel has two built-in tools that break the numbers down for you. This guide shows you where to find **Disk Usage** and **Bandwidth** on Noiz hosting, how to read what they report, and the caveats worth knowing before you start deleting things.
**Last reviewed:** 27 July 2026, against cPanel & WHM (Jupiter interface, latest stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Disk Usage interface](https://docs.cpanel.net/cpanel/files/disk-usage/)
- [cPanel Bandwidth interface](https://docs.cpanel.net/cpanel/metrics/bandwidth/)
## Prerequisites
- A Noiz hosting account on a cPanel plan, and your cPanel login.
## Check your disk usage
**1.** Log in to your cPanel account.
**2.** In the **Files** section, click **Disk Usage**.

**3.** The **Disk Usage** page lists how much space each directory in your home folder is using, so you can quickly spot the folders responsible for the bulk of your usage. The figures also include the size of your MySQL and PostgreSQL databases.

A few things worth knowing when you read this page:
- The mail store often accounts for far more space than people expect. Old messages, large attachments and full mailboxes all count towards your quota. For a per-mailbox breakdown, use the separate **Email Disk Usage** tool, also in the **Files** section.
- The totals can lag. cPanel notes that the figures may not reflect very recent changes, so if you have just deleted a large folder, give it a little time before the number catches up.
- Hidden folders and system directories (names beginning with a dot) are included in the totals even though they are easy to miss in File Manager.
## Check your bandwidth usage
**1.** In the **Metrics** section, click **Bandwidth**.

**2.** The **Bandwidth** page shows the traffic your account has used, with a graph and a breakdown by service. cPanel measures bandwidth across HTTP (web), FTP, and email traffic, then adds them into a combined total.

Keep in mind:
- The email figure counts **sent** mail (SMTP). Messages you download by POP3 or IMAP are not added to your bandwidth total, so heavy inbound email will not show here.
- Bandwidth is measured over a rolling period and resets on schedule, so a spike near the end of a period does not carry over indefinitely.
- Use the date and service filters at the top of the page to see whether a jump came from web traffic or from mail.
## Troubleshooting
**Disk usage looks higher than the files you can see**: databases, the mail store and hidden dot-directories all count towards the total. Check **Email Disk Usage** and your database sizes before assuming the figure is wrong.
**The number did not drop after deleting files**: the Disk Usage figures can lag behind recent changes. Wait a short while and reload the page.
**Bandwidth is climbing fast**: filter the Bandwidth page by service to identify the source. A sudden rise in HTTP traffic can indicate a busy site or, occasionally, unwanted bot activity worth investigating.
If you are close to a limit and are not sure what is driving it, or you would like Noiz to review your usage with you, contact the Noiz support team and they will be glad to help.
# How to Create Addon Domains in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-addon-domains-in-cpanel/
An addon domain lets you host a completely separate website from inside your existing cPanel account. The addon domain gets its own document root, its own email addresses and its own DNS records, yet it lives within the hosting account you already pay for. To visitors it looks and behaves like a fully independent website.
This guide shows you how to add an addon domain in current cPanel, where the old standalone **Addon Domains** tool has been folded into a single **Domains** interface.
**Last reviewed:** 27 July 2026, against current cPanel & WHM. Since cPanel version 90 the separate **Addon Domains**, **Aliases** and **Subdomains** tools were consolidated into one **Domains** interface, so the steps below use that interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Domains interface](https://docs.cpanel.net/cpanel/domains/domains/): the current tool for creating and managing addon domains, aliases and subdomains.
## Prerequisites
- The domain you want to add is registered and, ideally, not actively hosted somewhere else.
- The addon domain points at your hosting *before* you add it. Set its nameservers to the same nameservers your primary Noiz hosting domain already uses (typically `ns1.noiz.co.za` and `ns2.noiz.co.za`), then allow time for propagation. DNS changes usually take between a few hours and 24 hours to take effect worldwide.
- Your hosting plan has an addon domain slot free. If you have reached your plan limit, contact Noiz support to upgrade.
## Add an Addon Domain
### 1. Open the Domains interface
Log in to your cPanel account, then in the **Domains** section click **Domains**. On older cPanel themes this icon may still be labelled **Addon Domains**.

### 2. Start a new domain
Click **Create A New Domain** (on older builds this is the **Create an Addon Domain** form), then complete the fields:
- **Domain:** the addon domain name you want to host, for example `example2.com` (replace this with your own domain).
- **Document Root:** cPanel fills this in automatically from the domain name. Leave it as suggested unless you have a specific reason to change it.
- **Share document root:** leave the **Share document root...** option *unticked* so the addon domain gets its own separate folder and does not serve the same files as your primary domain.

### 3. Submit
Click **Submit** (labelled **Add Domain** on older builds). cPanel creates the addon domain, its document root folder and a matching DNS zone.

You should see a confirmation message that the addon domain has been created. It goes live once DNS has fully propagated.
## Good to Know
- **An addon domain also creates a subdomain.** cPanel automatically creates a subdomain of your primary domain (for example `example2.yourprimary.com`) that points at the same files. This is expected behaviour and can be ignored.
- **Upload your website files to the addon domain's own document root**, not your primary `public_html` folder. Use the cPanel File Manager or an FTP/SFTP client.
- **Email, DNS and SSL for the addon domain** are all managed from the same cPanel account. Once DNS points at the server you can issue a free SSL certificate for the addon domain from the **SSL/TLS Status** area.
## Troubleshooting
**Symptom:** "The domain already exists" or a warning that the domain is not registered or not pointing here. The domain may already be added to another cPanel account on the server, or its nameservers are not yet pointing to your hosting. Confirm the nameservers, wait for propagation, then try again.
**Symptom:** the addon domain shows your primary website instead of its own content. The **Share document root** option was left ticked, so both domains serve the same folder. Remove and re-add the domain with that option unticked, or move your files into the addon domain's own document root.
**Symptom:** the site does not load after you add it. DNS propagation is usually the cause. Allow up to 24 hours, then re-check. Also confirm you have uploaded content to the correct document root.
## Need a Hand?
If your addon domain will not resolve, or you are unsure which nameservers to use, Noiz support can check the DNS and account configuration for you. Open a ticket from your Noiz client area and include the addon domain name.
# How to Create Folders and Files in the cPanel File Manager
Source: https://docs.noiz.ie/cpanel/how-to-create-folders-and-files-in-the-cpanel-file-manager/
The cPanel **File Manager** lets you create, organise, and edit your website files directly in your browser, without needing a separate FTP client. This guide shows you how to create a new **folder** and a new **file** inside File Manager, and points out the naming details that trip people up on Linux hosting.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel and WHM (the **Jupiter** theme, which is now the default). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel File Manager (docs.cpanel.net)](https://docs.cpanel.net/cpanel/files/file-manager/)
## Prerequisites
- Access to your cPanel account (your Noiz welcome email contains the login details).
- An idea of where the new folder or file needs to live. Your public website files sit inside `public_html`.
## Create a New Folder
1. Log in to your cPanel account.
2. In the **Files** section, click **File Manager**. 
3. Navigate to the directory where you want the new folder. To place it on your live website, open `public_html` first.
4. On the toolbar at the top, click **+ Folder**. 
5. In the **New Folder Name** field, type a name such as `my-folder`, then click **Create New Folder**. The new folder appears in the current directory. 
## Create a New File
1. Navigate to the directory where you want the new file.
2. On the toolbar at the top, click **+ File**. 
3. In the **New File Name** field, type a name such as `myfile.txt`, then click **Create New File**. The empty file appears in the current directory, ready for you to edit.
## Naming Tips and Common Gotchas
- **Linux is case-sensitive.** On Noiz hosting servers, `MyFile.txt` and `myfile.txt` are two different files. Pick a convention (lowercase is a safe default) and stick to it, or links pointing at the wrong casing will return a "not found" error.
- **Avoid spaces in names.** Use hyphens (`my-folder`) or underscores (`my_folder`) instead of spaces, so your files behave predictably in URLs and on the command line.
- **Hidden files start with a dot.** Files such as `.htaccess` are hidden by default. To see or create them, open **Settings** at the top right of File Manager and tick **Show Hidden Files (dotfiles)**.
- **Location decides what is public.** Anything inside `public_html` is served on your main domain. Files kept outside the document root stay private and are not reachable from the web.
## Need a hand?
If you are on a managed Noiz plan and would rather have files created, moved, or edited for you, contact the Noiz support team through the client area and the team will assist.
# How to Create a Cron Job in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-a-cron-job-in-cpanel/
A cron job is a task your hosting account runs automatically on a schedule you set, so a script runs by itself at a fixed time instead of you having to trigger it by hand. This guide shows you how to create a cron job in cPanel on Noiz hosting, how to write the command correctly, and the gotchas worth knowing before you schedule one.
**Last reviewed:** 27 July 2026, against cPanel & WHM (Jupiter interface, latest stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Cron Jobs interface](https://docs.cpanel.net/cpanel/advanced/cron-jobs/)
## Prerequisites
- A Noiz hosting account on a cPanel plan, and your cPanel login.
- The full path to the script you want to run, or the command you would normally type at the shell.
## Create the cron job
**1.** Log in to your cPanel account.
**2.** In the **Advanced** section, click **Cron Jobs**.

**3.** Under **Add New Cron Job**, open the **Common Settings** drop-down and choose how often the job should run, for example **Once Per Day**. cPanel fills in the five schedule fields (**Minute**, **Hour**, **Day**, **Month** and **Weekday**) for you. You can adjust any of these fields by hand afterwards if you need a more specific time.
**4.** In the **Command** field, enter the command you want to run. Use the full path to the interpreter and to your script rather than a relative path. For a PHP script, that usually looks like this:
```
/usr/local/bin/php /home/username/public_html/cron/script.php
```
To run a script by requesting its URL instead, use `wget` or `curl`:
```
wget -q -O /dev/null https://yourdomain.com/cron/script.php
```
Replace `username`, the path and `yourdomain.com` with your own values.
**5.** Click **Add New Cron Job**. The job appears in the **Current Cron Jobs** table lower down the page, where you can edit or delete it at any time.

## Understanding the schedule fields
Each cron job is defined by five time fields, read left to right:
- **Minute** (0 to 59), **Hour** (0 to 23), **Day of month** (1 to 31), **Month** (1 to 12) and **Weekday** (0 to 6, where 0 is Sunday).
- An asterisk (`*`) means "every". So `0 3 * * *` runs at 03:00 every day, and `*/15 * * * *` runs every fifteen minutes.
The **Common Settings** drop-down is simply a shortcut that writes these values for you, which is the easiest way to start.
## The email notification gotcha
By default cPanel emails the output of every cron run to the address shown in the **Cron Email** box at the top of the page. A job that prints anything, even a routine success message, will send you an email on every single run, which quickly becomes noise. To keep only genuine errors, discard the normal output by adding this to the end of your command:
```
/usr/local/bin/php /home/username/public_html/cron/script.php >/dev/null 2>&1
```
Set a real address in **Cron Email** while you are testing a new job, then tidy the output once you are happy it works.
## Troubleshooting
**The job never seems to run**: check that you used full paths for both the interpreter and the script, and that the script has execute permission. A relative path such as `script.php` on its own will usually fail because cron does not run from your web directory.
**You are flooded with cron emails**: the script is producing output on every run. Redirect it with `>/dev/null 2>&1` as shown above so only real errors reach your inbox.
**The site slows down or the job overlaps itself**: you have scheduled it too frequently. Leave enough time between runs for the previous one to finish, and avoid one-minute intervals unless the task genuinely needs them.
**The Cron Jobs icon is missing**: cron access can be switched off at the plan level. If you do not see it in the **Advanced** section, contact the Noiz support team.
If you are unsure which command to schedule, or a cron job is not behaving as expected, contact the Noiz support team and they will be glad to help you set it up.
# How to Create a MySQL Database User in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-a-mysql-database-user-in-cpanel/
This guide shows you how to create a MySQL database user in cPanel on your Noiz hosting account. A database user (sometimes called a database username or MySQL login) is the account your website or application uses to connect to a database. Creating the user is one half of the job: on its own a new user cannot touch any data until you attach it to a database and grant it privileges, which is covered at the end of this guide.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM release using the default **Jupiter** interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel ยป MySQL Databases](https://docs.cpanel.net/cpanel/databases/mysql-databases/): the full reference for creating users, databases, and assigning privileges.
- [cPanel ยป Manage MySQL Databases](https://docs.cpanel.net/cpanel/databases/manage-mysql-databases/): editing privileges and removing users after they exist.
## Prerequisites
- An active Noiz hosting account with cPanel access.
- Your cPanel login details (sent in your welcome email, or available from the Noiz client area).
## Create the MySQL User
1. Log in to your cPanel account.
2. In the **Databases** section, click **MySQL Databases**. 
3. Scroll down to the **MySQL Users** heading and find **Add New User**.
4. In the **Username** field, type the name for the new user.
5. Enter a password in the **Password** and **Password (Again)** fields, or click **Password Generator** to have cPanel create a strong one for you. Aim for a strength score of **Very Strong**. 
6. Click **Create User**.
cPanel confirms the new user and returns you to the MySQL Databases page.
## What You Need to Know Before You Start
- **Your account name is added automatically.** cPanel prefixes every database user with your account username and an underscore. If you type `appuser` and your account is `example`, the real login becomes `example_appuser`. Always use the full prefixed name in your application's configuration file.
- **Keep the name short.** The full prefixed username has a length limit (32 characters on current MySQL/MariaDB, and older setups cap it at 16). If cPanel refuses a long name, shorten the part you typed.
- **Passwords must be strong.** The server enforces a minimum password strength, so a weak password is rejected on submit. The built-in **Password Generator** is the quickest way to satisfy it.
- **A new user has no access yet.** Creating a user does not connect it to any database. Until you grant privileges, connection attempts fail with an access-denied error even though the login exists.
## Next Step: Grant the User Access to a Database
To make the user usable, attach it to a database:
1. On the same **MySQL Databases** page, scroll to **Add User to Database**.
2. Choose the new user from the **User** menu and the target database from the **Database** menu, then click **Add**.
3. On the privileges screen, tick **ALL PRIVILEGES** for a standard application, then click **Make Changes**.
If you have not created the database yet, do that first in the **Create New Database** section at the top of the same page.
## Troubleshooting
**Symptom**: "The username you have chosen is too long." Shorten the part you typed; remember cPanel adds your account prefix, which counts towards the limit.
**Symptom**: The password is rejected on submit. It does not meet the required strength. Use the **Password Generator** or add length and a mix of upper case, lower case, numbers and symbols.
**Symptom**: The application reports "Access denied for user" after you created the login. The user exists but has not been added to the database. Complete the *Next Step* above to grant privileges.
**Tip:** Record the full (prefixed) database username and password somewhere safe. You will need both when configuring an application manually, and cPanel does not display the password again after creation.
If you would rather Noiz set this up for you, or you run into trouble, open a ticket from the Noiz client area and the support team will assist.
# How to Create a MySQL Database in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-a-mysql-database-in-cpanel/
This guide shows you how to create a MySQL database from within cPanel. A database is where applications such as WordPress, Joomla, PrestaShop and most content management systems store their content and settings. Creating the database is only the first half of the job: on its own an empty database cannot be used until you also create a database user and grant that user access to it, so this guide covers that essential next step too.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable release). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel ยป MySQL Databases](https://docs.cpanel.net/cpanel/databases/mysql-databases/) is the reference for every field on this screen.
- [cPanel ยป MySQL Database Wizard](https://docs.cpanel.net/cpanel/databases/mysql-database-wizard/) is a guided alternative that creates the database, its user and the privileges in one flow.
## Prerequisites
- A Noiz hosting account with cPanel access.
- Your cPanel username and password, or single sign-on from the Noiz client area.
## Create the database
1. Log in to your cPanel account.
2. In the **Databases** section, click **MySQL Databases**. 
3. Under **Create New Database**, type a name for the database in the **New Database** field. Read the note on naming below before you decide on a name. 
4. Click **Create Database**. cPanel confirms that the database was added. 
### How cPanel names your database
cPanel automatically prefixes the database name with your cPanel username and an underscore. If your username is `example` and you type `shop`, the real database name becomes `example_shop`. Always use this full, prefixed name when you configure an application or a connection string, otherwise the connection fails with an "unknown database" error. Database names are limited in length and may contain only letters, numbers and underscores.
## Create a user and grant access
An empty database is not usable until a MySQL user is attached to it. This is the step most people miss. On the same **MySQL Databases** page:
1. Scroll to **MySQL Users**, then **Add New User**. Enter a username and a strong password, then click **Create User**. As with databases, the username is prefixed with your cPanel username, for example `example_appuser`.
2. Scroll to **Add User to Database**, select the new user and the new database, then click **Add**.
3. On the privileges screen, tick **ALL PRIVILEGES** for a standard application, then click **Make Changes**.
You now have four values to give your application: the database name, the database username, that user's password, and the database host, which is `localhost` on Noiz cPanel hosting.
### Faster alternative: the MySQL Database Wizard
If you would rather create the database, its user and the privileges in one guided sequence, open **MySQL Database Wizard** from the **Databases** section instead. It walks you through the same three steps across a single set of pages.
## Troubleshooting
**Application cannot connect, or reports the database does not exist**: confirm you used the full prefixed database name (`username_dbname`), that the user has been added to the database, and that the host is set to `localhost`.
**"Access denied" for the database user**: re-open **Add User to Database** and confirm the user is assigned to the database with the privileges the application needs.
**You need to connect from your own computer or an external server**: local, same-server connections use `localhost`. Remote connections must first have your IP address authorised under **Remote MySQL** in the **Databases** section, and then connect to the server hostname rather than `localhost`.
## Need a hand?
If you are on a Noiz managed plan, the support team can create databases, users and privileges for you, or check a connection that will not come up. Open a ticket from the Noiz client area and include the application you are connecting and the exact error message.
# How to Create a Subdomain in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-a-subdomain-in-cpanel/
A subdomain is a separate section of your existing domain that lives under it, such as `blog.yourdomain.com` or `shop.yourdomain.com`. It works like an independent website (its own folder, its own content) while still belonging to your main domain, and it costs nothing extra to add. This guide shows you how to create one from cPanel on your Noiz hosting account.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable, Jupiter theme). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
One important change to know first: cPanel now manages subdomains from its unified **Domains** interface. The old, dedicated **Subdomains** tool was consolidated into **Domains** in cPanel version 100, so on current accounts you create a subdomain simply by adding a domain that sits beneath one you already own. The steps below cover that current method, and also the legacy **Subdomains** screen you may still see on older cPanel builds.
### Official Documentation Reference
- [cPanel Documentation: Domains interface](https://docs.cpanel.net/cpanel/domains/domains/)
## Prerequisites
- An active Noiz hosting account with cPanel access.
- The parent domain (your primary domain, or an addon domain) already added to the account. A subdomain can only be created beneath a domain cPanel already knows about.
## Create a Subdomain (Current cPanel)
1. Log in to your cPanel account.
2. In the **Domains** section, click **Domains**. 
3. Click **Create A New Domain**.
4. In the **Domain** box, type the full subdomain you want, for example `blog.yourdomain.com` (replace `yourdomain.com` with your own domain). Because the parent domain is already on the account, cPanel recognises the entry as a subdomain automatically.
5. Decide where the subdomain's files will live. By default, **Share document root** is ticked, which makes the subdomain serve the same files as its parent domain. To give the subdomain its own separate website, untick **Share document root** and confirm the **Document Root** path that cPanel suggests, such as `/home/user/blog.yourdomain.com`. 
6. Click **Submit**.
cPanel confirms that the subdomain has been created and, on Noiz hosting, adds the required DNS record for you automatically. Allow a short time for the change to propagate before the subdomain resolves in a browser.
### Older cPanel: the Legacy Subdomains Tool
If your account is on an older cPanel version, you may still see a dedicated **Subdomains** icon in the **Domains** section instead of doing this from **Domains > Create A New Domain**. The result is identical. On that screen you type the subdomain into the **Subdomain** field, choose the parent domain from the drop-down list, let the **Document Root** populate (or edit it), and click **Create**.
## After Creating the Subdomain
- **Upload your content.** If you gave the subdomain its own document root, that folder starts empty. Upload your site's files into it (via File Manager or FTP) or the subdomain will show an empty page or a "not found" error until you do.
- **Shared versus separate content.** If you left **Share document root** ticked, the subdomain shows exactly the same content as its parent domain. Untick it if you want the subdomain to be an independent site.
- **DNS and nameservers.** Subdomains resolve automatically only when the parent domain points at Noiz. Confirm the domain uses the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za`.
## Troubleshooting
- **You cannot select or add the domain**: the parent domain must already exist on the account. Add it first (as your primary or an addon domain), then create the subdomain beneath it.
- **The subdomain shows the parent site's content**: **Share document root** was left ticked. Remove the subdomain and recreate it with its own document root, or point it at a separate folder.
- **The subdomain does not load yet**: DNS changes can take a little time to propagate. Allow up to a few hours, and confirm the domain is using the Noiz nameservers above.
- **You see a 404 or an empty page**: the subdomain's document root has no files in it yet. Upload your website files into that folder.
If you would like Noiz to set up a subdomain for you, or if it is not resolving as expected, contact Noiz support from your client area and the team will assist.
# How to Create a Vacation Email Autoresponder in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-a-vacation-email-autoresponder-in-cpanel/
When you are away on holiday, off sick, or simply unavailable for a while, an email autoresponder replies to anyone who writes to you with a message you set in advance. The sender is told when to expect a reply, or who to contact in the meantime, and your normal mail still lands in your inbox as usual. This guide shows you how to create and later remove an autoresponder on a Noiz cPanel hosting account.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable release, Jupiter theme). This guide is written for Noiz cPanel hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: Autoresponders](https://docs.cpanel.net/cpanel/email/autoresponders/)
## Prerequisites
- A Noiz cPanel hosting account that you can sign in to.
- The email account you want to auto-reply from already created on that domain (for example `support@yourdomain.com`).
## Create an Autoresponder
1. Sign in to your cPanel account.
2. In the **Email** section, click **Autoresponders**.

3. On the **Autoresponders** page, click **Add Autoresponder**.
4. Complete the form:
- **Character Set:** Leave this as `utf-8` unless you have a specific reason to change it. `utf-8` handles accented and non-English characters correctly.
- **Interval:** The number of hours cPanel waits before it replies to the same sender again. A sender who writes to you three times within the interval receives only one auto-reply. Set this to a sensible value such as `24`. Avoid `0`, which replies to every single message and can create a mail loop if the other side is also running an autoresponder.
- **Email:** The local part of the address you are enabling the autoresponder on. To reply from `support@yourdomain.com`, enter **support** here.
- **Domain:** Select the correct domain from the drop-down list if the account holds more than one.
- **From:** The name that the auto-reply appears to come from, for example your own name or your team name.
- **Subject:** The subject line of the auto-reply, for example `Out of office until 5 August`.
- **This message contains HTML:** Tick this box only if you have written the body in HTML. Leave it clear for plain text.
- **Body:** The message senders receive. Keep it short and tell people when you will be back and who to contact for anything urgent.
Inside the **Subject** and **Body** fields you can insert the tags `%subject%`, `%from%` and `%email%`. cPanel replaces these with the original message's subject, the sender's name and the sender's address, so you can personalise each reply.
5. Under **Start**, choose **Immediately** to begin now, or **Custom** to pick a date and time. Under **Stop**, choose **Custom** and set the date your holiday ends. Leaving it on **Never** means the autoresponder keeps replying until you delete it by hand.

6. Click **Create**. cPanel confirms the autoresponder and it appears under **Current Autoresponders**.
## Remove an Autoresponder
1. In the **Email** section, click **Autoresponders**.
2. Find the address under **Current Autoresponders**.
3. Click **Delete** to the right of that address.

4. Confirm with **Delete Autoresponder**.
## Good to Know
- An autoresponder does not hold, block, or filter your incoming mail. Every message still arrives in your inbox as normal; the auto-reply is simply sent in addition.
- If you set a **Stop** date, remember it is the moment replies stop. Set it to when you are actually back at your desk, not the day you leave.
- Only messages that arrive while the autoresponder is active receive a reply. Mail that arrived before you enabled it is not answered retrospectively.
## Need a Hand?
If your autoresponder is not sending as expected, or you would like Noiz to set one up for you, open a support ticket from your Noiz client area and the team will assist.
# How to Create an Additional Web Disk Account in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-an-additional-web-disk-account-in-cpanel/
cPanel's **Web Disk** feature (also called WebDAV, or Web Folders on Windows) lets you mount your hosting account's files as a drive on your computer, so you can drag, drop, open and save files directly instead of using an FTP client or File Manager.
Your main cPanel username and password already work with Web Disk and give access to the whole home directory. This guide covers the other option: creating an **additional Web Disk account**, which is a separate login restricted to one folder. That is what you want when a designer, a client, a photographer or a backup script needs access to a single directory and nothing else.
**Last reviewed:** 27 July 2026, against current cPanel & WHM releases using the **Jupiter** interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: Web Disk](https://docs.cpanel.net/cpanel/files/web-disk/)
- [cPanel Knowledge Base: How to Configure Web Disk](https://docs.cpanel.net/knowledge-base/web-services/how-to-configure-web-disk/)
## Prerequisites
- A hosting plan that uses cPanel, and your cPanel login details. If the screens below do not match what you see, your plan is on a different control panel, so contact Noiz support and the equivalent steps will be sent to you.
- The folder you want to share, or at least the path you want it created at, for example `public_html/folderx`.
- A device that supports WebDAV (Windows File Explorer, macOS Finder, or a client such as Cyberduck).
## Create the Additional Web Disk Account
### 1. Log in to cPanel
Sign in to your cPanel account using the URL and credentials supplied by Noiz.
### 2. Open Web Disk
In the **Files** section, click **Web Disk**.

### 3. Fill in the new account details
Scroll to **Create an Additional Web Disk Account** and complete the form.

- **Username:** Enter a short name such as `folderx` and pick the domain beside it. The login the person actually uses is the full address, for example `folderx@yourdomain.com`, not the short name on its own. This trips up almost everyone the first time they connect.
- **Password:** Type a password, or click **Password Generator** for a strong random one. Copy it somewhere safe before you leave the page, because cPanel will not show it again.
- **Directory:** Enter the folder this login should be limited to, for example `public_html/folderx`. The path is relative to your home directory, and cPanel creates the folder if it does not already exist. Leaving the field blank grants access to the *entire* home directory, including `mail`, `logs` and any files outside `public_html`, so only do that deliberately.
- **Permissions:** Choose **Read-Write** if the person needs to upload, edit and delete, or **Read-Only** if they should only download and view. Read-Only is the safer default for anyone outside your organisation.
**Note on Digest Authentication:** tick **Enable Digest Authentication** only if the account will be used from Windows and you cannot make an SSL connection on port `2078`. Where the server has an SSL certificate signed by a recognised certificate authority and port `2078` is reachable, leave it off and connect over SSL instead, which is both simpler and more secure.
### 4. Create the account
Click **Create**. The new account appears in the **Manage Additional Web Disk Accounts** list, where you can later change its password or permissions, or delete it.
## Connecting to the New Account
Once created, the account is used exactly like the main one. From the **Manage Additional Web Disk Accounts** list, click **Configure Client Access** beside the account to get an operating-system-specific setup script and the connection details.
Full connection instructions for Windows, macOS and third-party clients are covered here: [How to Access cPanel Web Disk](/cpanel/how-to-access-cpanel-web-disk/).
The two ports involved are `2078` for SSL connections and `2077` for unencrypted connections. Always use `2078` unless you have a specific reason not to, since credentials sent over `2077` travel in the clear.
## Things Worth Knowing Before You Hand Out the Login
- **Storage is shared, not separate.** Additional Web Disk accounts do not get their own quota. Everything uploaded through them counts against your hosting plan's disk space.
- **Restriction is by folder, not by file type.** A Read-Write account can overwrite or delete anything inside its directory, including files you put there yourself.
- **Files inside `public_html` are publicly reachable.** If the folder sits under `public_html`, anything placed in it can be downloaded by anyone who knows or guesses the URL. For private file exchange, use a directory outside `public_html`, such as `webdisk-share` in your home directory.
- **Deleting the account does not delete the files.** Removing a Web Disk account only revokes the login. The directory and its contents remain on the account.
- **One account per person.** Resist sharing a single login between several people. Separate accounts mean you can revoke one without disrupting everyone else.
## Troubleshooting
**Symptom: the login is rejected.** Check that the full username including the domain is being used, for example `folderx@yourdomain.com`. Re-enter the password from cPanel rather than retyping it from memory.
**Symptom: the connection times out.** Port `2078` is often blocked on office, school and public networks. Test from a different connection, such as a mobile hotspot, to confirm before assuming a server fault.
**Symptom: Windows connects but the drive is read-only or drops out.** Confirm the account was created with **Read-Write** permissions, and use the **Configure Client Access** script from cPanel rather than mapping the drive by hand. Older Windows builds also need Digest Authentication enabled when SSL is not in use.
**Symptom: the person sees more folders than expected.** The **Directory** field was left blank or set too high in the tree. Delete the account and recreate it with the exact path, for example `public_html/folderx`.
## Need a Hand?
If the Web Disk account will not connect, or you would like Noiz to set up a restricted folder and login on your behalf, open a ticket from your Noiz client area with the domain name and the folder path you have in mind, and the Noiz support team will take it from there.
# How to Create an Alias or Park a Domain in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-an-alias-or-park-a-domain-in-cpanel/
An **alias** (cPanel's current name for what used to be called a **parked domain**) lets an extra domain name show the exact same website as your main domain. Use it to point both `yourbrand.co.za` and `yourbrand.com` at one site, to catch a common misspelling of your domain, or to reserve a name you have registered but not yet built out. This guide shows you how to add an alias in cPanel and explains how an alias differs from an addon domain and a subdomain.
**Last reviewed:** 27 July 2026. These steps follow the unified **Domains** interface that cPanel introduced in version 100, when the separate **Aliases** tool was merged into it. They remain current in the latest cPanel & WHM releases. This guide is written for Noiz hosting and complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel: The Domains interface](https://docs.cpanel.net/cpanel/domains/domains/)
- [cPanel: Create a New Domain](https://docs.cpanel.net/cpanel/domains/domains/create-a-new-domain/)
## Prerequisites
- A cPanel account on Noiz hosting, and your cPanel login details.
- The domain you want to add already registered in your name.
- The domain pointed at the Noiz nameservers, `ns1.noiz.co.za` and `ns2.noiz.co.za`, at its registrar. Until the domain resolves to Noiz, the alias will not load your website. Nameserver changes can take up to 24 to 48 hours to propagate.
## Create a Domain Alias in cPanel
1. Log in to your cPanel account.
2. In the **Domains** section, click **Domains**. 
3. Click **Create A New Domain**.
4. In the **Domain** box, type the domain you want to park, for example `yourdomain.com`. 
5. Leave the **Share document root (`.../public_html`) with "yourmaindomain.com"** box ticked. Sharing the document root is what makes the new domain an alias, so both names serve the same website. If you untick it and set a separate folder, cPanel creates an addon domain instead.
6. Click **Submit**.
The new domain now appears in your **Domains** list, marked as an alias, and serves the same website as your main domain.

Screens vary slightly between cPanel versions and themes, so the exact layout may differ from the images above, but the field and button names are the same.
## Alias, Addon Domain or Subdomain?
cPanel lets you attach three kinds of domain to your account. Choosing the right one avoids duplicate content and wasted setup.
- **Alias (parked domain):** a second domain that shows the same website as your main domain. Best for alternative spellings, other extensions of your brand, or names you are simply holding.
- **Addon domain:** a completely separate website with its own folder, hosted under the same cPanel account. Choose this when the domain needs its own content.
- **Subdomain:** a section of your existing domain, such as `shop.yourdomain.com`, with its own folder.
## Troubleshooting
**The alias does not load your website:** confirm the domain's nameservers are set to `ns1.noiz.co.za` and `ns2.noiz.co.za` at the registrar, then allow time for DNS to propagate before testing again.
**cPanel rejects the domain:** the domain may already be added to another hosting account on the server, or it may not yet point to Noiz. A domain can be aliased on only one account at a time.
**You want the alias to redirect rather than mirror the site:** an alias always shows the same site. To send visitors to a different address instead, set up a redirect from the **Domains** list.
## Need a hand?
If your alias will not resolve, or you are not sure which nameservers your domain currently uses, the Noiz support team can check it for you. Open a ticket from your [Noiz client area](https://www.noiz.co.za) and include the domain name you are trying to park.
# How to Create an Email Account in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-an-email-account-in-cpanel/
An email account gives you a mailbox at your own domain, such as `you@yourdomain.com`, that you can read in webmail or set up in Outlook, Apple Mail or your phone. This guide shows you how to create a new email account in cPanel on Noiz hosting, and explains the choices on the create screen so your mailbox is set up correctly the first time.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM Jupiter interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Docs: Email Accounts](https://docs.cpanel.net/cpanel/email/email-accounts/)
## Prerequisites
- Your cPanel sign-in details, which are in your Noiz hosting welcome email or available from your [Noiz client area](https://www.noiz.co.za).
- A domain that already points to your Noiz hosting. Email for a domain only works once that domain is added to the account and its DNS is pointed at Noiz.
## Create the Email Account
1. Log in to your cPanel account.
2. In the **Email** section, click **Email Accounts**. 
3. Click **+ Create** on the right-hand side of the Email Accounts page.
4. Under **Create an Email Account**, fill in the details described below. 
5. Click **Create**.
## What Each Field Means
- **Domain:** If the account holds more than one domain, choose the domain the mailbox should belong to from the drop-down. This is the part after the `@` in the address.
- **Username:** The part before the `@`, for example `info`, `sales` or your first name. Together with the domain this becomes the full address, such as `info@yourdomain.com`.
- **Security:** Choose **Set password now** and type a password, or click **Generate** to have cPanel create a strong one for you. cPanel shows a strength meter and will reject a weak password, so aim for a long mix of letters, numbers and symbols. Keep a note of the password; you will need it to log in to webmail and to set the mailbox up on a phone or mail app.
- **Optional Settings:** Click **Edit Settings** to expand this section. Under **Storage Space**, set a mailbox size in megabytes or tick **Unlimited** to let the mailbox grow up to the space available on your plan. You can also choose whether cPanel automatically creates folders for plus addressing (subaddresses such as `info+news@yourdomain.com`).
## After the Account Is Created
Once you click **Create**, the new mailbox appears in the list on the Email Accounts page, under the **Account @ Domain** column.

From the same list you can manage the mailbox at any time: use **Manage** to change the password or storage quota, **Check Email** to open webmail, or **Connect Devices** to see the incoming and outgoing server settings for setting the mailbox up in Outlook, Apple Mail or a phone.
## Good to Know
- **Reach your new mailbox straight away** at `https://webmail.yourdomain.com`, or by clicking **Check Email** next to the account. Sign in with the full email address and the password you set.
- **Set a sensible quota.** Every mailbox shares the disk space on your hosting plan. A generous fixed quota is usually safer than Unlimited, because it stops one mailbox from filling the whole account if it is ever flooded with mail.
- **The default address is not the same thing.** Creating a mailbox does not change the domain's default (catch-all) address. Manage that separately under the Email section if you need to control where mail to unknown addresses goes.
## Troubleshooting
**cPanel will not accept the password**: the strength meter has judged it too weak. Use a longer password with a mix of upper and lower case letters, numbers and symbols, or click **Generate** and copy the suggested one.
**The domain you want is not in the drop-down**: that domain has not been added to the account yet, or its DNS is not pointed at Noiz. Add the domain first, then create the mailbox.
**New mail is not arriving**: give DNS a little time to update after a domain is first pointed at Noiz, and check that mail is not being caught by a filter. If it still does not arrive, contact Noiz support.
## Need a Hand?
If you are on a Noiz managed hosting plan and would like a mailbox created or configured for you, open a support ticket from your [Noiz client area](https://www.noiz.co.za) and the support team will set it up and confirm it is working.
# How to Create an FTP Account in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-create-an-ftp-account-in-cpanel/
File Transfer Protocol (FTP) lets you upload, download and manage the files in your hosting account from a desktop FTP client such as FileZilla. Your main cPanel login already has FTP access to the whole account, but you will often want a separate FTP account that is restricted to a single folder, for example to give a developer or a client access to one website without exposing the rest of your account. This guide shows you how to create an additional FTP account in cPanel and connect to it.
**Last reviewed:** 27 July 2026, against the current cPanel **Jupiter** interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: FTP Accounts](https://docs.cpanel.net/cpanel/files/ftp-accounts/)
## Prerequisites
- An active Noiz cPanel hosting account and your cPanel login details.
- A desktop FTP client (such as FileZilla) if you intend to connect straight away.
## Create an FTP Account
1. Log in to your cPanel account.
2. In the **Files** section, click **FTP Accounts**.

Under **Add FTP Account**, complete the following fields:
- **Log In:** Enter a username for the account, for example `new-user` (no spaces). cPanel automatically appends your domain, so the full username becomes `new-user@yourdomain.com`.
- **Domain:** If your account hosts more than one domain, choose the one this FTP account belongs to.
- **Password:** Enter a strong password, or click **Password Generator**. A long, random password matters here, because FTP logins are a common target for brute-force attempts.
- **Directory:** This is the only folder the account can reach, and it cannot move above it. Enter `public_html` to grant access to the whole website, or a subfolder such as `public_html/new-user` to limit the account to one area.
- **Quota:** Set a storage limit in MB, or choose **Unlimited**.

Click **Create FTP Account**. The new account is added to the **FTP Accounts** list lower down the same page.
## Connect With Your FTP Client
Once the account exists, open your FTP client and enter the following:
- **Host:** Your website address, for example `ftp.yourdomain.com` or `yourdomain.com`. If your domain is not yet pointing to Noiz, use the server hostname or IP address from your Noiz welcome email instead.
- **Username:** The full FTP username, for example `new-user@yourdomain.com`.
- **Password:** The password you set when creating the account.
- **Port:** `21` for FTP (the default).
On the **FTP Accounts** page you can also click **Configure FTP Client** next to any account to view its exact settings or download a ready-made configuration file for FileZilla.
## Use a Secure Connection
Plain FTP on port 21 sends your username and password across the network in clear text. Where the server supports it, set your FTP client to **Require explicit FTP over TLS (FTPS)** so the session is encrypted. If SSH is enabled on your plan, **SFTP** (port 22) is another secure option; it uses your SSH access rather than a cPanel FTP account.
## Troubleshooting
- **Login fails**: Make sure you are using the full username including the domain (`new-user@yourdomain.com`), not just the login name.
- **Cannot connect at all**: Confirm the host address resolves to Noiz. If the domain is new or was just moved, use the server hostname or IP from your welcome email until DNS propagates.
- **Connection times out**: Switch your FTP client between **active** and **passive** mode. Most home and office networks require passive mode.
- **Files upload but the website does not change**: Check the account's **Directory**. Files must go into `public_html` (or the correct subfolder) to appear on the site.
## Related Articles
- [How to Change the Password of the FTP Account in cPanel](/cpanel/how-to-change-an-ftp-account-password-in-cpanel/)
- [How to Change the FTP User Quota in cPanel](/cpanel/how-to-change-the-ftp-user-quota-in-cpanel/)
- [How to Delete an FTP User Account From cPanel](/cpanel/how-to-delete-an-ftp-user-account-from-cpanel/)
If you are unsure which directory to use, or you need an FTP account set up for a developer, the Noiz support team is happy to help. Open a ticket from your client area and Noiz will take care of it.
# How to Delete a Database in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-delete-a-database-in-cpanel/
This guide shows you how to permanently remove a MySQL database from your hosting account using cPanel. Use it when you are decommissioning an old website, clearing out a test database, or freeing up space in your account.
**Last reviewed:** 27 July 2026, against cPanel & WHM (Jupiter theme, current stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel: MySQL Databases](https://docs.cpanel.net/cpanel/databases/mysql-databases/)
- [cPanel: phpMyAdmin (for exporting a backup first)](https://docs.cpanel.net/cpanel/databases/phpmyadmin/)
## Before You Delete a Database
Deleting a database is **permanent and immediate**. There is no recycle bin, and the data cannot be recovered from within cPanel once it is gone. Before you continue, please note:
- **Back it up first.** If there is any chance you will need the data again, export the database before deleting it. Open **phpMyAdmin** in the **Databases** section, select the database, and use the **Export** tab to download an `.sql` file.
- **Check what uses it.** If a live application such as WordPress, Joomla, or an online store points at this database, deleting it will break that site until it is reconnected to another database.
- **Database names are prefixed.** Your databases appear with your cPanel username in front, for example `youruser_wordpress`. Make sure you are deleting the right one.
## Delete the Database
1. Log in to your cPanel account.
2. In the **Databases** section, click on **MySQL Databases**. 
3. Scroll down to **Current Databases**. This table lists every database on your account. Locate the one you want to remove and, in the **Actions** column, click **Delete**. 
4. cPanel asks you to confirm. Click **Delete Database** to complete the removal. 
The database and all of its tables are now gone, and it disappears from the **Current Databases** list.
## Tidy Up the Database User
Deleting a database does **not** delete the MySQL user that was attached to it. That user account remains under **Current Users** on the same **MySQL Databases** page. If the user is no longer needed anywhere, remove it as well: find it in the **Current Users** list and click **Delete**. Removing unused users keeps your account tidy and reduces the number of credentials that could be misused.
## Troubleshooting
**The Delete link does nothing or the page errors:** another process may be holding the database open. Close any open phpMyAdmin sessions and any applications connected to it, then try again.
**Your website is now showing a database connection error:** the site was still using the database you deleted. Restore it from your backup, or update the application's configuration to point at the correct database.
## Need a Hand?
If you are on a managed Noiz plan, or you are not sure whether a database is safe to remove, contact Noiz support before you delete anything. It is far quicker to check first than to recover a site after the fact.
# How to Delete an FTP User Account From cPanel
Source: https://docs.noiz.ie/cpanel/how-to-delete-an-ftp-user-account-from-cpanel/
Deleting an FTP account removes a set of FTP login details from your hosting account. This guide shows you how to remove an FTP user in cPanel and, just as importantly, how to do it without deleting the files that account could reach.
An FTP account is only a login. The files it connects to live in your account's directories and are often shared with your website and with other FTP accounts. Removing the login does not have to remove the files, and in almost every case you want to keep them.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: FTP Accounts](https://docs.cpanel.net/cpanel/files/ftp-accounts/)
## Prerequisites
- Access to your cPanel account.
- The username of the FTP account you want to remove.
## Delete the FTP account
1. Log in to your cPanel account.
2. In the **Files** section, click **FTP Accounts**. 
3. Scroll to the **FTP Accounts** list, find the account you want to remove, and click **Delete** next to it. 
4. cPanel asks you to confirm. Click **Delete Account** (labelled **Delete FTP Account** in some cPanel versions) to finish.
## Important: do not delete the home directory
**Warning:** When you confirm, cPanel offers a second option that also deletes the account's home directory. Depending on your cPanel version this appears as a checkbox, **Delete the user's home directory as well**, or as a separate button, **Delete Account and Files**. Do not use it unless you are certain.
Choosing that option deletes every file and folder inside the FTP account's home directory. For an account pointed at your website, that can remove your live site. The files are removed from the server and cannot be recovered unless you restore them from a backup. To remove only the login and keep the files, always confirm with the plain **Delete Account** option.
## Troubleshooting
**Symptom:** The FTP account you want has no **Delete** option. This is usually the main FTP account, which shares its login with your cPanel account and cannot be deleted on its own. It is listed under **Special FTP Accounts** and only offers configuration options.
**Symptom:** An application or device stops connecting after the deletion. Any software, backup job, or device that used those FTP credentials will now fail to log in. Create a fresh FTP account and update the connection details wherever they were saved.
If you are on a Noiz managed plan and would rather Noiz handle FTP changes for you, contact the Noiz support team and it will take care of the account for you.
# How to Disable Two-Factor Authentication on Your cPanel Account
Source: https://docs.noiz.ie/cpanel/how-to-disable-two-factor-authentication-on-your-cpanel-account/
Two-factor authentication adds a second check to your cPanel login: after your username and password, cPanel asks for a six-digit code from an authenticator app on your phone. This guide shows you how to switch that second check off again, which you might need to do because you are replacing your phone, moving to a different authenticator app, handing the account over to someone else, or because the codes have stopped being accepted.
The removal itself is three clicks and takes under a minute. The parts worth reading are what to do *before* you remove it, why a rejected code usually does not mean you need to disable anything at all, and what to do if you have already lost the device and cannot get in to reach this screen.
**Last reviewed:** 27 July 2026, against cPanel & WHM with the **Jupiter** interface (current stable release). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: Two-Factor Authentication for cPanel](https://docs.cpanel.net/cpanel/security/two-factor-authentication-for-cpanel/)
- [cPanel Documentation: Two-Factor Authentication for WHM (server-side management and the Manage Users tab)](https://docs.cpanel.net/whm/security-center/two-factor-authentication-for-whm/)
- [cPanel Documentation: the Security section](https://docs.cpanel.net/cpanel/security/)
- [RFC 6238: TOTP, the time-based one-time password standard cPanel uses](https://datatracker.ietf.org/doc/html/rfc6238)
## Prerequisites
- A hosting account on a Noiz cPanel server, and your cPanel username and password.
- The ability to complete a cPanel login right now, including the current six-digit code. You cannot remove two-factor authentication from outside the account. If you have already lost access, skip to [If You Have Lost the Device and Cannot Log In](#lockedout).
- The **Two-Factor Authentication** icon present in the **Security** section. If it is missing, the feature is not enabled on your hosting package and there is nothing to disable.
## Before You Disable: Check Whether You Actually Need To
Most people who set out to disable cPanel two-factor authentication are doing it because their codes suddenly stopped working. In the majority of those cases the secret is fine and something simpler is at fault. Rule these out first, because if one of them applies, disabling and re-enabling is unnecessary work.
- **Your phone's clock has drifted.** Time-based one-time passwords are generated from the current time, so a phone whose clock is even a minute out will produce codes cPanel rejects as invalid. On the phone, turn on automatic date and time, or use the time correction option built into your authenticator app. This single fix resolves most "my codes stopped working" reports.
- **You are typing a code that has already expired.** Each code is valid for roughly thirty seconds. If you copy one just as the timer runs out, it will be refused. Wait for a fresh code and enter it straight away.
- **You are reading the wrong entry.** Authenticator apps fill up quickly, and several entries may carry similar labels. Confirm you are using the entry created for this cPanel account on this server, not one for a different account, for the client area, or for a website's own login.
- **You are being prompted somewhere else entirely.** cPanel, webmail, the Noiz client area and any two-factor plugin inside your website are separate systems with separate settings. Removing cPanel's will not stop a prompt coming from one of the others.
If you have worked through those and still want it off, or you are switching phones deliberately, carry on.
## Step 1: Log In to cPanel
Sign in to cPanel as normal and complete the two-factor prompt with a current code. The quickest route is the single sign-on link in your Noiz client area, which takes you straight into the account without a separate password.
## Step 2: Open Two-Factor Authentication in the Security Section
On the cPanel home screen, scroll to the **Security** section and click **Two-Factor Authentication**. If you would rather not scroll, type `two-factor` into the search box at the top of the page and the icon will filter into view.

## Step 3: Click Remove Two-Factor Authentication
Because two-factor authentication is already configured, the page opens on the management view rather than the setup wizard. Click **Remove Two-Factor Authentication**.

If what you see instead is a QR code and a **Set Up** or **Configure** button, two-factor authentication is not currently active on this cPanel account. Whatever is asking you for a code is coming from somewhere else. See the troubleshooting section below.
## Step 4: Confirm the Removal
cPanel asks you to confirm, so that a stray click cannot quietly weaken the account. Click **Remove**.

A green banner appears reading **Success: The system removed the two-factor authentication from your account**. That is the whole job. The next time you log in, cPanel will ask for your username and password only.
## What Happens the Moment You Confirm
Understanding exactly what changed prevents two common misunderstandings.
- **The shared secret is destroyed on the server.** It is not parked somewhere for later. If you re-enable two-factor authentication afterwards, cPanel issues a brand new secret and a new QR code, and the old entry in your authenticator app will never produce a working code again.
- **Your authenticator app is not told.** The old entry stays on your phone, still counting down and still generating codes that now go nowhere. Delete it yourself, or you will be scrolling past a dead entry for years and, worse, may one day try to use it against a freshly enabled setup and conclude that cPanel is broken.
- **Sessions already open stay open.** Removing two-factor authentication does not sign anyone out. If you are removing it because you suspect somebody else has your credentials, that alone changes nothing for an intruder who is already logged in. Change your cPanel password as well, which does invalidate other sessions.
- **Nothing else on the account is touched.** Files, databases, email accounts, cron jobs, FTP users and SSL certificates are all unaffected. This setting governs the cPanel login and nothing more.
## Switching to a New Phone or a Different Authenticator App
Removing and re-adding is the correct way to move two-factor authentication to a new device, and it is safer than trying to migrate the secret. Do it in this order, while you still have the old phone in your hand:
1. Install and open the authenticator app on the new phone first, so it is ready.
2. Log in to cPanel using a code from the old phone and remove two-factor authentication using the steps above.
3. Immediately set it up again and scan the new QR code with the new phone. The guide for that is [How to Enable the Two-Factor Authentication on Your cPanel Account](/cpanel/how-to-enable-two-factor-authentication-2fa-on-your-cpanel-account/).
4. Log out and log back in once to prove the new codes are accepted before you wipe or hand on the old phone.
5. Delete the stale entry from the old device.
The gap between step 2 and step 3 is the only window in which the account sits on password alone. Keep it to a couple of minutes rather than leaving it until the weekend.
Some authenticator apps now offer an encrypted cloud backup or an export-to-new-device transfer. Those work, and they save you this dance, but they also place the secret in the app vendor's hands. Whether that trade is acceptable is a decision for you. If you use it, protect the app account itself with a strong password and its own second factor.
## If You Have Lost the Device and Cannot Log In
This is the situation that brings most people to this article, and it has an awkward shape: the screen that removes two-factor authentication sits behind the login that two-factor authentication is guarding. Stock cPanel issues no printed backup codes and offers no SMS fallback, so there is no self-service escape hatch inside the account.
What does work:
- **Find the secret somewhere else.** If you saved the QR code image or wrote down the alphanumeric key when you first set it up, enter that key manually into any authenticator app on any device and it will start producing valid codes again immediately. The secret is not tied to a particular handset.
- **Check your other devices.** If the authenticator app was ever installed on a tablet or a second phone, or if you had cloud sync switched on, the entry may still be sitting there.
- **Ask for it to be cleared at server level.** Two-factor authentication for a cPanel account can be removed from WHM by the administrator of the server, without needing your codes. On Noiz hosting that means opening a ticket from the client area. Because this bypasses a security control, expect to prove you are the account holder before it is actioned, which is exactly what you would want if somebody else were asking on your behalf.
Raise the request from the email address registered on the Noiz account and include your primary domain name. That single detail speeds up verification more than anything else you can send.
## Think About What You Are Giving Up
A stolen or reused cPanel password is one of the more common ways a hosting account is taken over, and once someone is inside cPanel they have your files, your databases and your email. Two-factor authentication is what stops a leaked password on its own being enough. Turning it off is a real reduction in security, not a formality.
If you are disabling it permanently rather than as part of a device swap, put something in its place:
- Set a long, unique cPanel password that is used nowhere else, and store it in a password manager rather than in a browser or a note. See [How to Reset Your cPanel Account Password](/cpanel/how-to-reset-your-cpanel-account-password/).
- Keep two-factor authentication switched on for your Noiz client area, since that account can order services, change billing details and reach cPanel by single sign-on.
- Use SSH keys rather than passwords if your plan includes shell access, and remove keys belonging to anyone who no longer needs them.
- Review the account for things left behind by a previous holder or an intruder: unexpected email forwarders and filters, cron jobs you did not create, extra FTP users, and API tokens under **Security** then **Manage API Tokens**.
- If you are removing two-factor authentication because you are handing the site to someone else, change the password after the handover as well. Removing the second factor without rotating the password leaves the old holder with working access.
Re-enabling later is quick, and there is no penalty for switching it back on the moment your new phone is set up.
## Troubleshooting
**Symptom**: There is no **Two-Factor Authentication** icon in the **Security** section. The feature is not included in the feature list applied to your hosting package, so it cannot be active on the account either. Whatever is prompting you for a code is a different system. Contact Noiz support if you believe it should be available on your plan.
**Symptom**: The page shows a QR code and a setup form instead of a **Remove** button. Two-factor authentication is not enabled for this cPanel account. Check whether the prompt you are trying to get rid of belongs to the Noiz client area, to webmail, to WHM if you hold a reseller account, or to a security plugin inside your website.
**Symptom**: You removed it, but a code is still requested at the next login. Three usual causes. The browser served a cached copy of the login page, so try a hard refresh or a private window. You are signing in to WHM rather than cPanel, and WHM keeps its own separate two-factor setting. Or you are going through a login page that is not cPanel's at all. Confirm the address in the browser bar before entering anything.
**Symptom**: Codes are rejected, so you cannot log in to reach the removal screen. Almost always clock drift on the phone. Enable automatic date and time, or use the app's built-in time correction, then try again. If that fails, follow the lost device section above.
**Symptom**: **Remove Two-Factor Authentication** is visible but nothing happens when you click it. The confirmation runs in JavaScript. A browser extension, a strict content blocker or a corporate proxy can interrupt it. Try a different browser or turn off extensions for the cPanel domain.
**Symptom**: You re-enabled two-factor authentication and the old entry in your authenticator app no longer works. That is expected. Re-enabling generates a new secret. Delete the old entry and scan the new QR code.
**Symptom**: The success banner never appeared and you are unsure whether it worked. Reload the **Two-Factor Authentication** page. If it now offers to set two-factor authentication up, the removal succeeded.
## Related Guides
- [How to Enable the Two-Factor Authentication on Your cPanel Account](/cpanel/how-to-enable-two-factor-authentication-2fa-on-your-cpanel-account/)
- [How to Reset Your cPanel Account Password](/cpanel/how-to-reset-your-cpanel-account-password/)
- [How to Enable or Disable Mod Security in cPanel](/cpanel/how-to-enable-or-disable-modsecurity-in-cpanel/)
## Need a hand?
If you are locked out because the authenticator device is gone, or you are unsure whether the code prompt you are seeing even comes from cPanel, contact the Noiz support team through the client area with your primary domain name and a short description of what the login screen shows. Requests to clear two-factor authentication are verified against the registered account holder before being actioned, so send them from the email address on the account. If you are on a managed Noiz plan and would like the account hardened after a handover, including a password rotation and a check for leftover forwarders, cron jobs and API tokens, ask and the team will run through it with you.
# How to Download a Partial Backup (Home Directory, MySQL, or Email) in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-download-a-partial-backup-home-directory-mysql-or-email-in-cpanel/
A **partial backup** lets you download one specific part of your hosting account on its own, rather than a full backup of everything. This is the quickest way to grab a copy of just your website files, just your databases, or just your email routing, for example before you edit a site, migrate away, or hand a copy to a developer. cPanel's **Backup Wizard** offers three partial options: your **Home Directory** (all your website files), your **MySQL Databases**, and your **Email Forwarders and Filters**.
A partial backup is not the same as a full account backup. A full backup bundles everything into one large archive that cPanel prepares in the background, whereas a partial backup generates and downloads immediately to your computer. If you need a complete copy of the account instead, use the full backup option in the same Backup Wizard.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel and WHM. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Backup Wizard (docs.cpanel.net)](https://docs.cpanel.net/cpanel/files/backup-wizard/)
- [cPanel Backup interface (docs.cpanel.net)](https://docs.cpanel.net/cpanel/files/backup/)
## Prerequisites
- Access to your cPanel account (your Noiz welcome email contains the login details).
- Enough free space on your own computer to hold the download. A Home Directory backup can be large if your site stores many files, images, or mailboxes.
## Download a partial backup
### 1. Open the Backup Wizard
Log in to your cPanel account. In the **Files** section, click **Backup Wizard**.

### 2. Start a backup
Under **Backup or Restore**, click **Back Up**.
### 3. Choose which part to download
Under **Select Partial Backup**, choose the part you want to download:
- **Home Directory** downloads a single compressed archive (a `.tar.gz` file) containing all of your website files. Clicking it generates and begins the download straight away.
- **MySQL Databases** lists each of your databases separately so you can download an individual database as a compressed `.sql.gz` file.
- **Email Forwarders and Filters** lets you download your forwarder and filter configuration.

### 4. Download the file
Click **Download** (or the relevant item name) and save the file to your computer. Keep it somewhere safe; a backup is only useful if you can find it again when you need to restore.
## Troubleshooting
**The download seems to hang on a large site**: a Home Directory backup is built on the fly, so a large account can take a while before the download begins. Give it time rather than clicking repeatedly. If the account is very large, a full backup (which cPanel prepares and stores first) is often the more reliable route.
**You need to restore what you downloaded**: the same Backup Wizard can restore a partial backup. Return to it, click **Restore**, then upload the archive for the part you want to put back.
## Need a hand?
If you are on a managed Noiz plan and would prefer Noiz to take, verify, or restore a backup for you, contact the Noiz support team through the client area and the team will assist.
# How to Edit a File in the cPanel File Manager
Source: https://docs.noiz.ie/cpanel/how-to-edit-a-file-in-the-cpanel-file-manager/
You can edit files directly on your website using the built-in **File Manager** in your cPanel account, without downloading them or connecting over FTP. This guide shows you how to open a file, make your changes and save them, and explains the difference between the two editors cPanel offers so you pick the right one for the job.
**Last reviewed:** 27 July 2026, against cPanel & WHM (Jupiter interface, current stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel File Manager](https://docs.cpanel.net/cpanel/files/file-manager/) (feature reference, including the Edit and HTML Editor tools)
## Prerequisites
- A Noiz hosting plan that uses cPanel, and your cPanel sign-in details.
- The location of the file you want to edit (for a website, files usually live under `public_html`).
## Editing a File
1. Log in to your cPanel account.
2. In the **Files** section, click **File Manager**. 
3. Navigate to the directory where your file is located (for example, `public_html` for your main website).
4. Right-click the file, then click **Edit** or **HTML Editor** in the context menu. (If your file does not appear, see the note on hidden files in **Troubleshooting** below.) 
5. cPanel shows a character-encoding confirmation before it opens the editor. Leave the encoding as it is (usually `utf-8`) unless you have a specific reason to change it, then click **Edit** to open the editor. 
6. Make your changes, then click **Save Changes** at the top of the editor. 
Your file is now saved. Because File Manager edits go straight to the live copy on the server, the change takes effect on your site immediately.
## Edit or HTML Editor: Which to Use
cPanel gives you two editors, and picking the wrong one is the most common cause of a mangled file:
- **Edit** opens a plain code editor with line numbers and syntax highlighting. Use it for HTML you have written by hand, and for PHP, CSS, JavaScript, `.htaccess`, configuration files and anything else where the exact characters matter. This is the safe default for almost every edit.
- **HTML Editor** is a visual (WYSIWYG) editor for HTML pages, marked as a beta feature in current cPanel. It is convenient for simple text changes, but it can rewrite or reformat your markup and strip out code it does not understand, so avoid it on hand-crafted pages or anything containing scripts.
## Troubleshooting
**The file appears as strange or random characters**: you selected the wrong encoding at step 5. Do not click **Save Changes**, or you may corrupt the file. Close the editor, right-click the file again, and choose the correct encoding (`utf-8` suits most modern files) before opening it.
**You cannot open a large file**: the in-browser editor will not open files larger than roughly 1 MB. Download the file (right-click, **Download**), edit it on your computer, then upload it back over the original.
**The file (such as .htaccess) is not listed**: dotfiles are hidden by default. Click **Settings** in the top-right of File Manager, tick **Show Hidden Files (dotfiles)**, and save.
**Save Changes does nothing or reports an error**: the file may be read-only. Right-click it, choose **Permissions**, and confirm the owner has write access (for a typical file that is `644`).
Before editing anything important, it is worth keeping a copy: right-click the file, choose **Copy**, and save it with a name such as `index.html.bak` so you can roll back if a change goes wrong.
If you would rather Noiz handle the change for you, or you are unsure which file to edit, contact the Noiz support team and they will assist.
# How to Edit or Delete a Cron Job in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-edit-or-delete-a-cron-job-in-cpanel/
This guide shows you how to change the schedule or command of an existing cron job, and how to remove a cron job you no longer need, using the **Cron Jobs** tool in cPanel on your Noiz hosting account. A cron job (sometimes called a "cronjob" or "scheduled task") is a command that the server runs automatically on a repeating schedule, so editing one means adjusting either *when* it runs or *what* it runs.
**Last reviewed:** 27 July 2026, against the current stable cPanel & WHM interface (Jupiter theme). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: Cron Jobs](https://docs.cpanel.net/cpanel/advanced/cron-jobs/) (creating, editing and removing scheduled tasks)
## Prerequisites
- An active Noiz cPanel hosting account with cron access, and your cPanel sign-in details.
- At least one existing cron job listed under **Current Cron Jobs**. If you have not created one yet, there is nothing to edit or delete.
## How to Edit a Cron Job
1. Log in to your cPanel account.
2. In the **Advanced** section, click **Cron Jobs**. You can also type `cron` into the cPanel search bar at the top of the page to jump straight to it. 
3. Scroll down to the bottom of the page. Under **Current Cron Jobs**, find the job you want to change and click **Edit** next to it.
4. Adjust the schedule fields (minute, hour, day, month and weekday) or the **Command**, then click **Edit Line** to save your change. If you do not click **Edit Line**, your changes are not kept. 
### What you are actually editing
Each cron line is made of five time fields followed by the command to run. The five fields are, in order, **minute**, **hour**, **day of month**, **month** and **day of week**. cPanel gives you drop-down menus for the common intervals (for example "Once Per Hour" or "Twice Per Month"), so in most cases you do not need to write the schedule by hand.
A few things worth knowing before you save:
- **Use the full path in the command.** Cron runs with a minimal environment, so a command that works when you type it in the shell can fail under cron if it relies on a relative path. Where possible, use the absolute path to the script or binary, for example `/usr/local/bin/php /home/username/public_html/cron/task.php`.
- **The notification email is separate.** The address at the top of the Cron Jobs page is where the server sends any output a job produces. Editing a job does not change that address, and clearing that field stops cron emails for every job, not just one.
- **Test with a close-in time first.** If you are unsure a changed command works, set the schedule to run a minute or two ahead, confirm it behaves, then set it back to the real interval.
## How to Delete a Cron Job
1. Under **Current Cron Jobs**, find the job you want to remove and click **Delete** next to it.
2. In the **Delete this cron job?** confirmation, click **Delete** to confirm. 
Deletion is immediate and there is no undo. If there is any chance you will want the job back, copy the full command line into a note before you delete it, so you can recreate it later. To temporarily pause a job rather than lose it, edit it to run at an interval far in the future instead of deleting it.
## Troubleshooting
**Symptom: You cannot see the Cron Jobs icon.** Search `cron` in the cPanel search bar. If it still does not appear, your hosting plan may not include cron access; contact Noiz support to confirm.
**Symptom: Your edit did not take effect.** Make sure you clicked **Edit Line** after making the change. Navigating away without saving leaves the old schedule and command in place.
**Symptom: The job still runs after you deleted it.** You may have removed a different line. Refresh the page and check that the line no longer appears under **Current Cron Jobs**.
**Symptom: The job runs on the schedule but nothing happens.** This is almost always the command rather than the schedule. Check the path to the script or interpreter and any file permissions, then set a close-in test time to watch it run.
## Need a hand?
If a scheduled task is not behaving as expected, or you would like Noiz to review your cron setup, open a ticket from your Noiz client area and the support team will assist. Customers on managed plans can have cron jobs configured and checked on their behalf.
# How to Edit or Remove a CNAME Record in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-edit-or-remove-a-cname-record-in-cpanel/
A CNAME record points one hostname at another hostname, so that `www.yourdomain.com` or `shop.yourdomain.com` resolves to wherever the target resolves. You will need to change one whenever a third-party service moves you to a new endpoint, or remove one when you stop using a service, move a subdomain back onto your own hosting, or need to clear a conflicting record out of the way. This guide shows you how to do both from the cPanel **Zone Editor**, and covers the details that catch people out: the trailing dot, records you should not delete, and why the change does not always appear straight away.
You will see CNAME records described as *aliases*, *canonical name records* or simply *pointers*. They all mean the same record type, and cPanel labels it **CNAME**.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the current STABLE and LTS tier) and the **134** LTS release tier. The Zone Editor interface described here has been stable across recent cPanel releases, so the steps hold on older versions too. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel: Zone Editor](https://docs.cpanel.net/cpanel/domains/zone-editor/) for the reference description of every field and control on the page.
- [RFC 1912: Common DNS Operational and Configuration Errors](https://www.rfc-editor.org/rfc/rfc1912) for why a CNAME cannot sit alongside other records at the same name.
- [RFC 2181: Clarifications to the DNS Specification](https://www.rfc-editor.org/rfc/rfc2181) for the authoritative treatment of TTLs and record sets.
## Prerequisites
- Your cPanel username and password, and the login address for your server.
- The domain must be using your hosting server's nameservers. If the domain's DNS is hosted somewhere else, such as at your registrar or behind a third-party DNS provider, the cPanel Zone Editor will happily accept the change and nothing on the internet will act on it.
- The new target hostname, if you are editing rather than deleting. Get it from the service you are pointing at, in writing, rather than from memory.
- A note of what the record currently says, before you change it. Take a screenshot. It is the fastest way back if the change turns out to be wrong.
## Before You Change Anything
A CNAME is a redirection at the DNS level. Anything that resolves that hostname follows the pointer, so the blast radius of an edit is wider than it looks. Before you touch the record, work out what depends on it.
Three things are worth knowing up front:
- **A CNAME cannot share a name with any other record.** If `shop.yourdomain.com` has a CNAME, it cannot also have an A record, a TXT record or an MX record. This is why cPanel refuses some changes that look reasonable, and it is also why you cannot put a CNAME on the root of the domain: the root already carries the zone's SOA and NS records.
- **Editing is safer than delete-and-recreate.** Editing keeps the record in place and changes its value in one step. Deleting it and adding it again leaves a window where the hostname does not exist at all, which resolvers will cache as a negative answer.
- **Removing a CNAME breaks whatever was using it.** Service verification records, mail autodiscovery, CDN hostnames and third-party dashboards all commonly live on a CNAME. If you do not recognise a record, find out what it does before you delete it.
## How to Edit a CNAME Record in cPanel
1. Log in to your cPanel account.
2. In the **Domains** section, click **Zone Editor**. If you cannot see it, type `Zone Editor` into the search box at the top of the cPanel home page.

3. Find the domain you want to work on in the list. Each domain has a row of buttons under **Actions**, including shortcuts for adding an A record, a CNAME record or an MX record, and a **Manage** button that opens the full record list.

4. Click **Manage** beside the domain. This opens every record in that zone.
5. Narrow the list down. Use the type filter to show only **CNAME** records, or type part of the hostname into the search box. Zones on a busy account can run to dozens of records, and filtering removes the risk of editing the wrong row.
6. Find the CNAME record you want to change and click **Edit** on that row.

7. Change the fields you need. **Name** is the hostname the record answers for, **TTL** is how long resolvers are allowed to cache the answer, and **Record** or **CNAME** is the target hostname it points at.
8. Click **Save Record**. The change is written to the zone file immediately and the zone's serial number is bumped so that secondary nameservers pick it up.
## How to Remove a CNAME Record in cPanel
1. Follow steps 1 to 5 above to reach the record list for the domain and filter it to **CNAME**.
2. Confirm you have the right row. Read the **Name** column, not the target, and check it character by character. Deleting the wrong record is a two-second mistake with a several-hour cache tail.
3. Click **Delete** on that row, then confirm in the dialogue that appears.
The record is gone from the zone the moment you confirm. Resolvers that already have the old answer cached will keep serving it until the TTL expires, so the hostname does not stop working instantly for everyone.
If you are removing a CNAME so that you can put an A record on the same hostname, delete the CNAME first and add the A record second. The two cannot coexist, and cPanel will reject the A record while the CNAME is still there.
## Getting the Target Right: the Trailing Dot
This is the single most common CNAME mistake, and it produces a record that looks correct in the interface and resolves to nothing.
A hostname that ends with a dot is fully qualified and absolute. A hostname without a trailing dot can be treated as relative to the zone it sits in, which means your own domain gets appended to it. Type `ghs.googlehosted.com` into the target field without the dot and you can end up with a record pointing at `ghs.googlehosted.com.yourdomain.com`, which does not exist.
Two habits avoid it entirely:
- Always type the target in full and end it with a dot, for example `target.example-service.com.`
- After saving, look at the value cPanel displays back to you in the record list. If your own domain has been appended to the end of the target, the record is wrong. Edit it and add the trailing dot.
The same logic applies to the **Name** field, in the other direction. Entering `shop` gives you `shop.yourdomain.com`, which is almost always what you want. Entering `shop.yourdomain.com` without a trailing dot can give you `shop.yourdomain.com.yourdomain.com`. Either type the short label on its own, or type the full hostname with a trailing dot.
## Records You Should Not Delete
Some CNAME records in a cPanel zone are created by the server and are load-bearing. Deleting them takes services offline in ways that are not obvious until somebody complains.
- `mail` and `webmail`, which are how mail clients and browser webmail reach the server.
- `cpanel`, `whm` and `autodiscover`, which provide the friendly login and client-autoconfiguration hostnames.
- `ftp`, if you or anyone else still connects over FTP by name.
- Verification records from services such as mail providers, analytics platforms or certificate authorities. These often look like random strings and appear to be junk. They are not, and removing one can invalidate a domain verification you completed months ago.
If you are not sure what a record is for, leave it alone and ask. A stale record costs nothing. A deleted one that mattered costs an outage.
## How Long the Change Takes
The edit itself is instant on the server. What takes time is the cached copy of the old answer sitting in resolvers around the world, and that is governed by the record's TTL, not by any general propagation delay.
cPanel commonly creates records with a TTL of `14400` seconds, which is four hours. Until that many seconds have elapsed since a resolver last looked up the name, it will keep serving the old value without asking your nameservers again.
If you know a change is coming, plan for it:
- Lower the TTL on the record to `300` seconds a day or so before the change. Wait for the old, longer TTL to expire so the short value is the one in circulation.
- Make the actual change. It is now visible everywhere within about five minutes.
- Put the TTL back up to `14400` once you are satisfied. Very short TTLs mean more lookups against your nameservers for no benefit once the change has settled.
Older guidance quoting 24 to 48 hours dates from an era of much longer default TTLs and slower zone transfers. Treat the record's own TTL as the number that matters, and allow a little extra for the handful of resolvers and devices that cache more aggressively than they should.
## Verify the Change
Do not rely on loading the site in your browser. Browsers and operating systems keep their own DNS caches, and a browser will happily show you a page from cache long after the record behind it changed.
Query the record directly. On Linux or macOS:
```
dig +short CNAME shop.yourdomain.com
```
On Windows:
```
nslookup -type=CNAME shop.yourdomain.com
```
To check what your own nameservers are actually publishing, bypassing every cache in between, query them by name:
```
dig +short CNAME shop.yourdomain.com @ns1.noiz.co.za
```
If the authoritative answer is correct but a public resolver still returns the old value, the record is right and you are simply waiting out a cached answer.
## Troubleshooting
**Symptom**: there is no **Zone Editor** icon in cPanel. The feature has been removed from your hosting package's feature list, or DNS for the account is managed elsewhere. Open a ticket and ask which is the case before making changes at your registrar.
**Symptom**: the record saves without error but nothing changes. The domain's nameservers are almost certainly not the ones on this server. Check the delegation with `dig +short NS yourdomain.com` and edit the record wherever those nameservers point.
**Symptom**: cPanel refuses the change and mentions a conflict. Another record already exists at that name. A CNAME has to be the only record at its hostname, so remove or rename the conflicting A, TXT or MX record first.
**Symptom**: the target has your own domain appended to it. The trailing dot was missing when the record was saved. Edit the record and re-enter the target ending in a dot.
**Symptom**: the change is visible from one device but not another. That is caching, not an error. Flush the local DNS cache, restart the browser, or test from mobile data. If the authoritative query returns the new value, the record is correct.
**Symptom**: mail stopped working after a Zone Editor session. Check whether the `mail` CNAME or the domain's MX records were changed or removed. Mail routing depends on both, and an edit intended for a website subdomain can catch them by accident.
**Symptom**: the record disappeared on its own. Some cPanel operations rewrite parts of a zone, and a few third-party integrations manage their own records and will reinstate or remove them. If a record keeps reverting, something else is managing it, and that is worth identifying before you fight it.
## Related Articles
- [How to Edit or Remove a Record in cPanel](/cpanel/how-to-edit-or-remove-a-dns-record-in-cpanel/) for the same procedure applied to any record type, not just CNAME.
- [How to Add a CNAME Record in cPanel](/cpanel/how-to-add-a-cname-record-in-cpanel-zone-editor/) for creating one from scratch.
- [How to Edit or Remove an MX Record in cPanel](/cpanel/how-to-edit-or-remove-an-mx-record-in-cpanel/) for changing where mail for the domain is delivered.
- [How to Create a Subdomain in cPanel](/cpanel/how-to-create-a-subdomain-in-cpanel/) when you want the hostname served from this account rather than pointed elsewhere.
## Getting Help
If you are unsure what a record does, or a change has not taken effect the way you expected, open a ticket in the Noiz client area with the domain, the exact hostname, the value you set and the value you are seeing. On managed plans the Noiz team can check the zone as published by the nameservers, confirm whether the delegation points at this server, and restore a record you did not mean to remove.
# How to Edit or Remove a DNS Record in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-edit-or-remove-a-dns-record-in-cpanel/
Every DNS record your domain publishes, the address that points visitors at your website, the mail routing, the verification strings for third-party services, lives in a single zone file. On a Noiz cPanel account you manage that zone from **Zone Editor**, found under **Domains**. This guide covers the general case: finding any record, changing it, and deleting it safely. It also covers the two things that catch people out most often, namely editing a zone that is not actually being used, and expecting the change to appear instantly.
If you specifically need a record type walkthrough, see [How to Edit or Remove a CNAME Record in cPanel](/cpanel/how-to-edit-or-remove-a-cname-record-in-cpanel/) or [How to Edit or Remove an MX Record in cPanel](/cpanel/how-to-edit-or-remove-an-mx-record-in-cpanel/). This article is the general guide that applies to A, AAAA, CNAME, MX, TXT, SRV and CAA records alike.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the current STABLE and LTS tier). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [Zone Editor](https://docs.cpanel.net/cpanel/domains/zone-editor/), the cPanel interface reference for the screens shown here
- [RFC 1035](https://www.rfc-editor.org/rfc/rfc1035), the specification that defines what each record type may contain
- [RFC 2308](https://www.rfc-editor.org/rfc/rfc2308), negative caching, which explains why a record you just deleted can still be answered for a while
## Prerequisites
- A Noiz hosting account whose control panel is cPanel, and your cPanel login details.
- The domain must be listed in your cPanel account, either as the main domain, an addon domain, or a subdomain.
- The exact value you intend to publish. Copy verification strings from the source rather than retyping them, since a single wrong character silently fails.
## First, Check Whose DNS You Are Editing
This is the step people skip, and it is the reason most Zone Editor changes appear to do nothing at all.
cPanel will happily let you edit a zone file for any domain on your account, whether or not the internet is asking that server for answers. The zone only takes effect if the domain's authoritative nameservers are the Noiz hosting nameservers, `ns1.noiz.co.za` and `ns2.noiz.co.za`. If your domain is pointed at Cloudflare, at your registrar's own DNS, or at a previous host, then that provider holds the live zone and edits in cPanel change nothing that anyone can see.
Check before you start:
```
dig NS yourdomain.com +short
```
Replace `yourdomain.com` with your own domain. On Windows, `nslookup -type=ns yourdomain.com` does the same job. If the answer is not the Noiz nameservers, make your change in whichever control panel matches the answer you got, or move DNS to Noiz first.
## Step 1: Open Zone Editor
1. Log in to your cPanel account.
2. In the **Domains** section, click **Zone Editor**.

Depending on your cPanel theme and version, this section may be labelled **Domains** or **Domains & DNS**, and newer builds may take you to a combined **DNS** interface. The record list and the actions are the same in both.
## Step 2: Open the Zone for Your Domain
Zone Editor lists every domain on the account. Beside each one, under **Actions**, are shortcut buttons for adding common record types and a **Manage** link.
The shortcut buttons only add records. To change or delete anything that already exists, you need the full list, so click **Manage** beside the domain you want.

## Step 3: Find the Record
The Manage screen shows the whole zone, which on a busy domain can run to dozens of entries. Two controls make this manageable:
- The **Filter** or record type selector at the top, which narrows the list to a single type such as `A`, `MX` or `TXT`.
- The search box, which matches on the record name. Searching for `www` or for the subdomain you are working on is usually faster than scrolling.
Read the **Name** column carefully before you act. cPanel displays names fully qualified with a trailing dot, so the record for the domain itself appears as `yourdomain.com.` and a subdomain record as `shop.yourdomain.com.`. Records for `mail`, `webmail`, `cpanel`, `cpcalendars`, `cpcontacts` and `autodiscover` are service records created by cPanel, not stray entries.
## Step 4: Edit a Record
1. Click **Edit** on the row you want to change.
2. The row becomes editable in place. Change the **TTL**, the **Record** value, and for MX records the **Priority**, as required.
3. Click **Save Record**.

A few things to know while that row is open:
- **The record type cannot be changed.** If an entry needs to become a different type, for example an A record that should be a CNAME, delete it and add a new one. Editing will not offer you a type drop-down.
- **TTL is in seconds.** The cPanel default is `14400`, which is four hours. See the section below before you leave it alone.
- **Trailing dots matter.** For CNAME, MX and SRV targets, a value ending in a dot is treated as absolute. A value without one is treated as relative to the zone, so `mail.example.com` entered without the dot can resolve as `mail.example.com.yourdomain.com`. cPanel normally appends the dot for you, but check the saved value afterwards.
- **Long TXT values are fine.** DKIM keys and similar strings longer than 255 characters are split across chunks automatically. Paste the value in full and do not add your own quotes.
## Step 5: Remove a Record
1. Click **Delete** on the row.
2. Confirm when cPanel prompts you.
There is no undo and no recycle bin. Before deleting anything, copy the whole row into a text file. Reconstructing a record you cannot remember the value of is the sort of small problem that turns into an evening.
### Records Worth Leaving Alone
Deleting the wrong entry takes a site or its mail offline immediately, and the effect can persist for hours because of caching. Treat these as off limits unless you know exactly why you are changing them:
- **SOA and NS records.** These define the zone itself. Removing them breaks the domain outright.
- **The A record for the domain and for `www`.** These are what put your website on the internet.
- **MX records and the `mail` A record**, if you receive email on the domain. Delete these and inbound mail stops, usually bouncing rather than queueing.
- **SPF, DKIM and DMARC TXT records.** Removing them will not stop mail leaving, but it will get a growing share of it filed as spam. cPanel manages these through **Email Deliverability**, which is the correct place to fix them.
- **CAA records.** These control which certificate authorities may issue certificates for the domain. Deleting or mis-editing one can block automatic SSL renewal.
- **Service subdomain records** such as `cpanel`, `webmail`, `webdisk`, `cpcalendars` and `cpcontacts`. Removing these breaks the shortcut URLs you and your mail clients use.
## How Long the Change Actually Takes
Older guidance says to allow 12 to 24 hours. That figure is a leftover from an era of slower zone transfers, and it is not how caching works.
The change is live on the Noiz nameservers within seconds. What takes time is the rest of the world noticing, and that is governed by the **TTL** on the record as it was *before* you edited it. Any resolver that had already looked up the old value will keep serving it until its copy expires. At the cPanel default of `14400`, that is up to four hours. Some networks round TTLs up, so allow a little more.
The practical consequence is that TTL planning happens before the change, not after:
1. A day or so before a planned migration or cutover, edit the record and lower the TTL to `300`, which is five minutes. Save it and leave the value alone.
2. Wait for the old TTL to elapse so that resolvers pick up the short one.
3. Make the real change. It will now propagate in minutes.
4. Once you are satisfied, set the TTL back to `14400`. Permanently short TTLs add latency and unnecessary query load.
Deletions behave slightly differently. A resolver that asks for a record you have removed caches the *absence* of it as well, controlled by the negative caching value in the SOA record. That is why a deleted entry can seem to linger even after its own TTL has passed.
## Verify the Change
Do not judge the result from your browser, which has its own cache, and neither does your operating system tell the whole story. Ask the authoritative nameserver directly, which bypasses every cache between you and it:
```
dig @ns1.noiz.co.za yourdomain.com A +short
dig @ns1.noiz.co.za yourdomain.com MX +short
dig @ns1.noiz.co.za yourdomain.com TXT +short
```
If that returns the new value, your edit saved correctly and everything remaining is caching elsewhere. To see what the wider internet is currently getting, run the same query without the `@ns1.noiz.co.za` part, or check from a public resolver with `dig @1.1.1.1 yourdomain.com A +short`.
On Windows without `dig` installed, `nslookup yourdomain.com ns1.noiz.co.za` gives the equivalent authoritative answer.
## Troubleshooting
**Symptom: the record saves but nothing changes anywhere.** The domain's nameservers are not the Noiz ones, so a different provider is answering. Run `dig NS yourdomain.com +short` and edit the zone wherever that points instead.
**Symptom: cPanel rejects the record with a validation error.** The value does not match what the type allows. The usual causes are a full URL entered where a hostname is expected, an IP address in a CNAME, or stray quotation marks pasted along with a TXT value. Enter hostnames and addresses only, with no `http://` prefix and no trailing slash.
**Symptom: adding a CNAME fails, or the CNAME is ignored.** A name that has a CNAME cannot also have other records. Delete the conflicting A or TXT record at that same name first, and note that the zone apex, the bare `yourdomain.com`, can never hold a CNAME.
**Symptom: a deleted record comes back.** Something else in cPanel is regenerating it. Subdomain and addon domain A records are recreated as long as the domain exists in the **Domains** interface, so remove the domain there rather than in the zone. DKIM and SPF TXT records are managed by **Email Deliverability** and will be restored by it.
**Symptom: mail stopped after an edit.** Check that the MX record still exists with the correct priority, and that any A record its target depends on is still present. Restore from the copy you took before editing, then allow the TTL to elapse.
**Symptom: your cPanel does not look like the screenshots above.** Either your account is on a newer cPanel build where **Zone Editor** has been folded into a combined **DNS** interface, in which case the record list and the Edit and Delete actions work identically, or your Noiz package uses a different control panel altogether. Use the guide matching your panel, or contact Noiz support.
## Need a Hand
If you are unsure which record controls the behaviour you want to change, or a change has not taken effect after the TTL should have expired, open a ticket in the Noiz client area. Include the domain, the record name and type, the value you expected, and the output of `dig @ns1.noiz.co.za yourdomain.com ANY`. On managed plans Noiz will make the change and confirm the authoritative answer for you before you rely on it.
# How to Edit or Remove an MX Record in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-edit-or-remove-an-mx-record-in-cpanel/
An **MX record** (mail exchanger record) tells every sending mail server on the internet which host accepts email for your domain. Editing or removing one changes where your inbound mail goes, and it takes effect on live traffic. This guide shows you how to change or delete an existing MX record in cPanel's **Zone Editor**, and covers the parts that make MX different from every other record type: priority ordering, the routing setting cPanel keeps separately from the zone, and what actually happens to mail while the change spreads.
Related guides: to create a new MX record, see [How to Add an MX Record in cPanel](/cpanel/how-to-add-an-mx-record-in-cpanel/). For the general case covering A, CNAME, TXT and the rest, see [How to Edit or Remove a DNS Record in cPanel](/cpanel/how-to-edit-or-remove-a-dns-record-in-cpanel/). This article is the MX-specific version, because MX records carry consequences the others do not.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the current STABLE and LTS tier). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [Zone Editor](https://docs.cpanel.net/cpanel/domains/zone-editor/): the cPanel interface reference for every field and button used below, including the Manage Zone view.
- [Email Routing](https://docs.cpanel.net/cpanel/email/email-routing/): what Local, Backup and Remote Mail Exchanger do, in cPanel's own words.
- [RFC 5321, section 5.1](https://www.rfc-editor.org/rfc/rfc5321#section-5.1): how a sending server resolves MX records, and why an MX target must not be a CNAME or an IP address.
- [RFC 7505 (Null MX)](https://www.rfc-editor.org/rfc/rfc7505): the correct way to declare that a domain receives no mail at all, instead of deleting every MX record.
## Prerequisites
- Login details for the cPanel account that holds the domain.
- The replacement values, if you are editing rather than deleting. Your mail provider supplies a hostname and a priority number for each mail host. Use the values in front of you, not the examples here.
- Confirmation that this server answers DNS for the domain. The next section shows the check.
- The **Zone Editor** icon visible in cPanel. If it is missing, the feature has been switched off for the hosting package rather than removed from cPanel.
## Before You Touch Anything
Two checks take a minute each and prevent the two failure modes that dominate MX support tickets.
### Confirm You Are Editing the Live Zone
cPanel edits the zone file stored on the server it runs on. If the domain's nameservers point somewhere else, that file is never consulted, and your careful edit changes nothing at all. On Noiz hosting the authoritative nameservers are `ns1.noiz.co.za` and `ns2.noiz.co.za`. Check what the domain currently uses:
```
dig NS yourdomain.com +short
```
Replace `yourdomain.com` with your own domain. On Windows without `dig` installed, `nslookup -type=ns yourdomain.com` does the same job. If the answer is a registrar's nameservers, a CDN, or a separate DNS platform, that is where the MX record lives and that is where it must be edited. A domain proxied through a third-party DNS service keeps its DNS there permanently, not only during setup.
### Copy the Existing Record First
There is no undo in Zone Editor and no recycle bin. Before you change or delete anything, copy the full row (name, TTL, type, priority, destination) into a text file. Reconstructing an MX record whose hostname you cannot remember, while mail is bouncing, is a bad evening that costs nothing to avoid.
**Be aware that this change affects live mail delivery.** Unlike a website record, where a mistake produces an obvious error page, a wrong MX usually fails silently: messages are accepted somewhere you are not looking, or they bounce back to the sender without ever reaching you. Plan the change for a quiet period if the domain carries real mail.
## Open Zone Editor and Find the MX Records
1. Log in to your cPanel account.
2. In the **Domains** section, click **Zone Editor**. Depending on your cPanel theme and build, this section may be labelled **Domains** or **Domains & DNS**, and some newer builds open a combined **DNS** interface. The record list and the actions behave identically. 
3. Zone Editor lists every domain on the account. Beside each one, under **Actions**, sit shortcut buttons for adding common record types and a **Manage** link. The shortcut buttons only add records, so they are no help here. 
4. Click **Manage** beside the domain you want. The full record table opens.
5. Filter the table by **MX** using the record type selector at the top. On a busy zone this turns dozens of rows into the two or three that matter, and it lets you see the complete MX set at once, which is the only way to judge priority sensibly.
Read the whole MX list before acting. Most cPanel accounts are created with an MX record pointing at the server itself, typically `mail.yourdomain.com` at priority `0`. If you are moving mail elsewhere, that self-pointing record is usually the one causing trouble, and leaving it in place beside an external record is the single most common reason mail goes missing after a migration.
## Edit an MX Record
1. Click **Edit** on the MX row you want to change.
2. The row becomes editable in place. Adjust the **Priority**, the **Destination** and the **TTL** as needed.
3. Click **Save Record**.

Points to watch while the row is open:
- **The destination must be a bare hostname.** Something like `mx1.mailprovider.example`. Not an IP address, not a URL, no protocol prefix, no port, no trailing slash. cPanel adds the trailing dot for you, but check the saved value afterwards, because a target stored without one can be interpreted relative to the zone and resolve as `mx1.mailprovider.example.yourdomain.com`.
- **The target must not be a CNAME.** RFC 5321 requires an MX to point at a name with an A or AAAA record. Some sending servers tolerate a CNAME target and some refuse it outright, which produces mail that arrives from certain senders and not others.
- **The record type cannot be changed.** If a row needs to become a different type entirely, delete it and add a new one.
- **TTL is in seconds.** The cPanel default of `14400` is four hours, which is how long the old value can linger elsewhere on the internet. See the timing section below.
## Remove an MX Record
1. Click **Delete** on the MX row.
2. Confirm when cPanel prompts you.
Removing an MX record is the right move in exactly two situations: the host it names no longer accepts your mail, or it is a leftover from a previous mail setup that now competes with the current one. Retiring a mail provider means deleting every one of its MX records, not just the first, since a forgotten backup entry will quietly keep receiving mail whenever the primary host is briefly unreachable.
**Do not delete all MX records to stop a domain receiving mail.** With no MX published, sending servers fall back to the domain's A record under RFC 5321 and attempt delivery to your web server, which produces confusing bounces rather than a clean refusal. The correct way to declare that a domain receives no mail is a null MX as defined in RFC 7505: a single record with priority `0` and a destination of `.` (a lone dot). Zone Editor's quick-add form sometimes rejects the bare dot, in which case add it from the **Manage** screen or ask Noiz support to place it for you.
## Priority: The Lowest Number Wins
Priority is the field most often changed in the wrong direction, because the intuitive reading is backwards. It is a preference number, not a score, so a *lower* value means a *more* preferred server.
A sending server gathers every MX record for the domain, sorts them ascending by priority, and tries the lowest first. Only if that host refuses or times out does it move to the next. A typical pair looks like this:
- `10 mx1.mailprovider.example`: tried first, carries all mail under normal conditions.
- `20 mx2.mailprovider.example`: tried only when the first host is unreachable.
What this means when you are editing:
- The numbers themselves are meaningless in isolation, only their order relative to each other counts. `10` and `20` behave exactly like `1` and `2`. The convention of spacing by ten simply leaves room to slot a host in later without renumbering.
- Two records sharing a priority are treated as equals and sending servers spread traffic between them. Do that deliberately for load sharing, never by accident when editing, because half your mail will start arriving somewhere unintended.
- Raising the priority number on an old record does not retire it. It demotes it to a backup, and it will still receive mail every time the preferred host has a hiccup. If a host should no longer receive mail, delete its record.
- A backup MX only helps if that host is actually configured to queue and forward for your domain. An unconfigured backup accepts messages and then has nowhere to put them, which is worse than having no backup at all.
## Check Email Routing After the Change
This step is missing from most MX guides and it is the reason a change can look perfect from outside while half the mail vanishes. cPanel keeps a routing decision for each domain that is separate from the zone file, and editing the MX record does not update it.
If that decision still says the server handles the domain's mail, then anything sent *from* an account on the same server to your domain is dropped into a local mailbox and never leaves the machine. Contact form messages from your own website are the classic casualty.
1. Go to **Email > Email Routing** in cPanel.
2. Select the domain.
3. Choose the setting that now matches reality:
- **Automatically Detect Configuration**: the server reads the MX records in the local zone and routes accordingly. Sensible in most cases.
- **Local Mail Exchanger**: mailboxes live on this server. Correct even when an external filtering or gateway service sits in front of it.
- **Backup Mail Exchanger**: the server queues mail and holds it until a lower-numbered exchanger is reachable again.
- **Remote Mail Exchanger**: the server never delivers locally and hands everything to the lowest-numbered exchanger. This is what you want once mailboxes have moved to an external provider.
4. Click **Change**.
Automatic detection reads only the local zone file and performs no live DNS lookup. So if you edited the external MX but left the original self-pointing record in place, automatic detection still sees a local mail exchanger and keeps mail on the server. Remove the old record first, then set routing.
One consequence worth planning for: once routing is remote, cPanel mailboxes for that domain stop receiving new mail, but existing messages stay on the server. Export or forward anything you still need before cutting over, because changing the routing migrates nothing.
## How Long the Change Takes
Older guidance says to allow 12 to 24 hours. That figure is a leftover from an era of slow zone transfers and it is not how caching works.
The edit is live on the Noiz nameservers within seconds. What takes time is the rest of the internet noticing, and that is governed by the **TTL** on the record as it was *before* you changed it. Any resolver holding the old value keeps serving it until its copy expires, which at the cPanel default of `14400` is up to four hours. Some networks round TTLs up, so allow a little more.
TTL planning therefore happens before the change, not after:
1. A day or so ahead of a planned move, edit the MX records and lower the TTL to `300` (five minutes). Save and leave it.
2. Wait for the old TTL to elapse so resolvers pick up the short one.
3. Make the real change. It now propagates in minutes.
4. Once you are satisfied, restore the TTL to something sensible such as `14400`. Permanently short TTLs add latency and query load for no benefit.
Keep the old mailboxes reachable for a few days after a switch. Mail already queued for the previous server will still be delivered there, and it does not follow you.
## Verify the Change
Ask the authoritative nameserver directly, which bypasses every cache between you and it:
```
dig @ns1.noiz.co.za yourdomain.com MX +short
```
If that returns the new set, the edit saved correctly and anything still wrong is caching elsewhere. To see what the wider internet currently receives, query a public resolver instead:
```
dig MX yourdomain.com @1.1.1.1 +short
```
The output lists each priority and hostname. Confirm the list matches what your mail provider asked for, with no leftovers, and then send a test message from an address outside your own domain and outside the server.
## Troubleshooting
**Symptom**: the record saved without error but `dig` still returns the old MX. Either the TTL has not expired, or the domain's DNS is not served by this server. Re-run the nameserver check at the top of this article before changing anything else.
**Symptom**: mail from outside arrives at the new provider, but messages from your own website or from another account on the same server never turn up. Email Routing is still set to **Local Mail Exchanger**, or a self-pointing MX was left in the zone. Fix both, in that order.
**Symptom**: mail arrives at the old host intermittently after the change. An old MX record is still published at a higher priority number, so it is being used as a fallback. Delete it rather than demoting it further.
**Symptom**: cPanel rejects the destination as invalid. You have entered an IP address, a URL, or a hostname with a trailing slash. The destination must be a bare fully qualified hostname that resolves to an A or AAAA record.
**Symptom**: mail bounces with a message about too many hops or a delivery loop. Two servers each believe the other is responsible, almost always because an MX points at a host configured to forward back to the same domain. Check the routing setting on both ends.
**Symptom**: senders receive *"550 relay not permitted"* or *"no such user here"* from a server you have just moved away from. The MX moved but the old server still believes it owns the domain. Set that domain to **Remote Mail Exchanger** there, or remove the domain from it once the migration is complete.
**Symptom**: outbound mail started landing in spam folders after the MX change. Changing where mail is received usually means changing where it is sent from too. Update the SPF TXT record to authorise the new provider and remove the old one, publish the new DKIM selector record, and review the DMARC record at `_dmarc.yourdomain.com`. cPanel's **Email > Email Deliverability** screen reports on SPF and DKIM for domains it still handles.
**Symptom**: a deleted MX record reappears. Something else is regenerating it. Check whether the domain still exists in the **Domains** interface and whether Email Routing is set to **Local Mail Exchanger**, which can cause the server to restore its own mail exchanger entry.
**Symptom**: your cPanel does not look like the screenshots above. Newer builds fold **Zone Editor** into a combined **DNS** interface where the Edit and Delete actions work identically, or your Noiz package may use a different control panel entirely. The record values are the same in every panel and only the screen changes.
## Getting Help
MX changes affect live mail, and mistakes tend to surface as messages that quietly go elsewhere rather than as an obvious failure. If you are migrating a busy domain, are unsure which of several MX records should be removed, or have already made a change and mail has stopped arriving, open a ticket in the Noiz client area. Include the domain name, the records your mail provider asked for, and the output of `dig MX yourdomain.com @1.1.1.1 +short`. Noiz support will check the zone, the routing and the authentication records together, and on managed plans will carry out the cutover and confirm the authoritative answer before you rely on it.
# How to Edit the .htaccess File in the cPanel File Manager
Source: https://docs.noiz.ie/cpanel/how-to-edit-the-htaccess-file-in-the-cpanel-file-manager/
The `.htaccess` file is a per-directory Apache configuration file that controls redirects, URL rewriting, access rules, custom error pages and more for your website. This guide shows you how to find, create and edit `.htaccess` safely from the **File Manager** in cPanel, without needing FTP or SSH access.
The file name begins with a dot, which makes it a hidden file, so it will not appear in File Manager until you enable hidden files. That is the step most people miss.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable release, Jupiter interface). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel and Apache documentation linked below.
### Official Documentation Reference
- [cPanel & WHM: File Manager](https://docs.cpanel.net/cpanel/files/file-manager/)
- [Apache HTTP Server: .htaccess files](https://httpd.apache.org/docs/current/howto/htaccess.html)
## Prerequisites
- An active Noiz cPanel hosting account and your login details.
- Knowing which website or directory the change applies to. A site's document root is usually the `public_html` directory.
## Editing .htaccess in File Manager
1. Log in to your cPanel account.
2. In the **Files** section, click **File Manager**. 
3. Navigate to the directory that holds the `.htaccess` file. To edit the `.htaccess` file for your main website, open the `public_html` directory.
4. If the `.htaccess` file is not visible, click **Settings** at the top right of the File Manager toolbar, tick **Show Hidden Files (Dotfiles)** in the dialog, and click **Save**. The `.htaccess` file should now appear. If it still does not exist, create a new file named `.htaccess` in that directory. 
5. Right-click the `.htaccess` file and choose **Edit** from the context menu. 
6. If an encoding confirmation dialog appears, click **Edit** to continue. 
7. Make your changes, then click **Save Changes**. The change takes effect immediately on the next page load. 
## Before You Save: Back Up First
A single syntax error in `.htaccess` can take your whole site offline with a `500 Internal Server Error`, because Apache reads the file on every request. Before editing, copy the existing contents into a plain text file, or use **Copy** in File Manager to keep a backup such as `.htaccess.bak`. If a change breaks the site, restore the backup or remove the lines you added and save again.
## Troubleshooting
**The site returns a 500 error after saving**: the most recent edit contains invalid syntax or a directive your server does not permit. Restore your backup, or comment out the new lines by adding `#` at the start of each line, and save.
**The .htaccess file still will not appear**: confirm **Show Hidden Files (Dotfiles)** is enabled and that you are in the correct directory. If the file genuinely does not exist yet, use **+ File** in the toolbar to create one named `.htaccess` (note the leading dot and no file extension).
Need a hand? Noiz support can review or edit your `.htaccess` file for you. Open a ticket from your Noiz client area and the team will assist.
# How to Enable Hotlink Protection in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-enable-hotlink-protection-in-cpanel/
Hotlinking (also called inline linking, or bandwidth theft) happens when another website embeds one of your images directly from your hosting account instead of uploading its own copy. Every time a visitor loads that external page, the file is served from your account and consumes your bandwidth, while the other site takes the credit. cPanel's **Hotlink Protection** blocks requests for your files unless they come from pages you have approved. This guide shows you how to enable it on your Noiz hosting account, how to configure it so it does not break your own site, and how to prove it is actually working.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel & WHM and its Jupiter interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Docs: Hotlink Protection](https://docs.cpanel.net/cpanel/security/hotlink-protection/)
- [Apache HTTP Server: mod\_rewrite reference](https://httpd.apache.org/docs/current/mod/mod_rewrite.html)
- [MDN: the HTTP Referer header](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Referer)
## Prerequisites
- Your cPanel sign-in details, which are in your Noiz hosting welcome email or available from your [Noiz client area](https://www.noiz.co.za).
- A list of every domain and subdomain that legitimately displays your files: your main site, both the `www` and non-`www` addresses, any staging or demo subdomain, and any other site of yours that embeds the same images.
- If your site runs a CMS such as WordPress, know where its `.htaccess` file lives, because Hotlink Protection writes its rules into that same file.
## How Hotlink Protection Actually Works
Understanding the mechanism saves a lot of guesswork later. When a browser loads a page and then fetches an image embedded in it, the browser normally sends a `Referer` header naming the page the request came from. cPanel writes a set of Apache rewrite rules into the `.htaccess` file in your document root, and those rules inspect that header. If the referring page is on one of your approved domains, the file is served. If it is on anything else, the request is blocked or redirected. You never need to edit `.htaccess` by hand; the settings page manages the rules for you.
Two consequences follow, and between them they explain nearly every problem people hit with this feature:
- The decision rests on a header the visitor's browser supplies, not on anything cryptographic. Privacy extensions, some mobile apps, corporate proxies and strict browser settings strip the `Referer` header entirely, so those requests arrive looking as though nobody sent them. The header can also be forged. Treat Hotlink Protection as a strong deterrent against casual bandwidth theft, not as watertight security.
- Apache applies the rule at the moment the file is requested, so the feature stops embedding, not copying. Anyone can still right-click, save the image, and upload it to their own server. For that you need copyright notices, watermarking and takedown requests rather than a technical block.
## Enable Hotlink Protection
1. Log in to your cPanel account.
2. In the **Security** section, click **Hotlink Protection**. 
3. If the page shows **Hotlink protection is currently disabled**, click **Enable**. The status line at the top of the page changes to confirm it is on. 
Enabling it applies the default settings straight away, so work through the options below before you move on.
## Configure the Settings That Matter
### URLs to Allow Access
cPanel pre-fills this box with the addresses it detects for your account, but the list is rarely complete, and a missing entry means your own pages start showing broken images. Enter one URL per line and include:
- Both the bare and the `www` form of each domain, for example `https://yourdomain.com` and `https://www.yourdomain.com`.
- Every subdomain that embeds your files, such as a demo site at `https://demo.yourdomain.com`.
- Any separate site of yours, or any content delivery network, that legitimately loads the same files.
- The `http://` forms as well, if you still serve anything without TLS.
Replace `yourdomain.com` with your own domain. Anything not on this list is blocked.
### Block Direct Access for the Following Extensions
This comma-separated list decides which file types are protected. The cPanel default is a short list of older image formats, typically `jpg,jpeg,gif,png,bmp`. That default is now the most common reason people conclude Hotlink Protection is broken: modern sites and CMS image plugins serve `webp` and `avif`, and neither is in the default list. Add the formats you actually use, for example:
```
jpg,jpeg,gif,png,bmp,webp,avif,svg
```
If the files being leeched are large media rather than images, add those extensions too, such as `mp4`, `mp3`, `zip` or `pdf`. Do not add `html`, `css` or `js`: blocking stylesheets and scripts breaks legitimate integrations and caching services and gains you almost nothing.
### Allow Direct Requests
A direct request is one that arrives with no referring page at all. Tick this box and those requests are served; untick it and they are blocked as well.
Leave it ticked unless you have a specific reason not to. Requests with no referrer come from people typing an image address straight into the browser, opening an image from a bookmark, email clients displaying images, the link-preview scrapers used by social and messaging platforms, and any visitor whose browser or privacy tool suppresses the header. Unticking this box is the quickest way to break your own site for a slice of entirely ordinary visitors.
### Redirect the Request to the Following URL
Optionally, blocked requests can be sent somewhere else rather than simply failing. Many site owners point this at a branded placeholder image, which turns an attempted hotlink into free advertising. Leave it empty to deny the request outright.
One trap to avoid: do not point the redirect at a file that is itself on a protected domain and carries a protected extension. The replacement image is then blocked in turn and the request loops. Host the replacement elsewhere, give it an extension you have not listed for blocking, or redirect to an ordinary web page instead.
When the fields are set, click **Submit** to save.
## Confirm It Is Working
Do not test by loading your own site, because your own pages are on the allowed list and will look normal either way. Test by pretending to be somebody else. From a terminal, run these two commands, replacing the example domain and image path with your own:
```
curl -s -o /dev/null -w "%{http_code}\n" -e "https://example-thief.com/" https://yourdomain.com/images/logo.jpg
curl -s -o /dev/null -w "%{http_code}\n" -e "https://yourdomain.com/" https://yourdomain.com/images/logo.jpg
```
The first request pretends to come from someone else's site and should return `403`, or `301` or `302` if you configured a redirect. The second pretends to come from your own site and should return `200`. If both return `200`, that file's extension is almost certainly missing from your blocked list.
## Limitations Worth Knowing
- **It only protects files served from your account.** Files delivered through a content delivery network, an object storage bucket, or a separate media host are outside these rules and need protection configured at that service instead.
- **Coverage follows the document root.** The rules are written into the `.htaccess` file in your main document root and are inherited by the folders beneath it. A subdomain or add-on domain whose document root sits outside that folder is not covered.
- **Image search and social previews.** Search engines index images by fetching them, and social and messaging platforms fetch them to build link preview cards. Most of those fetches carry no referrer, so leaving **Allow direct requests** ticked is what keeps them working. Untick it and you may lose image search visibility and preview thumbnails along with the hotlinkers.
- **Legitimate third parties need listing.** If a page builder, a newsletter platform or a partner site loads your images from its own domain, add that domain to the allowed list or its images break too.
## Troubleshooting
**Images on your own site are now broken**: a hostname is missing from **URLs to allow access**. Check the exact address in your browser's URL bar, including whether it carries `www`, and add that exact form. Clear your browser cache and any caching plugin before retesting.
**Hotlinking still works**: the file extension is not in your blocked list. On a modern site this is nearly always `webp` or `avif`. Add it and retest with the `curl` commands above.
**Images vanish from social previews or image search**: tick **Allow direct requests**, since most of those fetches send no referrer, and set a redirect URL to a branded placeholder if you would rather those services receive an image than a block.
**Some visitors see broken images and others do not**: the `Referer` header is being stripped by a privacy tool, proxy or app on their side. Tick **Allow direct requests**.
**The settings reverted on their own**: cPanel stores these rules in `.htaccess`, and some CMS, security and migration plugins rewrite that file wholesale. Find the plugin that regenerates `.htaccess`, then re-save your Hotlink Protection settings afterwards.
**Requests loop or time out**: your redirect target is itself being blocked. Point it at a file on another domain, or at a normal web page.
**There is no Hotlink Protection icon in cPanel**: the feature may be disabled at server level for your plan. Contact Noiz support and the team will confirm what is available on your hosting.
## Need a Hand?
Hotlink Protection is a blunt instrument, and striking the balance between blocking bandwidth theft and keeping your own site working takes a little tuning. If images break after you enable it, or you are unsure which domains to allow or which extensions to block, open a support ticket from your [Noiz client area](https://www.noiz.co.za). If your hosting plan uses a different control panel, the support team will point you at the equivalent setting there and confirm the result for you.
# How to Enable Two-Factor Authentication (2FA) on Your cPanel Account
Source: https://docs.noiz.ie/cpanel/how-to-enable-two-factor-authentication-2fa-on-your-cpanel-account/
Two-Factor Authentication (2FA) adds a second check to your cPanel login. Even if somebody obtains your cPanel username and password, they still cannot get in without the six-digit code generated on your phone. This guide shows you how to turn 2FA on for your own cPanel account on Noiz hosting, what to expect at the next login, and the handful of things that catch people out.
cPanel uses the open TOTP standard (time-based one-time password), so any standard authenticator app works. There is no vendor lock-in and nothing to buy.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel and WHM (the **Jupiter** theme, which is now the default). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [Two-Factor Authentication in cPanel (docs.cpanel.net)](https://docs.cpanel.net/cpanel/security/two-factor-authentication/)
## Prerequisites
- Access to your cPanel account. Your Noiz welcome email contains the login details.
- A phone or device with a TOTP authenticator app installed. Good free options include **Google Authenticator**, **Microsoft Authenticator**, **Aegis**, **2FAS** and **Authy**. Password managers such as Bitwarden and 1Password can also store the code, and recent versions of iOS and Android can generate codes from the built-in password manager.
- The clock on that device set to update automatically. TOTP codes are derived from the current time, so a device with a drifting clock produces codes the server rejects.
## Enable Two-Factor Authentication
1. Log in to your cPanel account.
2. In the **Security** section, click **Two-Factor Authentication**. 
3. Click **Set Up Two-Factor Authentication**. Under **Step 1**, scan the QR code with your authenticator app. If your app cannot scan QR codes, tap the option to add an account manually and type in the **Account** name and **Key** shown on the page instead. 
4. Your app immediately starts producing a six-digit code that changes every 30 seconds. Under **Security Code**, type the code currently displayed and click **Configure Two-Factor Authentication**. 
5. cPanel confirms with **Success: Two-factor authentication is now configured on your account**. Two-factor authentication is live from this point on.
## Before You Close the Setup Page
This is the step most people skip, and it is the one that saves you later. cPanel does not issue printed backup or recovery codes for 2FA. If you lose the device holding the code and you did not keep a copy of the secret, the only way back in is for the server administrator to clear 2FA from your account.
- **Save the secret key.** Copy the **Key** string shown next to the QR code into your password manager, alongside the cPanel login itself. With that string you can re-add the account to a new authenticator app on any device.
- **Add it to a second device.** Scanning the same QR code on a tablet or a second phone gives you an identical code generator and a working spare.
- **Use a password manager that syncs.** Storing the TOTP secret in Bitwarden or 1Password means a lost phone is an inconvenience rather than a lockout.
## What Changes at Your Next Login
From the next sign-in onwards, cPanel asks for your username and password as usual, then presents a second screen requesting the current six-digit code. Enter it and you are in.
Worth knowing about the scope of the protection:
- 2FA applies to interactive logins to the cPanel interface. It is tied to the cPanel account, not to an individual domain, so it covers every domain and add-on domain in that account.
- Protocol-level services authenticate separately and are not covered by cPanel 2FA. FTP, SSH, and email clients connecting over IMAP, POP or SMTP still use their own credentials. Keep those passwords strong and unique, and disable any service you are not actually using.
- Turning 2FA on for your account does not turn it on for anyone else who has access. If a developer or agency has their own cPanel or FTP credentials on the account, review those separately.
## Troubleshooting
- **The code is rejected as invalid**: check the clock on the phone. Set date and time to update automatically, then try the next freshly generated code. Clock drift of more than about a minute is the single most common cause of rejected TOTP codes.
- **The code expired before you typed it**: each code lives for 30 seconds. If the countdown ring is nearly finished, wait for the next code rather than rushing the current one.
- **The Two-Factor Authentication icon is not in the Security section**: the feature is switched on at server level. Contact the Noiz support team through the client area and ask for it to be enabled on your hosting package.
- **You lost the phone and have no copy of the key**: contact Noiz support from the email address registered on the account. After identity verification the support team can clear 2FA so you can log in and set it up again on your new device.
- **You want to switch it off deliberately**: see [How to Disable the Two-Factor Authentication on Your cPanel Account](/cpanel/how-to-disable-two-factor-authentication-on-your-cpanel-account/).
## Need a hand?
If you are on a managed Noiz plan, or you are locked out and need 2FA cleared from your account, contact the Noiz support team through the client area and the team will assist.
# How to Enable or Disable ModSecurity in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-enable-or-disable-modsecurity-in-cpanel/
ModSecurity is the web application firewall that sits in front of your site and inspects every request before your website code ever sees it. Most of the time you never notice it. You notice it on the day a perfectly ordinary action, saving a WordPress post, submitting a contact form, uploading a file, suddenly returns **403 Forbidden** for no obvious reason. This guide shows you how to switch ModSecurity off and on from cPanel, for every domain at once or for a single domain, how to confirm it is genuinely the thing blocking you, and why turning it off is a diagnostic step rather than a fix.
You will see the name written several ways. *ModSecurity*, *Mod Security*, *mod\_security* and *modsec* all mean the same module. cPanel labels it **ModSecurity**, and that is the spelling used throughout this article.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the current STABLE and LTS tier) and the **134** LTS release tier. The ModSecurity interface described here has been present in this form since cPanel version 82 and the steps have not changed across recent releases. This guide is written for Noiz customers and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel: ModSecurity](https://docs.cpanel.net/cpanel/security/modsecurity/) for the reference description of the interface itself.
- [WHM: ModSecurity Tools](https://docs.cpanel.net/whm/security-center/modsecurity-tools/) if you have a VPS or dedicated server with WHM access and want to disable one rule rather than the whole module.
- [OWASP Core Rule Set documentation](https://coreruleset.org/docs/) for what the standard rule set actually blocks and why false positives happen.
## Prerequisites
- Your cPanel username and password, and the login address for your server.
- The **ModSecurity** icon present in the **Security** section of cPanel. It is a feature that the server administrator can switch off per hosting package, so it is not on every account.
- The exact time, URL and action that triggered the block, if you are troubleshooting. That detail is what turns a guess into a diagnosis.
## What ModSecurity Does and Why It Blocks You
ModSecurity reads each incoming request and compares it against a rule set, usually the OWASP Core Rule Set or a commercial equivalent. Requests that match a rule for SQL injection, cross-site scripting, remote file inclusion, command injection, known scanner signatures or malformed input are refused before they reach PHP. It is genuinely useful protection, and on a busy site it quietly turns away thousands of hostile requests a week.
The trade-off is false positives. The rules look at patterns, not intent, so legitimate content can look like an attack. The usual offenders are:
- Saving a WordPress post or page that contains code samples, SQL snippets, script tags or long base64 strings.
- Page builders and theme editors, which post large blocks of markup and serialised data.
- WooCommerce checkout and admin actions, plugin and theme file editors, and bulk import tools.
- `xmlrpc.php` requests from mobile apps and remote publishing tools.
- Contact forms where somebody pastes a URL, an apostrophe-heavy sentence or a block of code.
When a rule fires, the visitor gets a **403 Forbidden**, or occasionally a **406 Not Acceptable**, and the page fails immediately rather than timing out. The tell-tale sign is that browsing the site works perfectly but one specific action, almost always a form submission or a save, fails every single time.
## Check That ModSecurity Is Really the Cause
Before changing anything, spend two minutes confirming the diagnosis. Turning ModSecurity off will not fix a problem it is not causing, and you will have left your site unprotected for nothing.
### Read Your Own Error Log
In cPanel, open **Metrics** and then **Errors**. That page shows the most recent Apache error log entries for your account. A ModSecurity denial is unmistakable and looks roughly like this:
```
ModSecurity: Access denied with code 403 (phase 2). Matched "Operator Rx" against variable "ARGS:content" [id "941100"] [msg "XSS Attack Detected"] [hostname "yourdomain.com"] [uri "/wp-admin/post.php"]
```
Two fields matter. The `id` is the rule number, and the `uri` is the page that was blocked. Note both down. The rule ID is the single most useful piece of information you can give support, because it allows one rule to be excluded instead of the whole firewall being switched off.
### Rule Out a Firewall IP Block
A repeatedly blocked IP address is a different problem with a different fix. ModSecurity refuses one request at a time and returns a web page saying access is forbidden. A firewall block drops your IP address entirely, so the symptoms are much broader:
- The whole site stops loading and eventually times out, rather than returning a 403 page.
- Webmail, FTP and cPanel itself become unreachable at the same time.
- The site loads normally on mobile data, on a VPN or from another location, because only your IP address is blocked.
If that is what you are seeing, disabling ModSecurity will change nothing. The block needs lifting at the firewall, which means opening a ticket with Noiz and quoting the public IP address you are connecting from.
## How to Enable or Disable ModSecurity for All Domains
Noiz does not recommend leaving ModSecurity off. Use this to prove a point during troubleshooting, then put it back on. If a genuine application bug is being masked by the firewall, fixing the bug is the durable answer.
1. Log in to your cPanel account.
2. In the **Security** section, click **ModSecurity**.

3. Look at the **Configure All Domains** area at the top of the page. If ModSecurity is currently on, a **Disable** button is shown. Click it, then click **Disable All** in the confirmation box that appears. If ModSecurity is currently off, the button reads **Enable** instead, and clicking it switches it back on for every domain on the account.

The change is not instant. cPanel rewrites the Apache configuration for your domains and queues a graceful restart, which normally takes under a minute. If the site behaves exactly the same the second after you click, wait a moment and retest rather than clicking again.
Retest in a private or incognito browser window. A cached 403 response, from your browser or from a CDN in front of the site, will keep showing the old error long after the cause has gone.
## How to Enable or Disable ModSecurity for a Single Domain
If you host several domains, there is no reason to strip protection from all of them because one is misbehaving. The same page lets you set each domain individually.
1. Log in to cPanel, and in the **Security** section click **ModSecurity**.
2. Scroll down to **Configure Individual Domains** at the bottom of the page. Every domain, subdomain and addon domain on the account is listed there.
3. Find the domain in the list and, in the **Status** column beside it, click **On** or **Off**.

Three things catch people out here:
- **The global setting wins.** ModSecurity has to be enabled under **Configure All Domains** before the per-domain settings do anything. If you disabled everything first, the individual toggles will not give you the result you expect until you enable globally again.
- **A domain and its www version are one entry.** They share a virtual host, so setting one covers both. Subdomains and addon domains are separate entries with separate settings.
- **Off means completely off.** A domain set to **Off** has no ModSecurity rules applied to it at all. It is not a reduced or relaxed mode.
## A Better Fix Than Turning It Off
Disabling a web application firewall to get past one blocked form is like disconnecting a smoke alarm because the toast burned. It works, and it leaves you with no smoke alarm.
Once you have the rule ID from the error log, the surgical fix is to exclude that one rule, either globally or just for the URL where it misfires. Everything else in the rule set stays active. On shared hosting the interface for that lives in WHM, which end users do not have, so the route is to open a ticket with Noiz and include:
- The domain and the exact URL that was blocked.
- The date and time of the block, with your timezone.
- The rule ID and the `msg` text from the error log entry.
- What you were doing when it happened, in one sentence.
With that, a single rule can be excluded for your account in minutes and your site keeps its protection. If you run a VPS or dedicated server with WHM access, you can do the same yourself under **WHM** and then **Security Center** and then **ModSecurity Tools**, where the **Hit List** shows recent triggers and lets you disable an individual rule.
If you do decide to leave ModSecurity off on a domain, treat it as a decision with consequences. That domain now depends entirely on your own code, your plugins and your update discipline to keep hostile requests out. Keep the application and its plugins patched, use strong administrator passwords with two-factor authentication, and set a reminder to switch protection back on once the underlying problem is fixed.
## Troubleshooting
**Symptom**: there is no **ModSecurity** icon in the **Security** section. The feature has been removed from your hosting package's feature list, or the module is not installed on that server. It is not something you can restore from inside cPanel. Open a ticket and ask for the feature to be enabled on your account.
**Symptom**: the **On** and **Off** options under **Configure Individual Domains** do nothing, or the list appears inactive. ModSecurity is disabled globally. Enable it under **Configure All Domains** first, then set the individual domains you want switched off.
**Symptom**: the 403 error is still there after disabling ModSecurity. Give it a minute for the Apache configuration to rebuild, then retest in a private browsing window. If it persists, the block is coming from somewhere else. The usual candidates are a `Deny` or `Require` rule in `.htaccess`, hotlink protection, wrong file or directory permissions, a security plugin inside the application, or a CDN or proxy sitting in front of the site with its own firewall.
**Symptom**: the main domain works after disabling, but a subdomain or addon domain still fails. Each one is listed and controlled separately under **Configure Individual Domains**. Set the specific hostname that is failing, not just the primary domain.
**Symptom**: the whole site is unreachable, along with webmail, FTP and cPanel, but it loads on mobile data. That is a firewall block on your IP address rather than ModSecurity. Contact Noiz support with the public IP address you are connecting from and ask for it to be released.
**Symptom**: the block only happens on large uploads or long form submissions. ModSecurity has request body size limits alongside the rule set, and PHP has its own upload and post size limits. Check the error log entry: a size-related ModSecurity rule names the limit it hit, whereas a PHP limit produces a different error entirely.
**Symptom**: the toggle reverts to its previous state after you reload the page. The configuration change failed to save, which usually points to a problem on the server rather than with your account. Open a ticket rather than repeatedly retrying, and mention which domain and which direction you were trying to set.
## Related Articles
- [How to Block an IP Address in cPanel](/cpanel/how-to-block-an-ip-address-in-cpanel/) for stopping a specific visitor at the server rather than the firewall.
- [How to Edit the .htaccess File in the cPanel File Manager](/cpanel/how-to-edit-the-htaccess-file-in-the-cpanel-file-manager/) for checking whether a rule in your own configuration is causing the 403.
- [How to Enable Hotlink Protection in cPanel](/cpanel/how-to-enable-hotlink-protection-in-cpanel/) for another common source of unexpected Forbidden errors.
- [How to Enable the Two-Factor Authentication on Your cPanel Account](/cpanel/how-to-enable-two-factor-authentication-2fa-on-your-cpanel-account/) for hardening the account itself.
## Getting Help
If a legitimate part of your site is being blocked and you would rather not run without a web application firewall, open a ticket in the Noiz client area with the domain, the blocked URL, the timestamp and the rule ID from your error log. On managed plans the Noiz team can review the trigger and exclude the specific rule for your account, so your site keeps working and keeps its protection. If your IP address has been blocked at the firewall, include the public address you are connecting from and it can be released for you.
# How to Forward Email to Gmail or Another Provider in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-forward-email-to-gmail-or-another-provider-in-cpanel/
Email forwarding lets you send a copy of every message that arrives at one address to another mailbox automatically, without logging in to check two accounts. This guide shows you how to set up a forwarder in cPanel, whether you want to forward mail to Gmail, Outlook, or any other provider, or pipe incoming mail into a script for automated processing.
A forwarder does not need its own mailbox. It simply hands each incoming message straight to the destination you choose, so it is an ideal way to route mail for an address you do not want to log in to separately.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable release, Jupiter interface). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel ยป Email ยป Forwarders](https://docs.cpanel.net/cpanel/email/forwarders/) (interface reference and field descriptions)
- [cPanel ยป Email ยป Email Routing](https://docs.cpanel.net/cpanel/email/email-routing/) (how incoming mail is delivered)
## Prerequisites
- A cPanel account on your Noiz hosting plan, with your login details.
- A domain whose mail is delivered to the server (its MX records point to the Noiz mail server). If your domain uses a third party for mail, forwarders created here will not take effect.
- The destination address you want mail sent to, such as your Gmail or Outlook address.
## Forward an Email Address to Gmail or Another Provider
1. Log in to your cPanel account.
2. In the **Email** section, click **Forwarders**, then click **Add Forwarder**. 
3. Enter the following details: 
- **Address to Forward**: enter the local part of the address you want to forward. To forward `myemail@example.com`, enter `myemail` in this field (leave out the `@` and the domain).
- **Domain**: if your account hosts more than one domain, select the correct one from the **Domain** drop-down list.
4. In the **Destination** field, select **Forward to email address** and enter the address where you want to receive the forwarded mail, for example your Gmail address.
5. Click **Add Forwarder**.
New mail arriving at the forwarded address will now be delivered to the destination automatically. Messages that arrived before you created the forwarder are not affected.
## Pipe an Email to a Script or Program
Instead of sending mail to another address, you can pipe each incoming message into a program running on the server. This is useful for automation such as ticketing systems, contact-form processors, or custom parsers that read the raw message from standard input.
1. In the **Email** section, click **Forwarders**, then click **Add Forwarder**.
2. Enter the following details:
- **Address to Forward**: enter the local part of the address you want to pipe.
- **Domain**: select the correct domain from the **Domain** drop-down list if you host more than one.
3. In the **Destination** field, click **Advanced Options**, select **Pipe to a Program**, and enter the path to your script, for example `home/username/public_html/myemailpipe.php`. Note that the path is relative to your account home directory, so it does not begin with a leading slash. 
4. Click **Add Forwarder**.
For the pipe to work correctly, the script must:
- Be executable (typically `chmod 0700` or `0755`).
- Begin with a valid shebang line, such as `#!/usr/bin/php` or `#!/usr/bin/perl`.
- Read the incoming message from standard input and exit cleanly.
If the script fails or exits with an error, the incoming message may bounce back to the sender, so test your script from the command line before you rely on it.
## Troubleshooting
**Forwarded mail lands in spam at Gmail or Outlook:** when a message is forwarded, the receiving provider sees it arriving from the Noiz mail server rather than the original sender, and a strict DMARC or SPF policy on the sender's domain can cause it to be flagged. The server rewrites the return path to reduce this, but for high-volume or business-critical mail, collecting the mailbox directly over IMAP or POP3, or adding a filter rule at the destination, is more reliable than forwarding.
**Nothing arrives at the destination:** confirm the domain's MX records point to the Noiz mail server so that mail is actually delivered to this account. If mail for the domain is handled elsewhere, a cPanel forwarder will never see the message.
**A piped script produces a bounce:** run the script manually from a terminal, feeding it a sample message on standard input, and check the file permissions and shebang line. Path errors are the most common cause, so double-check that the path is correct and has no leading slash.
If you are on a managed Noiz plan and would like help configuring forwarding or a mail pipe, [open a support ticket](https://www.noiz.co.za/submitticket.php) from your Noiz client area and the team will assist.
# How to Generate a cPanel Backup and Send it to FTP
Source: https://docs.noiz.ie/cpanel/how-to-generate-a-cpanel-backup-and-send-it-to-ftp/
A full cPanel backup packages everything in your hosting account (your home directory and website files, databases, email accounts, forwarders and filters, and account settings) into a single downloadable archive. Sending that archive straight to a remote FTP or SCP server keeps a copy off the hosting server, which is exactly what you want for disaster recovery or for moving to a new server. This guide shows you how to generate a full backup in cPanel and have it delivered to a remote FTP destination.
**Last reviewed:** 27 July 2026, against the cPanel **Jupiter** interface (current default). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [Backup for cPanel](https://docs.cpanel.net/cpanel/files/backup-for-cpanel/) (the interface used in this guide)
- [Backup Wizard](https://docs.cpanel.net/cpanel/files/backup-wizard/) (guided partial backups and self-service restores)
## Prerequisites
- Access to your cPanel account.
- The remote FTP or SCP server's hostname or IP address, a username and password, the port number, and a writable target directory that already exists on the remote server.
## Generate a Full Backup and Send it to FTP
### 1. Open the Backup interface
Log in to your cPanel account. In the **Files** section, click **Backup**.

### 2. Start a full account backup
Under **Full Backup**, click **Download a Full Account Backup**.

### 3. Choose the remote FTP destination
On the **Generate a Full Backup** page, complete the fields:
- **Backup Destination:** select **Remote FTP Server**. If the connection stalls or the transfer fails, choose **Remote FTP Server (passive mode transfer)** instead, which works better through firewalls. For an encrypted transfer, choose **Secure Copy (SCP)** where the remote server supports it.
- **Email Address:** enter the address where cPanel should send a notification once the backup finishes. To skip the notification, tick **Do not send email notification of backup completion**.
- **Remote Server:** the FTP host, for example `ftp.yourdomain.com` (an example to replace with your own) or its IP address.
- **Remote User:** your FTP username.
- **Remote Password:** your FTP password.
- **Port:** `21` for standard FTP, or `22` for SCP. Use whichever port your remote server listens on.
- **Remote Dir:** the target folder on the remote server, for example `/home/username/backupfolder/`. The directory must already exist and be writable.
### 4. Generate the backup
Click **Generate Backup**. cPanel builds the archive in the background and uploads it to the remote server. Large accounts can take a while, so you do not need to keep the page open. If you left the email notification enabled, you will be told when it has finished.

## Good to Know
- **A full backup is for migration and safekeeping, not one-click restores.** You cannot restore a full account backup through the cPanel interface yourself; restoring one requires server-level (root) access. To restore individual files, folders, or databases on your own, use the **Backup Wizard** or the **File and Directory Restoration** tool instead.
- **Standard FTP is not encrypted.** Your username, password, and files travel in plain text over FTP. Prefer **Secure Copy (SCP)** where the remote server supports it.
- **Check the remote free space.** The archive contains your entire account, so make sure the remote server has enough space to receive it.
- **Back up regularly.** A backup is only useful if it is recent. Keep to a routine and hold at least one copy off the hosting server.
## Troubleshooting
- **The transfer fails or times out:** switch the Backup Destination to **Remote FTP Server (passive mode transfer)**. Active-mode FTP is often blocked by firewalls and NAT.
- **Login or permission errors:** confirm the username, password, and port, and make sure the **Remote Dir** exists and is writable by that account.
- **No confirmation email:** check the address you entered and your spam folder, or confirm you did not tick the do-not-notify option.
## Need a Hand?
If your Noiz plan includes cPanel and you would like help configuring a remote backup destination, or you need a full backup restored, open a support ticket from your Noiz client area and the team will assist.
# How to Generate and Download a Full Backup of Your cPanel Account
Source: https://docs.noiz.ie/cpanel/how-to-generate-and-download-a-full-backup-of-your-cpanel-account/
A recent backup is your safety net if a website is hacked, a bad update breaks it, or you delete something by mistake. This guide shows you how to generate and download a full backup of your cPanel account on Noiz hosting, so you always have a copy of your files, databases and email in a single archive that you can keep safely off the server.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM Jupiter interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Docs: Backup interface](https://docs.cpanel.net/cpanel/files/backup-for-cpanel/)
- [cPanel Docs: Backup Wizard](https://docs.cpanel.net/cpanel/files/backup-wizard-for-cpanel/)
## Prerequisites
- Your cPanel sign-in details, which are in your Noiz hosting welcome email or available from your [Noiz client area](https://www.noiz.co.za).
- Enough free disk space to hold the archive. A full backup is written into your home directory first, so it briefly needs roughly as much free space as your account currently uses.
## Full Backup or Partial Backup: Which One You Need
Before you start, it is worth knowing the difference, because it decides whether you can restore the backup yourself later.
- A **full backup** archives everything in one file: your home directory, databases, email accounts, forwarders and filters. It is the right choice for keeping a complete off-server copy or for moving an account to another server. The catch is that a full backup cannot be restored from within cPanel; only a server administrator can restore it. On Noiz managed plans, the support team does that for you.
- A **partial backup** covers one part at a time (your home directory, a single MySQL database, or your email forwarders and filters). Partial backups are the ones you can restore yourself through cPanel. If your goal is to be able to roll something back on your own, take partial backups as well.
## Generate a Full Backup
1. Log in to your cPanel account.
2. In the **Files** section, click **Backup**. 
3. Under **Full Backup**, click **Download a Full Account Backup**. 
4. Set the **Backup Destination** to **Home Directory**. Enter your email address so that cPanel notifies you when the archive is ready. If you would rather not be emailed, choose **Do not send email notification of backup completion** instead. 
5. Click **Generate Backup**. cPanel builds the archive in the background; a large account can take several minutes.
## Download the Backup
When the backup finishes you receive a notification, if you supplied an email address. Return to **Files** > **Backup** and, under **Backups Available for Download** on the Full Backup screen, click the archive (a `.tar.gz` file) to save it to your computer.

Once the file is safely on your own computer or another storage location, delete the copy that was left in your home directory so that it does not count against your disk quota.
## Good Practice
- **Keep the backup off the server.** A backup that only lives in your hosting account is lost if the account itself has a problem, so always download it and store a copy elsewhere.
- **Back up before big changes.** Take a fresh backup before updating your CMS, swapping themes or plugins, or editing the database, so you have a clean point to return to.
- **Mind your disk quota.** Because the archive is created in your home directory first, a very large account can hit its quota while the backup runs. Free up space, or ask Noiz support, if the backup will not complete.
## Troubleshooting
**The backup never completes or errors out**: this is usually a disk-space or quota problem, because the archive is built inside your account. Remove old backups and unnecessary files, then try again.
**You need to restore a full backup**: a full account backup cannot be restored from within cPanel. If you are on a Noiz managed plan, open a support ticket and the team will restore it for you. If you only need to roll back one part, use the partial-backup restore option on the Backup screen instead.
**The download is very slow or times out**: large archives download best over a stable connection. If the browser download keeps failing, contact Noiz support for an alternative way to retrieve the file.
## Need a Hand?
If you are on a Noiz managed hosting plan and would like a backup taken or restored for you, open a support ticket from your [Noiz client area](https://www.noiz.co.za) and the support team will handle it and confirm it is done.
# How to Include or Exclude a Domain from AutoSSL in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-include-or-exclude-a-domain-from-autossl-in-cpanel/
AutoSSL is the cPanel feature that issues and renews free domain-validated SSL certificates for the domains on your hosting account, without you having to buy, install or manually renew anything. By default it tries to cover every domain and subdomain on the account, but you decide which ones it actually looks after. This guide shows you how to add a domain to AutoSSL coverage (include it) and how to take one out of coverage (exclude it), and explains when each is the right move.
**Last reviewed:** 27 July 2026, against cPanel & WHM **v136** (current release tier). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
If the domain was only just created, give AutoSSL a few hours before you assume anything is wrong. cPanel runs AutoSSL on a schedule rather than the instant a domain appears, so a brand new domain or subdomain will normally pick up a certificate on the next run. You can see exactly what happened on the last run under **cPanel > SSL/TLS Status > Certificate Status**.
### Official Documentation Reference
- [cPanel Docs: SSL/TLS Status](https://docs.cpanel.net/cpanel/security/ssl-tls-status/) (the interface used throughout this guide)
- [cPanel Docs: Guide to SSL](https://docs.cpanel.net/knowledge-base/security/guide-to-ssl/) (background on certificates, DCV and issuance)
- [cPanel Docs: Manage AutoSSL](https://docs.cpanel.net/whm/ssl-tls/manage-autossl/) (server-administrator level settings, for context)
## Prerequisites
- A cPanel account on your Noiz hosting plan, and your cPanel login details.
- The domain or subdomain already added to the account (as an addon domain, subdomain, alias or the main domain).
- The domain resolving to your hosting server. AutoSSL proves ownership by fetching a validation file over HTTP, so a domain whose DNS points somewhere else cannot be validated.
- If you also want to force a certificate to issue immediately rather than waiting for the scheduled run, see [How to Install an SSL on Your Domain Using AutoSSL in cPanel](/security/how-to-install-an-ssl-certificate-on-your-domain-using-autossl-in-cpanel/).
## How to Include a Domain in AutoSSL
1. Log in to your cPanel account.
2. In the **Security** section, click **SSL/TLS Status**. 
3. Under **Domain**, tick the checkbox next to each domain or subdomain you want AutoSSL to cover, then click **Include x domain(s) during AutoSSL**. The selected domains and subdomains are added to AutoSSL coverage and will be picked up on the next run. 
The button label changes to match what you have selected, so it reads **Include 1 domain during AutoSSL** for a single tick and counts upwards from there. If the button appears greyed out or missing, you have not ticked anything yet.
Including a domain does not issue the certificate there and then. It adds the domain to the queue for the next scheduled AutoSSL run, which is normally daily. If you need the certificate now, run AutoSSL manually from the same page.
## How to Exclude a Domain from AutoSSL
1. On the **SSL/TLS Status** page, under **Domain**, tick the checkbox next to each domain you want AutoSSL to leave alone.
2. Click **Exclude x domain(s) from AutoSSL**. The selected domains and subdomains are removed from AutoSSL coverage. 
**Note:** the exclude option only applies to domains that are currently within AutoSSL coverage. A domain that has already been excluded, or that was never included, has nothing to exclude, so cPanel will not offer the option for it.
## When Should You Exclude a Domain?
Excluding is not something to do casually, because an excluded domain stops receiving free renewals. These are the situations where it genuinely helps:
- **The domain does not point at this server.** If DNS for a domain is aimed at a different host, AutoSSL will attempt validation, fail, and email you about it on every run. Excluding it stops the noise until you are ready to move the DNS across.
- **You are using a commercial or third-party certificate.** If you have purchased a certificate and installed it yourself, excluding the domain keeps AutoSSL out of the way entirely, so there is no chance of it being replaced when it nears expiry.
- **The certificate is terminated in front of the server.** Where a proxy or CDN presents its own certificate to visitors, the validation request may never reach cPanel. Excluding the domain avoids repeated failures for a certificate the origin does not need.
- **Service subdomains that do not resolve.** cPanel automatically creates service subdomains such as `mail.`, `cpanel.`, `webmail.`, `webdisk.` and `autodiscover.` for each domain. If those hostnames have no DNS records, AutoSSL reports a partial failure even though the main domain is fine. Excluding just those entries produces a clean run.
**The thing to be aware of before you exclude:** exclusion is permanent until you reverse it. An excluded domain that already holds an AutoSSL certificate keeps that certificate until it expires, and then it simply is not renewed. At that point visitors start seeing browser security warnings. If you exclude a live domain, put a reminder in your diary for the certificate expiry date, or re-include the domain well before then.
## Troubleshooting
**Symptom: the Include or Exclude button does nothing or looks disabled.** No domain is selected. Tick at least one checkbox in the **Domain** column first; the button label updates to show the count.
**Symptom: the domain has been included for over 24 hours but still has no certificate.** Validation is failing. Open **SSL/TLS Status** and read the message in the **Certificate Status** column, then check that the domain's A record points to your hosting server and that `http://yourdomain.com/.well-known/` is reachable. Redirect rules in `.htaccess` that force every request to HTTPS or to another URL are the most common cause, because they intercept the validation file before cPanel can serve it.
**Symptom: you keep receiving "AutoSSL could not issue a certificate" notices.** Either fix the underlying DNS or redirect problem, or exclude the domain that is failing. Excluding the specific failing entry, rather than turning coverage off across the account, keeps the rest of your certificates renewing normally.
**Symptom: a site started showing a certificate warning after you excluded it.** The old certificate has expired and was not renewed because the domain is out of coverage. Re-include the domain, then run AutoSSL to issue a fresh certificate straight away.
**Symptom: you cannot find SSL/TLS Status in cPanel.** The tool lives under **Security**. If it is genuinely absent, AutoSSL may be disabled at server level on your plan, or your account may be on a control panel other than cPanel. Open a ticket and Noiz support will confirm which applies to your account.
## Getting Help from Noiz
If a domain refuses to validate and the checks above have not identified why, raise a support ticket from your Noiz client area with the domain name and the exact message shown in the **Certificate Status** column. Noiz support can read the AutoSSL log on the server, confirm what the validation attempt actually returned, and tell you whether the problem is DNS, a redirect, or something at server level. On managed plans Noiz will make the fix for you rather than just describing it.
# How to Password Protect a Directory in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-password-protect-a-directory-in-cpanel/
**Directory Privacy** in cPanel lets you put a username and password in front of any folder in your hosting account, so a visitor has to authenticate before the browser will show anything inside it. It is the quickest way to lock down a staging area, a client preview, a private download folder or an admin section without writing any code. You may also see the feature called password protected directories or htpasswd protection.
Behind the scenes cPanel writes a standard `.htaccess` file into the folder and stores the usernames and hashed passwords in an `.htpasswd` file outside your web root. That switches on HTTP Basic Authentication, so the protection covers the whole folder and every file and sub-folder beneath it, and it is enforced by the web server before your application ever runs.
**Last reviewed:** 27 July 2026, against cPanel with the **Jupiter** interface (current default). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: Directory Privacy](https://docs.cpanel.net/cpanel/files/directory-privacy/)
- [cPanel Documentation: File Manager](https://docs.cpanel.net/cpanel/files/file-manager/)
## Prerequisites
- An active Noiz cPanel hosting account and your cPanel login details.
- The path of the folder you want to protect, for example `public_html/members` or `public_html/staging`.
- An SSL certificate active on the domain, so credentials are sent over HTTPS rather than in clear text. If the domain is not covered yet, you can issue a certificate from the **SSL/TLS Status** area in cPanel.
## Protect a Directory Step by Step
Directory Privacy sits in the **Files** section of the cPanel home page. If you cannot spot it, type `Directory Privacy` into the search box at the top of the page to jump straight to it.
1. Log in to your cPanel account.
2. In the **Files** section, click **Directory Privacy**. On some cPanel builds this tool is also surfaced under a **Security** group; either entry opens the same screen. 
3. Click a directory name to open it and browse to the folder you want to protect. Clicking the name navigates into the folder, which is how you reach nested paths such as `public_html/staging`. 
4. Click **Edit** next to the directory you want to protect. Use the **Edit** button rather than the folder name, which only navigates deeper. 
5. Under **Security Settings**, tick **Password protect this directory** and give the protected area a name, then click **Save**. That name appears in the browser login prompt, so keep it descriptive and do not put anything confidential in it. 
6. Click **Go Back** to return to the settings page. 
7. Scroll down to **Create User**. Fill in a username and password, or use the **Password Generator** to create a strong random password. If you generate one, copy it somewhere safe before you continue, because cPanel stores only a one way hash and cannot show it to you again. Click **Save**. 
The folder is protected as soon as the user is saved. There is no waiting period and nothing to restart. If you open the folder in a browser at an address such as `https://yourdomain.com/myfolder` (replace with your own domain and folder), the browser prompts for the username and password before it shows any content.

Test in a private or incognito window. Browsers cache Basic Authentication credentials for the rest of the session, so a normal window will often let you straight through and make it look as though nothing was applied.
## Add, Change or Remove Users
Go back into **Directory Privacy**, browse to the folder and click **Edit** again.
- **Add another user:** complete the **Create User** fields and click **Save**. A directory can hold as many users as you need, which is the tidy way to give several people access without everyone sharing one password.
- **Change a password:** enter the existing username with the new password in **Create User** and save. cPanel overwrites the stored hash for that user.
- **Remove a user:** select the username in the authorised users list and click **Delete User**.
- **Remove protection entirely:** untick **Password protect this directory** and click **Save**. Deleting the users on their own is not enough, because the folder stays protected and simply has nobody left who can get in.
## Good to Know
- **It protects everything inside the folder.** Every file and sub-folder is covered, including files you add later. There is no per-file control, so put private material in its own directory rather than mixing it with public files.
- **It protects paths, not data.** Anything reachable through a different path is still public. Protecting `public_html/uploads` does nothing for the same files if a script serves them from elsewhere or another folder exposes them.
- **Do not protect your document root by accident.** If you enable Directory Privacy on `public_html`, the whole website asks for a password. That is fine for a staging site, but it also blocks payment callbacks, webhooks and search engine crawling, and it is a common way to lock every visitor out of a live site.
- **Keep HTTPS on.** Basic Authentication sends the username and password with each request, Base64 encoded rather than encrypted. Over HTTPS that is protected in transit; over plain HTTP it is effectively in the clear. Always access a protected folder via `https://`.
- **It is a layer, not a replacement.** Directory Privacy in front of an application login is a useful extra barrier, but it is not a substitute for keeping that application patched and its own accounts secure.
- **Browsers remember the login for the session.** To force the prompt again after a successful login, close the browser or use a private or incognito window.
## Troubleshooting
**The browser does not ask for a password:** you are probably still authenticated from earlier in the session, or the page is cached. Test in a private or incognito window, and clear any caching plugin or CDN sitting in front of the site, since a cached response can be served without ever reaching the web server.
**The login box keeps reappearing with the correct password:** the credentials are being rejected rather than accepted. Recreate the user with a freshly generated password, and watch for a trailing space picked up when pasting.
**You see a 500 Internal Server Error after enabling protection:** this usually points to a conflict in an existing `.htaccess` file in that folder. Open **File Manager**, switch on **Show Hidden Files** in its settings and inspect the file, or open a support ticket and Noiz will resolve it.
**Parts of the site stop working:** scripts, stylesheets, images and API endpoints under the protected path are subject to the login too. Protecting a WordPress `wp-admin` folder, for example, also blocks `admin-ajax.php` and breaks front end features that depend on it. Protect a level that matches the boundary you actually want.
**You have locked yourself out of the whole site:** protection was almost certainly enabled on `public_html`. Return to **Directory Privacy**, edit that directory, untick **Password protect this directory**, and save.
**Directory Privacy is not in your cPanel:** the feature is controlled by the hosting package. If your plan should include it, contact Noiz support.
If you need a hand setting up protected areas, or you have locked out a live directory and cannot get back in, open a support ticket from your Noiz client area and the team will assist. On a managed plan, changes of this kind can be handled for you.
# How to Redirect Your Website to Any Page or External Domain
Source: https://docs.noiz.ie/cpanel/how-to-redirect-your-website-to-any-page-or-external-domain/
A redirect sends anyone who visits one web address straight on to another. You can point your whole domain at a different site, send a single old page to its new home, or forward a folder such as `/blog` to somewhere else entirely. This guide shows you how to set one up with the **Redirects** tool in cPanel, and how to choose between a permanent and a temporary redirect.
**Last reviewed:** 27 July 2026, against cPanel & WHM's **Jupiter** interface (latest stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel ยป Domains ยป Redirects](https://docs.cpanel.net/cpanel/domains/redirects/)
## Prerequisites
- You can log in to your cPanel account. Noiz sends your login details when your account is set up, and you can also open cPanel from your Noiz client area.
- The domain you want to redirect is added to the account and its DNS points at the server. A redirect only takes effect once visitors are actually reaching this server for that domain.
## Add a Redirect in cPanel
1. Log in to your cPanel account.
2. In the **Domains** section, click **Redirects**. 
3. Under **Add Redirect**, fill in the details and choose the options you want: 
- **Type**: choose **Permanent (301)** or **Temporary (302)**. See the note below on which to pick.
- **https?://(www.)?**: pick the domain from the drop-down list. Leave the text box next to it empty to redirect the whole domain, or type a folder or page name (for example `old-page.html` or `blog`) to redirect just that path.
- **Redirects to**: enter the full destination address, including `https://`, for example `https://www.yourdomain.com/new-page.html`.
- **www. redirection**: choose whether the redirect fires for the `www` version of the address, the non-`www` version, or both. **Redirect with or without www.** is the safest choice for most sites.
- **Wild Card Redirect**: tick this to forward every sub-path to the matching path on the destination, so `yourdomain.com/anything` lands on `destination.com/anything`. Leave it unticked to send every request to the single destination address.
4. Click **Add**. cPanel confirms the redirect and it takes effect straight away. 
## Permanent (301) or Temporary (302)?
The type you choose tells browsers and search engines how to treat the move:
- **Permanent (301)** means the address has moved for good. Search engines pass the old page's ranking on to the new address, so this is the right choice when you have retired a page or moved a site. Browsers cache a 301 aggressively, which is worth knowing: once a visitor's browser has followed one, it may keep going to the destination even after you delete the redirect. Clear the browser cache, or test in a private window, when you are checking your work.
- **Temporary (302)** means the move is short-lived, for example while a page is under maintenance. Search engines keep the original address indexed and browsers do not cache it, so it is the safer choice whenever you plan to undo the redirect later.
## How the Redirect Is Stored
cPanel writes each redirect as a rule in the `.htaccess` file for the domain. That has two practical consequences. Redirects only work on domains served by Apache on this account, which covers standard Noiz cPanel hosting. And if you edit `.htaccess` by hand, take care not to remove the redirect rules cPanel added, or delete them there if you want to remove a redirect that way.
## Remove a Redirect
To undo a redirect, return to **Domains ยป Redirects**, find it in the **Current Redirects** list at the bottom of the page, and click **Delete** next to it. Because of the browser caching mentioned above, test the result in a fresh private window rather than the browser you set the redirect up in.
## Troubleshooting
- **The redirect does not fire at all**: confirm the domain's DNS points at this server. If visitors are being served by another host, a redirect set here never runs. On Noiz hosting the client nameservers are `ns1.noiz.co.za` and `ns2.noiz.co.za`.
- **It still redirects after you deleted it**: your browser has cached a 301. Test in a private or incognito window, or clear the cache, and it will behave correctly.
- **Only the www or only the non-www version redirects**: revisit the **www. redirection** setting and choose **Redirect with or without www.** so both forms are covered.
- **You get a redirect loop**: the destination points back to the address being redirected. Check that **Redirects to** is a different address from the one in the top row, and that a Wild Card Redirect is not folding the destination back onto itself.
Need a redirect that the Redirects tool cannot express, such as forwarding based on the requested path or query string? Open a ticket from your Noiz client area and the support team will help you set it up.
# How to Redirect a Subdomain to an External URL
Source: https://docs.noiz.ie/cpanel/how-to-redirect-a-subdomain-to-an-external-url/
This guide shows you how to point a subdomain (for example `shop.yourdomain.com`, where `yourdomain.com` is an example you replace with your own domain) at an external web address using cPanel. Once the redirect is in place, anyone who opens the subdomain is forwarded automatically to the site or page you specify. This is useful when you want a short, memorable subdomain to send visitors to a page hosted somewhere else, such as a booking system, a shop on another platform, a social profile, or a landing page.
In current cPanel, this kind of redirect is created with the **Redirects** tool in the **Domains** section. The subdomain itself must already exist before you can redirect it, so if you have not created it yet, do that first.
**Last reviewed:** 27 July 2026, against cPanel **version 134** (the current STABLE and LTS tier). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Redirects interface](https://docs.cpanel.net/cpanel/domains/redirects/)
- [cPanel Domains interface (creating domains and subdomains)](https://docs.cpanel.net/cpanel/domains/domains/)
## Prerequisites
- A hosting account with cPanel access.
- The subdomain you want to redirect must already exist. If it does not, create it first in **Domains** ยป **Domains** using **Create A New Domain**, then return here.
- The full external web address you want to forward visitors to, including the `https://` at the start.
You will find the subdomain tools grouped in the **Domains** section of the cPanel home screen.

## Redirect the Subdomain
1. Log in to your cPanel account.
2. In the **Domains** section, click **Redirects**.
3. Under **Type**, choose the kind of redirect you want:
- **Permanent (301)** tells browsers and search engines that the subdomain has moved for good. Use this for a lasting redirect.
- **Temporary (302)** signals that the move is short term. It is handy while you are testing, because browsers do not cache it as aggressively.
4. Open the domain dropdown and select the subdomain you want to redirect (for example `shop.yourdomain.com`).
5. Leave the path box (shown as `/`) empty to redirect the whole subdomain. Only enter a path here if you want to forward one specific folder or file.
6. In the **Redirects to** field, type the full destination address, including the protocol, for example `https://www.example.com/landing`.

7. Choose how the **www.** version should behave. For most external redirects, **Redirect with or without www.** is the safest choice, so both `shop.yourdomain.com` and `www.shop.yourdomain.com` are forwarded.
8. Leave **Wild Card Redirect** unticked unless you specifically want every path under the subdomain mapped to a matching path on the destination.
9. Click **Add**.

cPanel confirms the new redirect and lists it near the bottom of the **Redirects** page. Open the subdomain in a fresh browser tab to check that it now forwards to the correct address.
## Changing or Removing a Redirect
cPanel does not let you edit a redirect once it exists. To change where a subdomain points, delete the current entry in the redirect list at the bottom of the **Redirects** page, then create a new redirect with the correct destination. To stop redirecting altogether, simply delete the entry.
## Troubleshooting
**The redirect does not seem to work**: browsers cache permanent (301) redirects aggressively. Test in a private or incognito window, or clear your browser cache. While you are still deciding on the final destination, use a temporary (302) redirect so changes take effect sooner.
**The subdomain is not in the dropdown**: it has not been created yet. Create it in **Domains** ยป **Domains** first, then come back to the **Redirects** tool.
**You forgot the protocol**: the destination must include `http://` or `https://`. Without it, the redirect is treated as a path on your own site rather than an external address.
If a redirect will not behave as expected, or you would like Noiz to set it up for you, contact the Noiz support team through the client area and the team will be glad to help.
# How to Redirect an Add-on Domain in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-redirect-an-add-on-domain-in-cpanel/
An add-on domain lets you host a second, fully separate website inside the same cPanel account. Sometimes you do not want that second site to serve its own content at all, but instead to send every visitor straight to another address, for example an existing website, a landing page or a social profile. This guide shows you how to point an add-on domain at another domain or URL using a redirect in cPanel.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable release, Jupiter theme). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: Redirects](https://docs.cpanel.net/cpanel/domains/redirects/)
- [cPanel Documentation: Domains](https://docs.cpanel.net/cpanel/domains/domains/)
## Prerequisites
- Access to your Noiz cPanel account.
- The add-on domain already exists in your account. If it does not, add it first from the **Domains** interface using **Create A New Domain**.
- The destination address you want visitors to land on, for example `https://www.yourotherdomain.com` (replace this example with your own address).
Current versions of cPanel have merged the old **Addon Domains**, **Subdomains** and **Aliases** pages into a single **Domains** interface, so you no longer manage add-on domains on their own page. Redirects for any domain on your account, including add-on domains, are handled by the dedicated **Redirects** tool. The steps below use that tool, which is the reliable way to redirect an add-on domain to another address.
## Redirect an Add-on Domain
1. Log in to your cPanel account.
2. Find the **Domains** section, which groups all of your domain tools including your add-on domains and redirects.
3. Click **Redirects**.
4. Under **Type**, choose **Permanent (301)** or **Temporary (302)**. See the note below if you are unsure which to pick.
5. From the domain drop-down list (shown as `https://(www.)?`), select the add-on domain you want to redirect.
6. In the **redirects to** box, enter the full destination address you want visitors sent to, including the `https://` prefix, for example `https://www.yourotherdomain.com`.
7. Choose a **www. redirection** option. **Redirect with or without www.** is the safest default, as it catches visitors who type the address either way.
8. Optionally tick **Wild Card Redirect** to also forward requests for any page or folder under the domain (so `yourdomain.com/page` follows the redirect too), rather than only the home page.
9. Click **Add**.
The redirect is now live and appears in the **Current Redirects** list at the bottom of the same page. To remove or replace it later, click **Delete** next to the entry in that list.
## Permanent (301) or Temporary (302): Which to Choose
The type you choose tells browsers and search engines how to treat the redirect, so it is worth getting right.
- **Permanent (301)**: use this when the move is for good. Search engines transfer the old address's ranking to the destination, and browsers may cache the redirect, so future visits go straight to the new address without checking your server again. This is the usual choice when you are consolidating an old add-on domain onto your main site.
- **Temporary (302)**: use this for a short-term redirect you intend to reverse, such as sending visitors to a holding page while you build the real site. Search engines keep the original address indexed, and browsers do not cache it as aggressively.
## Using an Older cPanel Account
If your account still shows the classic **Addon Domains** icon rather than the merged **Domains** interface, you can redirect from there instead. The **Redirects** method above works on every version, so use these steps only if you prefer the older page.
1. Log in to your cPanel account.
2. In the **Domains** section, click **Addon Domains**. 
3. Under **Modify Addon Domain**, locate the add-on domain and click **Manage Redirection**. 
4. Enter the address you want the add-on domain redirected to in the text box. 
5. Click **Save**.
## Troubleshooting
**The add-on domain does not appear in the drop-down list**: it must be added to your account before you can redirect it. Open the **Domains** interface, add it with **Create A New Domain**, then return to **Redirects**.
**The redirect does not seem to work when you test it**: a permanent (301) redirect is often cached by your browser. Test in a private or incognito window, or clear your browser cache, before assuming the redirect is wrong. Also confirm the add-on domain's DNS is pointed at your Noiz hosting, as a redirect can only fire once requests reach this server.
**You see a certificate warning at the add-on domain**: the redirect can only run after the browser makes a secure connection to the add-on domain, so the domain still needs a valid SSL certificate covering it. On Noiz hosting, cPanel issues free AutoSSL certificates automatically once the domain resolves to the server; allow a little time after adding the domain for the certificate to be issued.
**You want to undo a redirect**: scroll to **Current Redirects** on the **Redirects** page and click **Delete** next to the relevant entry. The add-on domain then serves its own content again.
## Need a Hand?
If you are on a managed Noiz hosting plan and would like the Noiz team to set up or check a redirect for you, open a support ticket from your client area and include the add-on domain and the destination address you want it pointed to.
# How to Remove Parked Domains and Aliases in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-remove-parked-domains-and-aliases-in-cpanel/
This guide shows you how to remove a domain **alias** from a cPanel account. An alias (historically called a **parked domain**) is a second domain name that shows the same website as your main domain. Removing it simply stops that extra name from pointing at your account; it does not cancel or delete the domain's registration, so you keep ownership of the name.
**Last reviewed:** 27 July 2026, against current cPanel & WHM (Jupiter theme). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Domains interface](https://docs.cpanel.net/cpanel/domains/domains/): create, manage and remove every domain type from one place.
## Prerequisites
- Your cPanel sign-in details for the account that holds the alias. You can reach cPanel from the single sign-on link in your Noiz client area, or directly at your server hostname on port `2083`.
- The exact alias name you want to remove, so you do not remove the wrong domain.
**Note:** removal takes effect immediately. Any website content, redirect or email routing that relied on that extra name will stop working once it is gone, so confirm nothing important is still using it first.
## Remove an Alias in cPanel
Recent cPanel versions merged the old **Aliases**, **Addon Domains** and **Subdomains** tools into a single **Domains** interface. On a current account, use this method.
1. Log in to your cPanel account.
2. In the **Domains** section, click **Domains**.
3. Find the alias you want to remove in the list of domains.
4. In the **Actions** column for that domain, click **Manage**.
5. Scroll to the bottom of the management page and click **Remove Domain**.
6. Confirm the removal when cPanel prompts you.
cPanel displays a success message once the alias has been removed.
## Older cPanel Versions: the Aliases Interface
If your account still shows a separate **Aliases** tool rather than the unified **Domains** page, use these steps instead. The outcome is identical.
1. Log in to your cPanel account.
2. In the **Domains** section, click **Aliases**. 
3. Under **Remove Aliases**, find the domain name and click **Remove**. 
4. To confirm, click **Remove Alias** again.
You will see a message confirming that the alias has been removed.
## Good to Know
- **Your domain registration is untouched.** Removing an alias only detaches the name from this cPanel account. You still own the domain and can point it elsewhere or add it back later.
- **DNS may take time to catch up.** If the old address still loads shortly after removal, allow for DNS caching and propagation before assuming something is wrong.
- **Email and redirects tied to the alias stop.** Because an alias shares your main domain's configuration, any mail delivery or redirect that depended on the alias name ends when you remove it.
If you are unsure whether a domain is set up as an alias, an addon domain or a subdomain, or you would prefer Noiz to make the change for you, open a support ticket from your Noiz client area and the team will handle it.
# How to Remove a Domain Redirect in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-remove-a-domain-redirect-in-cpanel/
This guide shows you how to remove an existing domain redirect from your Noiz hosting account using the **Redirects** tool in cPanel. Use it when a domain or subdomain is still forwarding visitors to an address you no longer want, and you need traffic to load the site's own content again.
A redirect created in cPanel is a rule that tells the web server to send anyone who requests one URL straight on to another. Removing the rule stops that forwarding. It does **not** delete the domain, its files, or its email, so it is safe to remove a redirect you no longer need.
**Last reviewed:** 27 July 2026, against cPanel & WHM (Jupiter interface, current stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel & WHM Documentation: Redirects](https://docs.cpanel.net/cpanel/domains/redirects/)
## Prerequisites
- Access to your cPanel account (your Noiz welcome email contains the login details, or reach cPanel from the **Services** area of the [Noiz client area](https://www.noiz.co.za/clientarea.php)).
- An existing redirect on the domain or subdomain you want to restore. If you created the forwarding rule yourself, this is the reverse of [How to Redirect Your Website to Any Page or External Domain](/cpanel/how-to-redirect-your-website-to-any-page-or-external-domain/).
## Remove the Redirect
### 1. Open the Redirects tool
Log in to your cPanel account. In the **Domains** section, click **Redirects**.

### 2. Find the redirect and remove it
Scroll to the bottom of the page. Under **Current Redirects**, find the domain or subdomain you want to restore and click **Remove** on that row.

### 3. Confirm the removal
cPanel asks you to confirm. Click **Remove Redirect** once more to finish.

The redirect is now gone from the **Current Redirects** list, and requests to the domain will load its own content instead of forwarding elsewhere.
## Troubleshooting
**Symptom:** the site still redirects after removal. A permanent (301) redirect is cached aggressively by web browsers, so your browser may keep forwarding you even though the rule is gone. Test the address in a private or incognito window, clear your browser cache, or try a different device to confirm the change. Search engines and other caches can also hold on to a 301 for a while.
**Symptom:** the redirect is not listed under Current Redirects. Only redirects created with the cPanel **Redirects** tool appear here. If the forwarding was added another way, for example a rule written directly into the site's `.htaccess` file or a redirect set on a subdomain, remove it there instead. See [How to Redirect a Page to Another Page or Website Using htaccess](/server-administration/how-to-redirect-a-page-to-another-page-or-website-using-htaccess/) for editing `.htaccess` rules.
**Symptom:** a whole domain still points to the wrong place. That is usually DNS, not a cPanel redirect. Check the domain's DNS records and nameservers. Noiz client hosting uses `ns1.noiz.co.za` and `ns2.noiz.co.za`.
## Need a Hand?
If a redirect will not clear or you are unsure which forwarding rule is in play, the Noiz support team can check it for you. Open a ticket from the [Noiz client area](https://www.noiz.co.za/clientarea.php) and mention the affected domain.
# How to Remove a Subdomain in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-remove-a-subdomain-in-cpanel/
A subdomain is a separate section of your main domain that behaves like its own site, for example `blog.yourdomain.com` or `shop.yourdomain.com`. When you no longer need one, you can remove it from cPanel in a few clicks. This guide shows you how to remove a subdomain on your Noiz cPanel hosting, and explains the one thing cPanel does not do for you: delete the files that were behind it.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable, version 110+ with the Jupiter theme). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Domains interface](https://docs.cpanel.net/cpanel/domains/domains/), the current recommended place to manage subdomains.
- [cPanel Subdomains interface](https://docs.cpanel.net/cpanel/domains/subdomains/), the classic interface shown in the screenshots below.
## Prerequisites
- Access to your cPanel account. If you are not sure how to sign in, see [How to Create a Subdomain in cPanel](/cpanel/how-to-create-a-subdomain-in-cpanel/) for the login steps.
- The name of the subdomain you want to remove.
## Two ways to reach the subdomain list
Current cPanel versions (Jupiter theme) manage subdomains inside the unified **Domains** interface, while older or customised setups still show a dedicated **Subdomains** icon. Both remove the subdomain the same way. Use whichever your account displays.
### Option A: the Domains interface (current cPanel)
1. Log in to your cPanel account.
2. In the **Domains** section, click **Domains**.
3. Find the subdomain in the list, then click **Manage** beside it and choose **Remove Domain** (in some versions the action is a **Remove** link directly in the row).
4. Confirm the removal when prompted.
### Option B: the Subdomains interface (classic)
1. Log in to your cPanel account.
2. In the **Domains** section, click **Subdomains**. 
3. Under the **Modify a Subdomain** list you will see every subdomain on the account.
4. Click **Remove** in the **Actions** column for the subdomain you want to delete. 
5. To confirm, click **Delete Subdomain**. The subdomain is then removed permanently. 
## Important: your files are not deleted
Removing a subdomain in cPanel deletes the subdomain entry and its associated DNS record, so the address stops resolving. It does **not** delete the files in the subdomain's document root folder (typically a folder such as `public_html/blog`). Those files stay on the server and continue to count towards your disk usage.
If you want the content gone as well, open **File Manager** from the **Files** section of cPanel, browse to the subdomain's old document root, and delete the folder yourself. Do this only if you are certain you no longer need the content, as it cannot be undone.
## Troubleshooting
**Symptom**: The subdomain is not in the list. It may have been created as an **addon domain** or a separate **domain** rather than a subdomain. Check the **Domains** interface (Option A above), where all domain types appear together.
**Symptom**: cPanel will not let you remove it, or an error mentions an addon domain. A subdomain that was generated automatically for an addon domain cannot be removed on its own. Remove the addon domain instead, which also removes its subdomain.
**Symptom**: The address still loads after removal. DNS changes can take time to clear from your device and from resolvers on the internet. Clear your browser cache or try a private window, and allow time for the change to propagate.
## Need a hand?
If you are on a managed Noiz plan, or you are unsure which subdomain is safe to remove, open a ticket from your [Noiz client area](https://www.noiz.co.za/clientarea.php) and the support team will handle the removal for you.
# How to Remove an Add-on Domain in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-remove-an-add-on-domain-in-cpanel/
An add-on domain lets you host a completely separate website, with its own domain name, inside a single cPanel account. This guide shows you how to remove an add-on domain you no longer need, so it stops resolving to your hosting and frees the name up for use elsewhere.
**Last reviewed:** 27 July 2026, against cPanel & WHM (Jupiter theme, version 110 and later). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Domains interface](https://docs.cpanel.net/cpanel/domains/domains/) (the current, merged tool)
- [cPanel Add-on Domains](https://docs.cpanel.net/cpanel/domains/addon-domains/) (legacy tool, for older versions)
## Prerequisites
- Access to the Noiz cPanel account that holds the add-on domain.
- The add-on domain must already exist in that account. If it lives in a different account, log in to that one instead.
## Remove an Add-on Domain in cPanel
Current cPanel merges add-on domains, subdomains, and aliases into a single **Domains** interface, so add-on domains are now removed from there rather than from a separate tool.
1. Log in to your Noiz cPanel account.
2. In the **Domains** section, click **Domains**.
3. Find the domain you want to remove in the list, then click **Manage** in its **Actions** column.
4. Scroll to the bottom of the manage page and click **Remove Domain**.
5. In the confirmation window, click **Remove Domain** again to confirm.
cPanel confirms the domain has been removed, and it no longer appears in the **Domains** list. Note that you cannot remove the account's main (primary) domain from here.
## On Older cPanel Versions (the Add-on Domains Tool)
Older cPanel releases kept add-on domains in a separate **Add-on Domains** tool rather than the unified Domains interface. If your account still shows that tool, use these steps instead.
1. In the **Domains** section of the cPanel home screen, click **Addon Domains**.

2. Under **Modify Addon Domain**, find the domain you want to remove and click **Remove**.

3. Click **Remove** again in the confirmation prompt. A message confirms that the add-on domain has been removed.
## What Removing a Domain Does and Does Not Delete
Removing an add-on domain is not a full clean-up on its own. Keep the following in mind:
- It removes the domain from cPanel and deletes its DNS zone, so the name stops resolving to your hosting.
- It does **not** delete the website files in the document root. If you no longer need them, delete them separately in **File Manager**.
- Email accounts, forwarders, and autoresponders on the domain are **not** removed automatically. Delete those from the **Email Accounts** and **Forwarders** tools if required.
- Databases and database users linked to the site are **not** removed.
- If you are moving the domain to another account or server, remove it here first. This avoids the common conflict where the destination refuses to add a domain that already exists elsewhere on the server.
## Troubleshooting
**The domain is not listed in Domains**: it may sit in a different cPanel account, or it is the account's main domain, which cannot be removed from this interface.
**cPanel says the domain already exists when you try to re-add it elsewhere**: a leftover DNS zone or entry can remain on the server. Open a ticket and the Noiz support team can clear it for you.
**The website still loads after removal**: this is almost always browser or DNS caching. Clear your browser cache and allow time for DNS changes to take effect.
## Need a Hand?
If you are not sure which account holds the domain, or you need a leftover DNS zone cleared after removal, the Noiz support team can help. Open a ticket from your [Noiz client area](https://www.noiz.co.za).
# How to Rename a MySQL Database in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-rename-a-mysql-database-in-cpanel/
This guide shows you how to rename an existing MySQL database from within cPanel on your Noiz hosting account. It is written for anyone who needs to tidy up an application migration, correct a mistyped database name, or align a database with a new project. cPanel calls this action **Rename** in the **MySQL Databases** tool.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable release). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel ยป MySQL Databases](https://docs.cpanel.net/cpanel/databases/mysql-databases/) (create, rename and manage databases)
## Before You Begin
- You need access to the cPanel account that owns the database.
- Note which application uses the database (for example WordPress, Joomla or a custom app). You will need to update that application after the rename.
- Take a fresh backup of the database first. Renaming moves every table into a newly named database, and a backup gives you a safe fallback if anything goes wrong.
- cPanel automatically prepends your account username and an underscore to every database name (for example `youracct_shopdb`). You only type the part after the underscore; the prefix stays the same when you rename.
## Renaming Your Database
1. Log in to your cPanel account.
2. In the **Databases** section, click **MySQL Databases**. 
3. Scroll to **Current Databases**, where you will see a list of every database on the account. Locate the database you want to change and click **Rename** in its row. 
4. Type the new database name and click **Proceed**. cPanel keeps the same username prefix and moves the tables and their user grants across to the new name. 
## After Renaming: Update Your Application
The rename does not touch your website code. Any application that connected to the old database name will fail to load until you point it at the new one. Open your application's database configuration and replace the old name with the new one:
- **WordPress:** `wp-config.php`, the `DB_NAME` line.
- **Joomla:** `configuration.php`, the `$db` value.
- **Laravel and similar frameworks:** the `DB_DATABASE` entry in `.env`.
cPanel recreates the existing database users and their privileges against the new database, so you should not need to add users again. It is still worth loading your site once the change is saved to confirm it connects.
## Troubleshooting
**The Rename button does nothing or the operation times out:** very large databases can exceed the time limit for an in-browser rename. Restore from your backup, then ask Noiz support to complete the rename at server level.
**Your site shows a database connection error afterwards:** the application is still using the old name. Update the configuration file listed above with the new database name, including the account prefix.
**You cannot see the Rename option:** confirm you are logged in to the cPanel account that owns the database, and that you are looking under **Current Databases** rather than the **Create New Database** box at the top of the page.
## Need a Hand?
If the database is large, powers a live site, or you would rather not risk downtime, open a ticket and the Noiz support team will handle the rename and verify the application afterwards.
# How to Reset Your cPanel Account Password
Source: https://docs.noiz.ie/cpanel/how-to-reset-your-cpanel-account-password/
Your cPanel password is the master password for your hosting account's control panel. If you can still log in to cPanel, you can change it yourself in a few clicks using the **Password & Security** tool. This guide shows you how, and explains what the change does and does not affect.
**Last reviewed:** 27 July 2026, against cPanel & WHM's **Jupiter** interface (latest stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel ยป Preferences ยป Password & Security](https://docs.cpanel.net/cpanel/preferences/password-and-security/)
## Prerequisites
- You can currently log in to your cPanel account.
- You know your current cPanel password. If you have lost it and cannot log in, see [Forgot your password?](#forgot) below.
## Change Your cPanel Password
1. Log in to your cPanel account.
2. In the **Preferences** section, click **Password & Security**. 
3. Enter your **Old Password**.
4. Enter your **New Password**, or click the password generator to create a strong random password. cPanel shows a strength meter and will not accept a password it rates as too weak.
5. Click **Change your password now**. 
When cPanel displays a success message, your password has been changed. You can log in with the new password straight away. If you used the generator, store the password in a password manager before you leave the page.
## What Changing This Password Does and Does Not Affect
The cPanel password protects the control panel itself. Changing it does **not** change the passwords for:
- **Email accounts** you have created (managed under **Email Accounts**).
- **FTP accounts** (managed under **FTP Accounts**).
- **Databases and database users** (managed under **MySQL Databases**).
Those keep their own passwords and are unaffected. However, if an FTP client, backup job, or deployment tool signs in as the main account, update its saved password after the change or it will start failing to connect.
## Forgot Your Password?
If you have forgotten your cPanel password and cannot log in, you cannot reset it from inside cPanel. Open a support ticket from your Noiz client area and the Noiz support team will reset it for you. For security, the reset is confirmed against the account holder on record.
# How to Reset the PHP Version to the Default in cPanel
Source: https://docs.noiz.ie/cpanel/how-to-reset-the-php-version-to-the-default-in-cpanel/
If a domain on your cPanel account has been pinned to a specific PHP version and you want it to follow the server default again, you do not pick a version number. You set the domain back to **inherit**. This guide explains what "default" means inside cPanel, how to reset one domain or several at once, and what a reset deliberately leaves untouched.
If instead you want to move a domain onto a particular PHP version, see [How to Change the PHP Version on Your Domain in cPanel](/cpanel/how-to-change-the-php-version-on-your-domain-in-cpanel/). This article covers the opposite move: giving up the per-domain override and going back to the baseline.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM stable release and its **MultiPHP Manager** interface. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: MultiPHP Manager for cPanel](https://docs.cpanel.net/cpanel/software/multiphp-manager-for-cpanel/)
- [cPanel Documentation: MultiPHP INI Editor for cPanel](https://docs.cpanel.net/cpanel/software/multiphp-ini-editor-for-cpanel/)
- [cPanel Documentation: MultiPHP Manager for WHM (resellers and server administrators)](https://docs.cpanel.net/whm/software/multiphp-manager-for-whm/)
- [PHP: Supported Versions and End-of-Life Dates](https://www.php.net/supported-versions.php)
## Prerequisites
- Access to the cPanel account that owns the domain.
- The **MultiPHP Manager** icon present in the **Software** section. If it is missing, the feature has been restricted at server level and Noiz support can make the change for you.
- A recent backup of the site, or at least the confidence that you can restore it, in case the default version is not compatible with the application.
## What "Default" Actually Means in cPanel
cPanel does not store a per-domain instruction that says "use the default". It stores the special value `inherit`. A domain set to `inherit` takes whichever PHP version the server administrator has set as the system default, and it keeps following that default forever, including after the server is later moved onto a newer PHP release.
A domain pinned to an explicit version such as `ea-php74` behaves the other way round. It stays on that exact version and ignores every future default change, which is exactly how sites end up stranded on a PHP release that no longer receives security fixes. That is the single best reason to reset a domain to `inherit` once the reason for the override has gone away.
Typical reasons to reset:
- You pinned an older version to keep a legacy plugin or theme working, and the application has since been updated.
- A migration from another host brought per-domain PHP overrides across with it, and they no longer match anything.
- A site broke after an experiment with a newer version and you want the known baseline back.
- You want the domain to track the supported version automatically rather than being maintained by hand.
## Reset a Single Domain to the Default PHP Version
**1.** Log in to your cPanel account.
**2.** In the **Software** section, click on **MultiPHP Manager**.

**3.** Scroll down to the domain list at the bottom of the page. Tick the checkbox to the left of the domain you want to reset. Open the **PHP Version** drop-down menu on the right, select **inherit**, then click **Apply**.

**4.** A confirmation message appears within a few seconds and the **PHP Version** column for that domain changes to show `inherit`, usually alongside the version it currently resolves to. The change is live immediately; there is nothing to restart.
## Reset Several Domains at Once
The domain list is a multi-select. Tick the checkbox beside each domain you want to reset, or use the checkbox in the table header to select every domain on the account, then choose **inherit** once and click **Apply**. cPanel applies the same setting to every selected entry in a single pass.
Be deliberate about the select-all option. The list includes addon domains, parked domains and subdomains, so a bulk reset can move a staging subdomain or a legacy application onto the default version at the same time as the site you actually meant to change. If any of those still need an explicit version, reset the rest first and leave the exceptions pinned.
## Confirm the Domain Is Back on the Default
The **PHP Version** column in MultiPHP Manager is the authoritative answer and is normally all you need. If you want to see the version the site itself reports, upload a single-line file containing `
AddHandler application/x-httpd-ea-php84 .php .php8 .phtml
# php -- END cPanel-generated handler, do not edit
```
Apache reads `.htaccess` files from the top of the document root downwards, and directives in a subdirectory override the ones above it. That is the whole trick: drop a block naming a different `ea-phpXX` package into a subdirectory, and every PHP file at or below that point runs on that version instead. Nothing else about the account changes.
**The PHP-FPM caveat, read this first.** If PHP-FPM is enabled for the domain, Apache hands `.php` requests straight to a FastCGI pool that is configured outside `.htaccess`, and the `AddHandler` lines above are simply ignored. You can add them, save the file, and get no error and no change. Per-directory PHP versions via `.htaccess` only work when PHP-FPM is switched off for that domain. Check the **PHP-FPM** column in MultiPHP Manager before you spend time on this. If you need PHP-FPM and split versions at the same time, the supported answer is a separate domain, subdomain or hosting account for the odd-version application, and Noiz support can advise on the cleanest split.
## Step 1: Open MultiPHP Manager
1. Log in to your cPanel account.
2. In the **Software** section, click **MultiPHP Manager**.

## Step 2: Generate the Handler Code
The reliable way to get a correct handler block is to let cPanel write one for you, then copy it. This avoids typos in the package name, which is the usual cause of PHP files downloading instead of running.
1. Scroll to the **Set PHP Version per Domain** table at the bottom of the page.
2. Tick the domain on the left.
3. Choose the version you want the *subdirectory* to use from the **PHP Version** drop-down on the right, then click **Apply**.

This temporarily sets the whole domain to that version. That is expected, and you will put it back in step 5.
## Step 3: Copy the Generated Block
1. Open **File Manager** and edit `/public_html/.htaccess`. If you cannot see the file, enable **Show Hidden Files (dotfiles)** in File Manager's settings.
2. Find the block between the `# php -- BEGIN cPanel-generated handler` and `# php -- END cPanel-generated handler` markers, and copy it in full, including both comment lines.

## Step 4: Create the Directory Override
Suppose you want `/public_html/forums/` to run the version you just generated.
1. In File Manager, navigate into `public_html/forums`.
2. If a `.htaccess` file already exists there, edit it. If not, create a new file named exactly `.htaccess`, including the leading dot.
3. Paste the copied block at the **top** of the file, above any rewrite rules, and save.
Repeat for any other directory that needs the same version. The same block can be pasted into as many directories as you like.
## Step 5: Put the Domain Back
Return to **MultiPHP Manager** and set the domain back to the version the rest of the site should use. The block you pasted into `/forums/` stays where it is and keeps overriding the parent setting, so the two versions now coexist.
To pin a third directory to yet another version, repeat steps 2 to 5 with that version selected.
## Step 6: Verify
Do not trust the interface, check the running version. Create a file called `version-check.php` in the directory you changed, containing:
```
/dev/null 2>&1` to the end of its command. cPanel then has nothing to email.
- To be told only when a job fails, discard normal output but keep errors: append `>/dev/null` (leaving errors to be emailed).
Edit the command from the same **Cron Jobs** page: find the job in the **Current Cron Jobs** list and use its **Edit** action.
## Troubleshooting
**No cron emails arriving**: confirm the address is spelled correctly and check the mailbox's spam or junk folder. Remember that a job only emails you when it prints something, so a silent, successful job is normal and sends nothing.
**Emails go to the wrong place**: the **Cron Email** field is account-wide, so updating it here changes the destination for all jobs at once. There is no per-job address in cPanel; route notifications by pointing this field at a monitored, shared, or forwarding mailbox.
If you are on a Noiz managed plan and would like Noiz to review or adjust your scheduled tasks and their notifications, contact Noiz support and the team will assist.
# How to Upload Files via the cPanel File Manager
Source: https://docs.noiz.ie/cpanel/how-to-upload-files-via-the-cpanel-file-manager/
The cPanel File Manager lets you upload files to your hosting account straight from your web browser, with no separate FTP program to install or configure. It is the quickest way to add a page, a logo, a configuration file, or a whole website archive to your account. This guide shows you how to do it on your Noiz cPanel hosting.
**Last reviewed:** 27 July 2026, against cPanel & WHM with the **Jupiter** interface (latest stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel File Manager](https://docs.cpanel.net/cpanel/files/file-manager/) (feature overview)
- [Upload files in File Manager](https://docs.cpanel.net/cpanel/files/file-manager/#upload)
## Prerequisites
- An active Noiz cPanel hosting account and your cPanel login details.
- The file or files you want to upload, ready on your computer.
- An idea of where the files belong. For your main website this is the `public_html` directory; subdomains and addon domains have their own document roots.
## Upload a File in cPanel File Manager
**1.** Log in to your cPanel account.
**2.** In the **Files** section of the cPanel home screen, click **File Manager**.

**3.** In File Manager, navigate to the directory you want to upload into. To publish files to your main website, open the `public_html` directory. In the directory list on the left, double click **public\_html**.

**4.** With the destination directory open, click **Upload** in the toolbar at the top. This opens the upload page in a new browser tab.

**5.** Click **Select File** and choose the file you want to upload from your computer, then click **Open**. The upload begins straight away and a progress bar shows how far it has got. You can also drag and drop files from your computer directly onto the upload area. When every file reads 100%, the upload is complete and you can close the tab and return to File Manager.

## Tips and Troubleshooting
- **Overwriting existing files:** if a file of the same name already exists in the folder, tick **Overwrite existing files** on the upload page before you upload. Without it, cPanel adds a number to the new file name instead of replacing the old one.
- **Uploading a whole site at once:** the File Manager uploads individual files, not folders. To move a large site or a folder tree, compress it into a single `.zip` on your computer, upload the archive, then select it in File Manager and click **Extract** to unpack it in place.
- **Maximum upload size:** browser uploads have a size limit, shown as **Maximum file size allowed for upload** on the upload page. For very large files that exceed it, use SFTP or, on a managed plan, ask Noiz support to place the file for you.
- **Nothing appears on your website:** confirm you uploaded into the correct document root. Files must sit inside `public_html` (or the relevant subdomain or addon domain folder) to be served, and your home page usually needs to be named `index.html` or `index.php`.
- **Hidden files such as `.htaccess`:** if you cannot see a dotfile after uploading, click **Settings** in the top right of File Manager and enable **Show Hidden Files (dotfiles)**.
If an upload keeps failing or a file will not appear where you expect it, Noiz support can check the account and place the files for you. Open a ticket from your [Noiz client area](https://www.noiz.co.za/clientarea.php) and include the file name and the folder it should live in.
# How to Access and Log In to WHM (Web Host Manager)
Source: https://docs.noiz.ie/whm/how-to-access-and-log-in-to-whm-web-host-manager/
**WHM** (Web Host Manager, sometimes written WebHost Manager) is the administrative control panel that sits above cPanel. Where a cPanel account manages one hosting account, WHM manages the accounts themselves: creating them, setting their packages and limits, suspending them, and reaching the server-level settings that individual cPanel users never see. If your Noiz plan is a reseller, VPS or dedicated server package built on cPanel, WHM is where you spend your administrative time. This guide shows you exactly which address to use, how to log in, and what to do when the login page will not load or will not accept you.
WHM is not part of a standard shared hosting account. If your Noiz plan gives you a single cPanel login and no reseller privileges, there is nothing at port 2087 for you, and the guides in the cPanel section of this knowledgebase are the ones you want. Some Noiz plans run a different control panel entirely, in which case WHM does not apply at all.
**Last reviewed:** 27 July 2026, against the current stable cPanel & WHM release. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [How to Log in to Your Server or Account](https://docs.cpanel.net/knowledge-base/accounts/how-to-log-in-to-your-server-or-account/): the vendor reference for every login route, including external authentication and the single-use `whmlogin` session URL.
- [How to Configure Your Firewall for cPanel Services](https://docs.cpanel.net/knowledge-base/general-systems-administration/how-to-configure-your-firewall-for-cpanel-services/): the authoritative port list for WHM, cPanel, Webmail and the rest.
- [WHM Documentation](https://docs.cpanel.net/whm/): the full interface reference for every screen you reach after logging in.
- [Two-Factor Authentication for WHM](https://docs.cpanel.net/whm/security-center/two-factor-authentication-for-whm/): how the six-digit code step is enabled, enforced and recovered.
- [cPHulk Brute Force Protection](https://docs.cpanel.net/whm/security-center/cphulk-brute-force-protection/): the mechanism that locks out an IP address after repeated failed logins.
## Prerequisites
- A Noiz plan that includes WHM access: reseller, VPS or dedicated server on cPanel & WHM.
- Your welcome email, which carries the server hostname, the server IP address, and your WHM username and password. It is sent once the order is provisioned.
- An outbound network path to port `2087`. Most home and office connections have this. Some corporate, school and public networks do not, and the workaround is covered below.
- A current browser. WHM is a web application and older browsers fail in ways that look like login problems.
## Where Your Login Details Come From
After the order is placed and payment clears, Noiz provisions the account and sends a welcome email containing the details you need. Keep it. The three items that matter are:
- **Server hostname**: something in the form `server1.yourdomain.com`. This is the preferred address to use.
- **Server IP address**: a numeric address such as `198.51.100.25`. Useful before DNS is working, and as a fallback.
- **WHM username and password**: for a reseller account the username is your account name. On a VPS or dedicated server it is normally `root`.
If you cannot find the welcome email, do not guess. Log in to the Noiz client area and open the service, or raise a ticket. Repeated guessing at a password will get your IP address blocked by the server's brute force protection, which turns a five-minute problem into a longer one.
## The WHM Address
WHM does not live at a normal web address. It listens on its own service port, so the port number is part of the URL and cannot be left out.
- **`https://server1.yourdomain.com:2087`**: the correct address, encrypted. Use this one.
- `http://server1.yourdomain.com:2086`: the legacy unencrypted port. It exists for historical reasons and is normally configured to redirect to port 2087. Never enter credentials on a page that has not redirected to `https`.
- `https://198.51.100.25:2087`: the same interface reached by IP address. This works before DNS points anywhere, but expect a certificate warning (see below).
Replace `server1.yourdomain.com` and `198.51.100.25` with the real hostname and IP from your welcome email. They are examples, not live addresses.
For completeness, the related cPanel ports on the same server are `2083` for cPanel accounts and `2096` for Webmail, both over HTTPS. Their unencrypted counterparts are `2082` and `2095`.
### Hostname or IP Address: Which to Use
Use the hostname whenever it resolves. The server holds a valid SSL certificate issued for its own hostname, so a hostname URL loads cleanly with no warning. An SSL certificate can only ever be issued for a name, never for a bare IP address, so an IP URL will always produce a browser warning along the lines of *"Your connection is not private"* or *"There is a problem with this website's security certificate"*. The connection is still encrypted, but the browser cannot confirm what it is encrypted to.
That is why the IP address route is a fallback rather than a habit. Use it during initial setup, before the hostname's DNS has propagated, and switch to the hostname as soon as it resolves. If you are ever asked to click through a certificate warning on an address you did not expect, stop and check with Noiz support first.
Once your own domain resolves to the server, `https://yourdomain.com:2087` also reaches WHM. It will warn about the certificate for the same reason unless a certificate covering that name has been installed for the service.
## How to Log In to WHM
1. Open your WHM login URL in a browser, including the `:2087` port. 
2. Enter your WHM **Username** and **Password**, then click **Log in**. 
3. If the details are correct, WHM opens on its **Home** screen and you are logged in. 
A few things worth knowing about that first screen. WHM's navigation is a long list of grouped features down the left-hand side, and the fastest way through it is the search box at the top of that list rather than scrolling. Typing part of a feature name filters the whole menu instantly, which is how experienced administrators navigate WHM. The layout has shifted between releases, so a screenshot that does not match your screen pixel for pixel is normal; the feature names are stable and the search box finds them regardless of where they have been moved to.
On a brand new server the first root login also presents the initial setup steps, including accepting the licence terms and setting contact details and nameservers. Work through it rather than skipping it, because several later screens assume it has been completed. A reseller account sees none of this, only the subset of features the server owner has granted.
## When Port 2087 Is Blocked
This is the single most common reason a WHM login page fails to load, and it is easy to misdiagnose as the server being down. Plenty of corporate networks, school networks, hotel Wi-Fi and mobile data connections permit only ports 80 and 443 outbound. Nothing is wrong with the server; your network will not carry the connection.
Two ways to confirm and work around it:
- **Try the standard-port alias.** cPanel & WHM answers on the `/whm` path of a domain hosted on the server, for example `https://yourdomain.com/whm`. This runs over the ordinary HTTPS port 443, so it passes through restrictive firewalls, and it redirects you into the same login screen.
- **Test from a different connection.** Tethering to a mobile phone for one attempt is the quickest way to prove the block is on your side rather than on the server.
If neither works from any connection, the problem is not a local firewall and it is worth raising a ticket with Noiz support.
## Two-Factor Authentication
If two-factor authentication is enabled on the account, the password step is followed by a prompt for a six-digit code from your authenticator app. WHM permits only one concurrent session per user when 2FA is active, so logging out in one browser window logs you out everywhere.
Enabling 2FA on a WHM account is strongly worth doing. WHM controls every hosting account on the server, so a compromised WHM password is not a single-site problem. Set it up while you still have working access, and store the recovery detail somewhere other than the device running the authenticator app. Losing the authenticator with no recovery route means a support ticket and identity verification before access is restored.
## Security Behaviour You Should Expect
- **Failed logins are counted.** cPanel & WHM includes brute force protection that temporarily blocks an IP address after repeated failed attempts, and can lock the account itself. If you have been guessing, wait rather than continuing, and contact Noiz support if you are still locked out.
- **Sessions are tied to your IP address.** If your connection changes address mid-session, which happens on some mobile and consumer connections, WHM ends the session and returns you to the login screen. This is expected behaviour, not a fault.
- **Sessions time out.** Leaving WHM open in a tab overnight will not keep you logged in. Log in again rather than assuming something has broken.
- **The URL contains a session token after login.** WHM inserts a segment such as `/cpsess1234567890/` into the address once you are authenticated. Never bookmark or share that address; it is specific to the session. Bookmark the plain `https://server1.yourdomain.com:2087` address instead.
## Troubleshooting
**Symptom**: the page will not load at all, or times out. The port is almost certainly blocked on your network. Try `https://yourdomain.com/whm` or a different connection, as described above.
**Symptom**: *"This site can't be reached"* when using the hostname, but the IP address works. DNS for the hostname has not propagated yet, or is pointing elsewhere. Use the IP address for now and let DNS settle.
**Symptom**: a certificate warning appears. Expected when connecting by IP address, because certificates cannot be issued for IP addresses. Use the server hostname from your welcome email instead and the warning goes away. If a warning appears on the hostname itself, do not click through; raise a ticket.
**Symptom**: the browser loads something other than WHM. The port number was left off the URL, so the browser went to the website on port 443 instead. Add `:2087` to the end of the address.
**Symptom**: *"The login is invalid"* despite correct details. Check for a trailing space pasted along with the password, confirm the username is the WHM account name rather than an email address, and confirm you are using WHM credentials rather than a cPanel account's credentials. They are different accounts even when the passwords match.
**Symptom**: the login is rejected repeatedly and then the page stops responding entirely from your location. Brute force protection has blocked your IP address. Stop attempting, and contact Noiz support with the public IP address you are connecting from.
**Symptom**: login succeeds but far fewer features appear than expected. You are logged in as a reseller rather than as the server administrator. Reseller accounts see only the features the server owner has granted, which is by design.
**Symptom**: the interface does not match the screenshots above. cPanel & WHM updates on its own release schedule and the layout changes between versions. Use the search box at the top of the left-hand menu to find any feature by name.
## Getting Help
If you cannot reach WHM after working through the checks above, open a ticket in the Noiz client area. Include the exact URL you are trying, the public IP address you are connecting from, the precise wording of any error, and whether the same attempt fails from a second network such as mobile data. That combination is usually enough to tell a network block, a DNS issue and an account lockout apart on the first reply. Noiz support can confirm the service is listening, clear a brute force block, and reset WHM credentials once your identity is verified.
# How to Create a Feature List in WHM
Source: https://docs.noiz.ie/whm/how-to-create-a-feature-list-in-whm/
This guide shows you how to create a feature list in WHM on your Noiz reseller or server account. A feature list is a saved set of tick boxes that decides which tools appear inside a cPanel account. Create one when you want a plan that exposes only certain features, for example a budget package with no cron jobs and no SSH access, or a developer package with everything switched on.
Two terms are easy to confuse. A **package** (also called a hosting plan) sets the numbers: disk space, bandwidth, how many databases and email accounts an account may have. A **feature list** sets the tools: whether the account holder can see and use Cron Jobs, Backups, Terminal, Softaculous, and so on. Every package points at exactly one feature list, so the two work together rather than replacing each other.
**Last reviewed:** 27 July 2026, against current stable cPanel & WHM, where this interface is **WHM ยป Packages ยป Feature Manager**. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel & WHM Documentation: Feature Manager](https://docs.cpanel.net/whm/packages/feature-manager/)
- [cPanel & WHM Documentation: Add a Package](https://docs.cpanel.net/whm/packages/add-a-package/)
## Prerequisites
- A WHM login for your Noiz reseller or server account. Your Noiz welcome email contains the details, and you can also reach WHM from the **Services** area of the [Noiz client area](https://www.noiz.co.za/clientarea.php).
- The **Feature Manager** privilege on your account. Resellers only see this interface if the privilege has been granted; if it is missing from your menu, open a ticket with Noiz support.
- A clear idea of which features the plan should expose. It is worth listing them before you start, because the selection screen is long.
## Create the Feature List
### 1. Log in to WHM
Sign in to WHM with your reseller or server credentials.
### 2. Open Feature Manager
Go to **Packages** ยป **Feature Manager**. If you prefer, type **Feature Manager** into the menu filter box at the top left of WHM and click the result when it appears.

### 3. Name and add the list
In the **Add a new feature list** field, type a name for the list, then click **Add Feature List**.

Choose a name that still makes sense to you in a year, because you will pick it from a drop-down list when you build packages. Something descriptive such as `starter-plan` or `developer-plan` beats `list2`. Keep it to plain letters, numbers, hyphens and underscores, and avoid spaces and punctuation, which can cause problems when the name is passed around the system.
### 4. Choose the features and save
WHM now shows the full list of available features with a tick box beside each one. Tick the features you want the plan to include, or tick **Select all features** to enable everything at once and then untick the few you want to withhold. When the selection is right, click **Save**.

The list is long, so use your browser's find function (`Ctrl+F`, or `Cmd+F` on a Mac) to jump to a specific feature name rather than scrolling. Go through the whole list before saving; anything left unticked will simply not appear in the cPanel accounts that use this list, and the account holder will not be told why.
Your feature list is now created and ready to use.
## Put the Feature List to Work
Creating a list changes nothing on its own. It only takes effect once a package points at it, or once you apply it to an individual account.
- **For a new plan:** go to **Packages** ยป **Add a Package**, set the quotas, and choose your new list from the **Feature List** drop-down before saving.
- **For an existing plan:** go to **Packages** ยป **Edit a Package**, select the package, change its **Feature List**, and save.
- **For one account only:** see [How to Enable/Disable Features of cPanel Account From WHM](/whm/how-to-enable-or-disable-cpanel-account-features-in-whm/).
## Things Worth Knowing Before You Save
- **Editing a list affects every account using it.** Feature lists are applied live, not copied at account creation. If you untick a feature later, it disappears from every cPanel account whose package uses that list, straight away. Create a separate list for a trial rather than editing a live one.
- **The *default* list is the fallback.** Any package that has no list of its own uses *default*, so changes there ripple across a lot of accounts. Leave it alone and build your own list instead.
- **The *disabled* list overrides everything.** This special list marks features that are unavailable server-wide. If a feature is switched off there, ticking it in your new list will not bring it back. It is not meant to be assigned to an account or a package. On a Noiz managed server, some features may be off at this level for security or platform reasons; contact Noiz support if you need one of them.
- **Turning off a feature hides the tool, it does not delete data.** Removing Cron Jobs from a list hides the icon in cPanel; jobs already scheduled are not wiped. Bear that in mind when you use feature lists as a security control rather than a tidiness one.
- **Deleting a list is not destructive.** If you remove a feature list later, any packages and accounts that used it fall back to the *default* list. See [How to Remove a Feature List from WHM](/whm/how-to-remove-a-feature-list-from-whm/).
## Troubleshooting
- **Symptom:** Feature Manager is not in the Packages menu. Your reseller account does not have the Feature Manager privilege. Open a ticket with Noiz support and ask for it to be enabled.
- **Symptom:** a feature you ticked still does not appear in cPanel. Check three things in order. First, confirm the account's package actually points at your new list. Second, check whether the feature is switched off in the *disabled* list, which overrides all others. Third, confirm the underlying software is installed on the server, since a feature list can only expose tools that exist.
- **Symptom:** the new list does not show in the **Feature List** drop-down when adding a package. Reload the Add a Package page. WHM caches the form, so a list created moments earlier sometimes needs a refresh to appear.
- **Symptom:** the list saved but every feature is still on. It is easy to click **Add Feature List** and then leave the page without clicking **Save** on the selection screen. Reopen the list from Feature Manager, set your selection, and save it properly.
## Need a Hand?
If you are unsure which features to expose on a plan, or a feature refuses to appear no matter how the list is set, Noiz support can check the server-level settings for you. Open a ticket from the [Noiz client area](https://www.noiz.co.za/clientarea.php) and include the feature list name and the affected account.
# How to Create a Hosting Package in WHM
Source: https://docs.noiz.ie/whm/how-to-create-a-hosting-package-in-whm/
A package in WHM is a saved template of hosting limits and features: disk quota, bandwidth, mailbox and database counts, the cPanel theme, and the feature list. Once a package exists you can create a cPanel account from it in a couple of clicks instead of typing every limit by hand, and every customer on that plan gets an identical specification. Packages are also what billing and provisioning software matches against when it creates accounts automatically, so the package name you choose here matters beyond WHM itself.
This guide is for server administrators and resellers with WHM access on a Noiz cPanel server. Packages are sometimes called plans or hosting plans in billing software, and cPanel's own documentation occasionally refers to them as account packages. They are the same thing.
**Last reviewed:** 27 July 2026, against current cPanel & WHM releases. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below. Field names shift slightly between cPanel & WHM versions, so if a label on your screen differs from the one quoted here, the nearest equivalent is almost certainly the right one.
### Official Documentation Reference
- [WHM: Add a Package](https://docs.cpanel.net/whm/packages/add-a-package/) (full field-by-field reference)
- [WHM: Feature Manager](https://docs.cpanel.net/whm/packages/feature-manager/) (building the feature lists a package can use)
- [WHM: Upgrade/Downgrade an Account](https://docs.cpanel.net/whm/account-functions/upgrade-downgrade-an-account/) (moving an existing account onto a package)
## Prerequisites
- A WHM login on your Noiz cPanel server, either the root account or a reseller account whose privileges include package creation.
- A decision on what the plan actually sells: disk space, monthly bandwidth, and how many domains, mailboxes and databases it allows.
- If the package will use a custom feature list, create that list first in **Packages** >> **Feature Manager**.
## Step 1: Open the Add a Package interface
1. Log in to WHM.
2. Go to **Packages** >> **Add a Package**, or type `Add a Package` into the menu filter box at the top left and click the result when it appears.

## Step 2: Name the package
Enter a name in the **Package Name** field. Keep it to letters, numbers, hyphens and underscores, and avoid spaces and full stops. Short, plan-shaped names such as `Bronze`, `Silver-2026` or `Business-10GB` are easier to live with than descriptive sentences.
Two things about naming that catch people out:
- If you are logged in as a **reseller** rather than as root, WHM automatically prefixes the package with your username and an underscore, so `Bronze` is stored as `yourreseller_Bronze`. That prefixed name is the real name, and it is what any external billing or provisioning system must be pointed at.
- Package names cannot be changed after creation. Renaming means creating a replacement package and moving accounts onto it, so it is worth a moment's thought now.
## Step 3: Set the resource limits
Work down the resources section and set each limit to suit the plan. Most fields accept either a number or an **Unlimited** tick box.

- **Disk Quota (MB)**: the total space the account may use, including mail and databases. Setting this to unlimited on a shared server means a single account can fill the filesystem and take every other site on the machine down with it. Noiz recommends a real number on every shared package, however generous.
- **Monthly Bandwidth (MB)**: counts web, mail and FTP traffic together, and resets at the start of each month. It is not the same as the transfer allowance quoted by your upstream network.
- **Max FTP Accounts**, **Max Email Accounts**, **Max Email Lists**, **Max Databases**: straightforward counts. Zero means none allowed, which is a valid choice for a locked-down plan and is not the same as unlimited.
- **Max Subdomains**, **Max Aliases**, **Max Addon Domains**: these govern how many extra domains the account can host. Aliases were called parked domains in older cPanel versions and appear under either label depending on your release.
- **Max Quota per Email Address (MB)**: the ceiling a user may set on any one mailbox. Leave headroom above what you expect people to need, because a mailbox that hits its quota starts bouncing incoming mail.
- **Maximum Hourly Email by Domain Relayed** and the failed-or-deferred percentage limit: these are the outbound mail brakes. Leaving them unlimited is how a compromised script on one account gets the server's IP address onto a blocklist. A conservative hourly cap on shared plans is worth far more than the support tickets it saves.
## Step 4: Configure the package settings
Under **Settings**, set the following.
- **Dedicated IP**: leave this unticked unless you have a specific reason and a spare IP address allocated to the server. Modern browsers and clients all support SNI, so SSL certificates no longer require a dedicated IP. Ticking this on a package with no free addresses in the pool causes account creation to fail rather than silently fall back.
- **Shell Access**: grants the account SSH access to the server. Noiz recommends leaving this unticked and enabling shell access per account, only where it is genuinely needed. If you do grant it, use the jailed shell option at account level rather than full shell.
- **CGI Access**: enables legacy CGI script execution. Most modern sites do not need it.
- **cPanel Theme**: on current cPanel & WHM versions `jupiter` is the only theme shipped, since the older Paper Lantern theme was removed. If your server offers only one entry here, that is expected.
- **Locale**: the default interface language for accounts created from this package. Individual users can change their own afterwards.
- **Feature List**: which cPanel features the account can see. Leave it on `default` unless you have built a custom list in **Feature Manager**. The `default` list exposes everything the server licence allows, which is fine for most plans and too much for cut-down ones.

## Step 5: Save the package
Click **Add**. WHM confirms that the package was created and it becomes immediately available in the package list when you create a new account through **Account Functions** >> **Create a New Account**.
Repeat steps 2 to 5 for each further plan you want to offer.
## What Happens to Existing Accounts
This is the single most common misunderstanding about packages. A package is a template applied at the moment an account is created. It is not a live policy that keeps enforcing itself afterwards. Editing a package later does not retrospectively change accounts that were already built from it. To push new limits onto an existing account, reassign it through **Account Functions** >> **Upgrade/Downgrade an Account**, which reapplies the package as it stands today.
The practical consequence: if you are correcting a mistake in a plan that customers are already on, changing the package is step one of two, not the whole job.
## Troubleshooting
**Symptom**: **Add a Package** does not appear in the WHM menu. Your WHM account does not have the package creation privilege. On a reseller account, the server owner has to grant it through **Resellers** >> **Edit Reseller Nameservers and Privileges**.
**Symptom**: WHM reports that the package name is invalid. Remove spaces, full stops and other punctuation, and keep to letters, numbers, hyphens and underscores.
**Symptom**: WHM reports that the package already exists, but you cannot see it. As a reseller you only see your own prefixed packages, so a name may already be taken by the prefixed version, or by a root-owned package of the same name. Choose a distinct name.
**Symptom**: account creation fails with an IP address error. The package has **Dedicated IP** ticked and the server has no unassigned addresses left. Untick it on the package, or have an address allocated to the server first.
**Symptom**: an existing customer's limits did not change after you edited the package. Expected behaviour. See *What Happens to Existing Accounts* above and reassign the account.
## Related Articles
- [How to Edit a Hosting Package in WHM](/whm/how-to-edit-a-hosting-package-in-whm/)
- [How to Delete a Package in WHM](/whm/how-to-delete-a-package-in-whm/)
If your server is on a Noiz managed plan and you would rather have the packages built for you, or you want a second opinion on sensible limits before you sell a plan, open a ticket from the Noiz client area and the Noiz support team will take it from there.
# How to Create a New cPanel Account in WHM
Source: https://docs.noiz.ie/whm/how-to-create-a-new-cpanel-account-in-whm/
WHM (WebHost Manager) is the administrative layer that sits above cPanel. Creating an account in WHM is how you turn a hosting package into a live cPanel user: a username, a home directory, a DNS zone, mail routing and a set of resource limits, all provisioned in one step. This guide walks you through the **Create a New Account** interface, explains what each field actually does, and flags the choices that are awkward to reverse later.
It is written for anyone with WHM access: a reseller creating accounts for clients, or a server administrator creating accounts on a VPS or dedicated server.
**Last reviewed:** 27 July 2026, against the current stable cPanel & WHM release. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below. Field names and section order vary slightly between versions and between reseller and root logins, so treat the labels below as the current wording rather than a fixed layout.
### Official Documentation Reference
- [WHM: Create a New Account](https://docs.cpanel.net/whm/account-functions/create-a-new-account/) (full field reference)
- [WHM: Add a Package](https://docs.cpanel.net/whm/packages/add-a-package/)
- [WHM: Modify an Account](https://docs.cpanel.net/whm/account-functions/modify-an-account/)
- [WHM: Account Functions overview](https://docs.cpanel.net/whm/account-functions/)
- [cPanel product versions and the release process](https://docs.cpanel.net/knowledge-base/cpanel-product/product-versions-and-the-release-process/) (how to tell which version your server runs)
## Prerequisites
- Login details for WHM, either the root account or a reseller account with the **Create Account** privilege.
- At least one hosting package. Packages define disk quota, bandwidth, the number of mailboxes and databases, and the feature list. If you have not created one yet, see [How to Create/Add a Package in the WHM](/whm/how-to-create-a-hosting-package-in-whm/).
- The domain name the account will host, and somewhere safe to store the generated password (a password manager, not a text file on your desktop).
- Enough free disk space and enough remaining account slots on your reseller or server licence.
## Step 1: Log in to WHM
Sign in to WHM with your root or reseller credentials. Reseller accounts see a reduced menu and can only create accounts within the limits their provider has set.
## Step 2: Open Create a New Account
In the left sidebar, go to **Account Functions** >> **Create a New Account**. The quickest route is to type `create` into the menu filter box at the top of the sidebar and click the matching result.

## Step 3: Fill in Domain Information
This is the only section you must complete by hand. Everything below it has a sensible default.
- **Domain:** The domain the account will host, for example `yourdomain.com` (replace this with the real domain). Enter it without `www.` and without `http://`. This becomes the account's primary domain and it is the one value that is genuinely painful to change later, so check the spelling before you continue.
- **Username:** Click into the blank field and WHM suggests a username derived from the domain. You can overwrite it. The username is permanent for the life of the account, it prefixes every database and system mailbox name, and it is the Linux user that owns the files.
- **Password** and **Re-type Password:** Use the built-in **Password Generator** and copy the result somewhere safe before you submit the form. WHM shows a strength meter and will refuse weak passwords if a minimum strength is enforced on the server. If the password is lost, it can be reset later from **Modify an Account** or from within cPanel.
- **Email:** A working contact address for the account holder. Do not use an address at the domain you are about to create, because the mailbox does not exist yet and account notifications would be undeliverable.

## Step 4: Choose a package
Under **Package**, pick an existing package from the **Choose a Package** drop-down. The package supplies the disk quota, bandwidth allowance, mailbox and database limits, and the feature list the customer sees inside cPanel.
Selecting **Select Options Manually** instead reveals the **Manual Resource Options** section, where you can set those limits per account and optionally save the result as a new package. Manual settings are convenient once and a maintenance problem forever: an account created that way is not linked to a package, so a later change to your standard limits will not reach it. Prefer creating a package and reusing it.
## Step 5: Review the Settings section
Defaults here are usually correct. The fields worth understanding are:
- **Dedicated IP:** Assigns the account its own IP address instead of the shared server IP. Only tick this when there is a real requirement, and only if a spare address is available. Modern SSL certificates work fine on shared IPs thanks to SNI, so a dedicated IP is rarely needed for HTTPS.
- **Shell Access:** Grants SSH access to the server. Leave this off for ordinary hosting accounts. If a developer needs shell access, jailed shell is the safer choice where your server offers it.
- **CGI Access:** Allows the account to execute CGI scripts from `cgi-bin`. This option still exists in current versions and is enabled by default, but almost nothing needs it today. PHP applications run through PHP-FPM or a similar handler, not CGI. Leave it as the package sets it unless a specific legacy Perl or shell script requires it.
- **Digest Authentication for Web Disk:** Only needed for Web Disk connections from older Windows clients over an unencrypted connection. Leave it off and use an encrypted Web Disk or WebDAV connection instead.
- **cPanel Theme:** Leave the default unless you deliberately provision a different interface style.
- **Locale:** The language the new cPanel account opens in. Set it to match the account holder rather than yourself.

## Step 6: Check Mail Routing and Reseller Settings
**Mail Routing Settings** tells the server what to do with mail for the new domain. **Automatically Detect Configuration** is the correct choice in almost every case: it inspects the domain's MX records and routes accordingly. Choose **Remote Mail Exchanger** only when mail for the domain is deliberately hosted elsewhere, such as a third-party mail provider, otherwise the server will keep mail locally and the customer will not receive it.
Under **Reseller Settings**, **Make the account a reseller** promotes the new user so they can create accounts of their own. Leave it unticked for a normal hosting account. This option appears only when you are logged in as root or as a reseller with the relevant privilege.
## Step 7: Confirm DNS Settings
- **Enable DKIM on this account:** Enabled by default. Keep it enabled. DKIM signs outgoing messages so receiving servers can confirm the mail genuinely came from the domain.
- **Enable SPF on this account:** Keep it enabled. SPF publishes which servers are allowed to send mail for the domain, which makes spoofing harder and improves the odds that legitimate mail reaches the inbox.
- **Enable DMARC on this account:** Publishes a policy telling receiving servers how to treat mail that fails SPF and DKIM. Current versions add a starting record automatically.
- **Use the nameservers specified at the domain's registrar:** Tick this when the domain's DNS is managed somewhere other than this server. If you leave it unticked, WHM creates a local DNS zone that will simply be ignored while the registrar points elsewhere, which is a common source of confusion when records are edited in the wrong place.
DKIM, SPF and DMARC records only take effect once the domain's authoritative DNS is actually served by this server. If DNS is hosted elsewhere, copy the generated records across manually.

## Step 8: Create the account
Leave any remaining options at their defaults, scroll to the bottom of the form and click **Create**.

WHM streams a progress log while it provisions the home directory, DNS zone, mail configuration and database user. Wait for the confirmation that the account was created successfully rather than navigating away, because errors are reported inside that log and nowhere else.
## After the account is created
- Point the domain at the correct nameservers if you have not already. Domains hosted with Noiz use **ns1.noiz.co.za** and **ns2.noiz.co.za**.
- Issue an SSL certificate for the new domain. On servers with AutoSSL enabled this happens automatically once DNS resolves to the server, which can take a few hours after a nameserver change.
- Send the account holder their cPanel username and login URL, and ask them to change the password on first login.
- Resource limits, the package, the contact address and the password can all be adjusted afterwards from **Account Functions** >> **Modify an Account**. The username and the primary domain are the two values best treated as permanent.
## Troubleshooting
**Symptom**: "This domain is already set up" or "domain already exists". The domain, or a subdomain of it, is already hosted on the server under another account. Search **List Accounts** for the domain and remove or rename the conflicting entry before retrying.
**Symptom**: The username is rejected. cPanel usernames are lowercase, start with a letter, contain only letters and digits, and are limited in length. They also cannot clash with an existing system user, so avoid names such as `mail`, `test` or `admin`.
**Symptom**: "You have reached your maximum number of accounts". A reseller limit or a licence limit has been reached. Ask your provider to raise the limit, or remove an unused account first.
**Symptom**: The account is created but the website shows the default page. DNS has not propagated to the new server yet, or the domain still points at the old nameservers. Confirm the domain resolves to the correct IP address before assuming the account is at fault.
**Symptom**: Mail is accepted by the server but the customer never receives it. Mail routing is set to local while the MX records point elsewhere, or the reverse. Correct the routing in **Edit MX Entry** for that domain.
**Symptom**: The customer needs their account taken offline rather than deleted. Suspend it instead of removing it, which preserves the files and settings. See [How to Suspend a cPanel User in the WHM Account](/whm/how-to-suspend-a-cpanel-user-in-the-whm-account/).
## Need a hand?
If you are unsure which control panel your Noiz plan uses, or an account will not provision, open a support ticket from the Noiz client area with the domain name and the exact error text from the WHM log. Noiz support can check server-side limits, DNS and licensing on your behalf.
# How to Delete a Package in WHM
Source: https://docs.noiz.ie/whm/how-to-delete-a-package-in-whm/
A hosting package in WHM is a reusable template of resource limits and features that you apply to cPanel accounts when you create them. Deleting a package removes that template from your reseller or server account list so it can no longer be selected for new accounts. This guide shows you where the option lives in WHM, what happens to accounts that were created from the package, and the one condition that stops a deletion from going through.
Packages are sometimes called plans or hosting plans. In WHM they are always "packages", and a reseller package name is stored with your username as a prefix, for example `reseller_starter`.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable release). This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [WHM: Delete a Package](https://docs.cpanel.net/whm/packages/delete-a-package/): the vendor reference for this interface.
- [WHM: Edit a Package](https://docs.cpanel.net/whm/packages/edit-a-package/): change a package instead of deleting it.
- [WHM: Upgrade/Downgrade an Account](https://docs.cpanel.net/whm/account-functions/upgrade-downgrade-an-account/): how to move an account onto a different package.
- [WHM: Packages](https://docs.cpanel.net/whm/packages/): the full packages section, including feature lists.
## Prerequisites
- A WHM login for your Noiz reseller account, or root access if you administer the whole server.
- At least one package that you own. Resellers can only delete their own packages; a package created by the server administrator is not yours to remove.
- Confirmation that no live account still needs the package. See the section below before you start.
## Check Whether the Package Is Still in Use
This is the step most people skip, and it is the reason a deletion fails. **WHM will not delete a package that an account on the server currently uses.** The package has to be free of accounts before the interface will remove it.
To see which accounts sit on which package, go to **Account Information** >> **List Accounts** and check the **Package** column, or expand an individual account row. If any account still shows the package you want to remove, move it first.
To move an account onto a different package, go to **Account Functions** >> **Upgrade/Downgrade an Account**, choose the account, select the replacement package, and apply the change. Repeat for every account still on the old package, then come back and delete it.
One point that trips people up: the package is only a template. An account created from a package gets its own copy of those limits at creation time, so removing the package afterwards does not strip disk space, bandwidth or features from a live site. Nothing is suspended and no data is lost. What you do lose is the tidy grouping, and the ability to select that package for future accounts or in an upgrade or downgrade.
## Delete the Package in WHM
1. Log in to your WHM account.
2. Go to **Packages** >> **Delete a Package**. If you prefer, type **Delete a Package** into the menu filter box at the top of the left sidebar and click the result that appears. 
3. Under **Delete a Package**, select the package you want to remove from the list, then click **Delete**. 
WHM confirms the removal on screen. The package disappears from the list and is no longer offered when you create an account.
## Before You Delete: This Cannot Be Undone
There is no undo and no recycle bin for packages. A deleted package has to be rebuilt by hand, and rebuilding it means re-entering every quota, every feature list selection and every setting exactly as it was. If the package is one you might want back, take a screenshot of it in **Packages** >> **Edit a Package** first, or simply edit the package to be unavailable in practice rather than deleting it.
Editing is usually the better answer when a plan is being retired rather than abandoned. An edited package keeps its history and can be reused; a deleted one is gone.
## If You Sell Through Billing Software
If you resell hosting and your billing system provisions cPanel accounts automatically, the package name is stored in the product configuration on the billing side as well as in WHM. Deleting the package in WHM does not update the billing system, so the next order placed against that product will try to create an account using a package that no longer exists and the provisioning will fail.
Update or disable the matching product in your billing system at the same time you delete the package. Doing both in one sitting avoids a failed order landing in your queue days later with no obvious cause.
## Troubleshooting
**Symptom**: the deletion is refused because the package is in use. One or more accounts are still assigned to it. Move them with **Account Functions** >> **Upgrade/Downgrade an Account**, then delete the package. Remember to check suspended accounts too, since a suspended account still holds its package assignment.
**Symptom**: the package does not appear in the list at all. As a reseller you only see packages you own. Package names you created are prefixed with your username, so `starter` created by the server administrator and `yourreseller_starter` created by you are two different things. If the package you want is not prefixed with your username, it belongs to the server administrator.
**Symptom**: **Delete a Package** does not show in the sidebar. Your reseller account has not been granted the package management privilege. Ask for it to be added to your reseller permissions.
**Symptom**: you deleted the wrong package. It cannot be recovered. Recreate it with **Packages** >> **Add a Package**, matching the original limits and feature list. Existing accounts that used the old package are unaffected, but they will not automatically re-link to the recreated package unless you reassign them.
## Related Articles
- [How to Create a Hosting Package in WHM](/whm/how-to-create-a-hosting-package-in-whm/)
- [How to Edit a Hosting Package in WHM](/whm/how-to-edit-a-hosting-package-in-whm/)
## Need a Hand?
If a package will not delete and you cannot find the account holding it, open a ticket from your Noiz client area with the exact package name and the error WHM shows you. The Noiz support team can confirm the assignment server side and tell you precisely which account is still on the package.
# How to Edit a Hosting Package in WHM
Source: https://docs.noiz.ie/whm/how-to-edit-a-hosting-package-in-whm/
A package in WHM is a saved template of hosting limits and features: disk quota, monthly bandwidth, mailbox and database counts, the cPanel theme and the feature list. Editing a package changes that template, so every account you build from it afterwards is created to the new specification. This guide shows you where the interface lives on a Noiz cPanel server, what each section controls, the handful of settings WHM will not let you change once the package exists, and what an edit does and does not do to accounts that are already on the package.
This guide is written for server administrators with root access and for resellers whose WHM privileges include package management. Root lets you edit any package on the server. A reseller can only edit packages they own, and those are stored with the reseller username as a prefix, so `Bronze` created by a reseller is really `yourreseller_Bronze`. Packages are sometimes called plans or hosting plans in billing software. They are the same thing.
**Last reviewed:** 27 July 2026, against the current stable cPanel & WHM release. The **Edit a Package** interface described here is valid from cPanel & WHM version 118 through the latest release. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below. Field labels shift slightly between releases, so if a label on your screen differs from the one quoted here, the nearest equivalent is almost certainly the right one.
### Official Documentation Reference
- [WHM: Edit a Package](https://docs.cpanel.net/whm/packages/edit-a-package/) (the vendor reference, field by field)
- [WHM: Feature Manager](https://docs.cpanel.net/whm/packages/feature-manager/) (building the feature lists a package can point at)
- [WHM: Upgrade/Downgrade an Account](https://docs.cpanel.net/whm/account-functions/upgrade-downgrade-an-account/) (reapplying a package to one existing account)
- [WHM: Modify/Upgrade Multiple Accounts](https://docs.cpanel.net/whm/multi-account-functions/modify-upgrade-multiple-accounts/) (doing the same in bulk)
- [WHM: Packages](https://docs.cpanel.net/whm/packages/) (the whole packages section)
## Prerequisites
- A WHM login on your Noiz cPanel server: either root, or a reseller account whose privileges include package management.
- At least one package that you own. If there is nothing to edit yet, start with [How to Create a Hosting Package in WHM](/whm/how-to-create-a-hosting-package-in-whm/).
- The new limits decided before you open the form. It is far easier to type a considered set of numbers once than to keep saving and re-opening the package.
- If the package will point at a custom feature list, build that list first in **Packages** >> **Feature Manager**.
## Edit a Package in WHM
**1.** Log in to your WHM account.
**2.** Go to **Packages** >> **Edit a Package**, or type **Edit a Package** into the menu filter box at the top of the left sidebar and click the result when it appears.

**3.** Select the package you want to change from the **Package** menu, then click **Edit**. Resellers see only their own prefixed packages here, so if the plan you are looking for is missing, it probably belongs to the server administrator rather than to you.

**4.** The full package form opens with the current values already filled in. Work down the **Resources** section to change disk space, monthly bandwidth, mailbox, database and domain limits, then the **Settings** section for shell access, the cPanel theme, the locale and the feature list. Any field with an **Unlimited** option can be set to a number instead, and vice versa.

**5.** Scroll to the bottom and click **Save Changes**. WHM confirms the update on screen. If you have made a mess of the form and want the previous values back, click **Reset** instead, which restores the stored settings without saving anything.
## What You Cannot Change Once a Package Exists
Three things are fixed at creation time, and knowing which they are saves you hunting for a field that is not there.
- **The package name.** WHM has no rename. If the name is wrong, create a replacement package with the correct name and move the accounts onto it through **Account Functions** >> **Upgrade/Downgrade an Account**. This matters more than it sounds, because the package name is the value external billing and provisioning systems match against.
- **Dedicated IP.** This setting cannot be edited after the package is created. Changing it means building a new package.
- **Which package extensions are attached.** You can edit the values inside an extension the package already carries, but you cannot add or remove extensions from an existing package through the WHM interface. Use **Packages** >> **Add a Package** for a different set, or the WHM API. If an attached extension is no longer installed on the server, WHM shows a warning and blocks the edit until you either install it or tick **Remove missing extensions from package** and save.
## Fields Worth a Second Look
Most of the form is self-explanatory. These are the ones that cause support tickets.
- **Disk Space Quota (MB)**: covers files, mail and databases together. Take care when lowering it. An account already sitting above the new figure lands over quota the moment the change reaches it, and an over-quota account cannot write files, cannot receive mail, and will usually break any database-driven site on it. Check current usage under **Account Information** >> **List Accounts** before you cut a quota.
- **Monthly Bandwidth Limit (MB)**: counts web, mail and FTP traffic together and resets at the start of each month. It is not the same thing as the transfer allowance quoted for the server itself.
- **Max Quota per Email Address (MB)**: the ceiling a user may set on any single mailbox. Raising or lowering it does not touch mailboxes that already exist, only ones created afterwards, so an existing oversized mailbox will not shrink because you changed this.
- **Maximum Hourly Email by Domain Relayed**: the outbound mail brake, and the setting that stops one compromised script putting the whole server's IP address on a blocklist. You cannot set it higher than the server-wide **Max hourly emails per domain** tweak setting, though you can set it lower. A value of `0` behaves as unlimited rather than as a block, which is the opposite of what most people expect.
- **Maximum Percentage of Failed or Deferred Messages a Domain May Send Per Hour**: WHM looks at the previous hour of mail and temporarily stops a domain sending once it crosses the figure. A sensible percentage here catches a compromised contact form long before a human notices.
- **Feature List**: decides which cPanel tools accounts on this package can see. Click **View** next to the menu to jump straight to **Feature Manager** and check what a list actually contains before you assign it. Never assign the `disabled` list to a package. It is a server-level definition of features to switch off, not a list to hand to accounts, and assigning it produces a cPanel with almost nothing in it.
- **Shell Access**: grants SSH access to every account on the package. Noiz recommends leaving it off at package level and granting shell per account only where it is genuinely needed, using a jailed shell rather than full shell.
- **cPanel Theme**: current cPanel & WHM releases ship `jupiter` only, since Paper Lantern was removed. A single entry in this menu is expected, not a fault.
## What Happens to Accounts Already on the Package
This is the single biggest misunderstanding about packages, and it is worth being clear about before you edit anything. A package is a template that is applied at the moment an account is created. It is not a live policy that keeps enforcing itself afterwards. Editing the package does not retrospectively rewrite the limits of accounts that were already built from it.
So if you are correcting a plan that customers are already on, changing the package is step one of two:
1. Edit the package, using the steps above, so new accounts are correct from here on.
2. Reapply it to the existing accounts. For a single account, use **Account Functions** >> **Upgrade/Downgrade an Account**, which reapplies the package exactly as it stands today. For several at once, use **Multi Account Functions** >> **Modify/Upgrade Multiple Accounts**.
After either operation, confirm the result on one real account rather than assuming. **Account Information** >> **List Accounts** shows the package and the current limits per account, and that check takes a few seconds against the hours a silently unapplied quota change can cost you.
## If You Sell Through Billing Software
Billing and provisioning systems join to WHM on the package name, and they keep their own copy of what the plan is supposed to include. Editing the package in WHM changes what the server hands out; it does nothing to the product description, the price or the advertised limits on the billing side. Update both in the same sitting, or the plan you sell and the plan you provision will drift apart, usually discovered by a customer rather than by you.
## Troubleshooting
**Symptom**: **Edit a Package** is not in the WHM sidebar. On a reseller account the interface can be switched off by the server administrator through **Resellers** >> **Edit Reseller Nameservers and Privileges**. Ask for the package management privilege to be added.
**Symptom**: the package you want is not in the **Package** menu. Resellers see only their own packages, and those carry a username prefix. A package named `starter` owned by the server administrator and `yourreseller_starter` owned by you are two separate packages, and you cannot edit the first.
**Symptom**: there is no field to rename the package. Correct, WHM does not offer one. Create a replacement package and move the accounts across.
**Symptom**: a customer's limits did not change after you saved the package. Expected behaviour. Editing the package does not update accounts built from it. Reapply it through **Upgrade/Downgrade an Account** as described above.
**Symptom**: an account went over quota, and mail started bouncing, straight after an edit. The new disk quota is lower than what that account is already using. Raise the quota again to restore service, then work out what is consuming the space (old backups and mailboxes are the usual culprits) before you try lowering it a second time.
**Symptom**: the form refuses to save and complains about a missing extension. One of the package extensions attached to this package is not installed on the server. Install it, or tick **Remove missing extensions from package** and save again.
**Symptom**: **Save Changes** appears to do nothing. The confirmation is rendered in JavaScript, so a strict content blocker, a browser extension or a corporate proxy can swallow it. Reload **Edit a Package**, select the same package and check whether the values you entered are showing before you save a second time.
## Related Articles
- [How to Create a Hosting Package in WHM](/whm/how-to-create-a-hosting-package-in-whm/)
- [How to Delete a Package in WHM](/whm/how-to-delete-a-package-in-whm/)
## Need a Hand?
If a package edit has not reached the accounts you expected, or you would rather have someone check a set of limits before you push them onto live customers, open a ticket from your Noiz client area with the package name and the accounts involved. The Noiz support team can confirm what each account is actually provisioned with server side. On a managed Noiz plan the team will make the change and reapply it across the affected accounts for you.
# How to Enable or Disable cPanel Account Features in WHM
Source: https://docs.noiz.ie/whm/how-to-enable-or-disable-cpanel-account-features-in-whm/
WHM lets you decide exactly which tools appear inside your customers' cPanel accounts. If you would rather not expose the PHP version selector, SSL/TLS tools, cron jobs or any other feature to a particular set of accounts, you control that from **Feature Manager** by ticking or unticking features on a feature list.
This guide covers editing an existing feature list to enable or disable individual features. It is written for resellers and server administrators who manage cPanel accounts through WHM.
**Last reviewed:** 27 July 2026, against the current stable cPanel & WHM release. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel documentation: WHM Feature Manager](https://docs.cpanel.net/whm/packages/feature-manager/) (full reference for every feature that can be toggled)
- [cPanel documentation: Edit a Package](https://docs.cpanel.net/whm/packages/edit-a-package/) (how a feature list is attached to a hosting package)
- [cPanel documentation: Add a Package](https://docs.cpanel.net/whm/packages/add-a-package/)
## Prerequisites
- WHM access with reseller or root privileges.
- At least one feature list to edit. WHM always ships with the **default** list; to build your own first, see [How to Create a Feature List in WHM](/whm/how-to-create-a-feature-list-in-whm/).
- An understanding of which hosting package the affected accounts use, because that is what links an account to a feature list.
## How Feature Lists Actually Apply
Editing a feature list does not target a single customer. The chain works like this:
- A cPanel account is created from a **package**.
- Each package names one **feature list**.
- The feature list decides which icons and tools that account can see.
So a tick or an untick propagates instantly to every account whose package points at that list. Two consequences are worth knowing before you save anything:
- **The default list is shared.** Any account whose package has no specific list assigned falls back to **default**. Editing **default** therefore changes those accounts too, which is rarely what you want when you are trying to restrict one customer tier. Create a separate list for that tier instead.
- **The disabled list wins over everything.** WHM reserves a list named **disabled**. Anything ticked there is switched off server-wide, no matter what the account's own feature list says. If a feature stubbornly refuses to appear after you enable it, check **disabled** first.
A reseller can only hand out features that their own reseller account holds. If a feature is missing from the Feature Manager screen entirely, it is either not installed on the server or not part of your own privileges, and the server administrator needs to enable it upstream.
## Enable or Disable Features in Feature Manager
### 1. Log in to WHM
Sign in to WHM with your reseller or root credentials.
### 2. Open Feature Manager
Go to **Packages** >> **Feature Manager**, or type **Feature Manager** into the menu filter box at the top left and click the result that appears.

### 3. Choose the feature list to edit
Under **Feature Manager List**, select the list you want to change from the drop-down menu, then click **Edit**.
Confirm you have picked the right list before continuing. If you are unsure which list a customer is on, check the package assigned to their account under **Packages** >> **Edit a Package**, which names the feature list it uses.

### 4. Tick or untick features, then save
Tick the checkbox next to any feature you want to enable, and clear the checkbox next to any feature you want to disable. The list is long, so use the search box on the page to jump straight to a feature by name. When you are happy with the selection, click **Save**.

### 5. Verify the result from the customer's side
Changes take effect immediately, with no need to recreate accounts or repackage anything. To confirm, go to **Account Information** >> **List Accounts**, click the cPanel icon beside an affected account to log in as that user, and check that the feature has appeared or disappeared. A customer with cPanel already open in a browser tab may need to refresh or sign out and back in before the change shows.
## What Disabling a Feature Does and Does Not Do
- **It hides the interface, it does not delete data.** Disabling cron jobs, for example, removes the icon from cPanel but leaves existing cron jobs scheduled and running. The same applies to email accounts, databases and redirects. If the intent is to remove something, remove it explicitly before hiding the tool that manages it.
- **It is a scoping tool, not a security boundary.** cPanel refuses most API calls for features that are switched off, but a feature list is meant to shape what a hosting tier offers, not to contain a hostile account. Use quotas, permissions and account-level limits for anything security critical.
- **It applies to every account on that list.** There is no per-account override inside Feature Manager. If one customer needs something different, put them on a package that uses a different feature list.
## Troubleshooting
- **Symptom**: a feature is still missing after you ticked it. Check that it is not ticked in the **disabled** list, which overrides all other lists, and confirm the account's package really points at the list you edited.
- **Symptom**: the change did not reach the customer. Confirm which list their package uses under **Edit a Package**. Editing the wrong list is by far the most common cause.
- **Symptom**: the feature you want is not listed at all in Feature Manager. The related service or plugin is not installed on the server, or your reseller account does not hold that feature. Ask the server administrator to enable it.
- **Symptom**: the customer still sees the old cPanel layout. Ask them to refresh the page or sign out and back in, since cPanel caches the interface for the length of a session.
## Related Articles
- [How to Create a Feature List in WHM](/whm/how-to-create-a-feature-list-in-whm/)
- [How to Remove a Feature List from WHM](/whm/how-to-remove-a-feature-list-from-whm/)
If you are unsure which feature list a hosting package should use, or you need a feature enabled that does not appear in WHM at all, open a ticket from the Noiz client area and the Noiz support team will take a look with you.
# How to Force cPanel Users to Change Their Passwords in WHM
Source: https://docs.noiz.ie/whm/how-to-force-cpanel-users-to-change-their-passwords-in-whm/
If you run a reseller or server account with WHM, you can require any of your cPanel users to set a new password the next time they log in. This is the fastest way to close off a shared or leaked password across one account or across every account on the server at once, without having to reset each password yourself and then distribute it.
This guide covers the **Force Password Change** interface in WHM, what the user actually experiences afterwards, and the knock-on effects worth planning for before you tick every box and hit submit.
**Last reviewed:** 27 July 2026, against cPanel & WHM (the **Force Password Change** interface is valid for version 82 through the latest release). This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [WHM: Force Password Change](https://docs.cpanel.net/whm/account-functions/force-password-change/)
- [WHM: Password Modification](https://docs.cpanel.net/whm/account-functions/password-modification/)
- [WHM: Password Strength Configuration](https://docs.cpanel.net/whm/security-center/password-strength-configuration/)
- [cPanel: Password & Security](https://docs.cpanel.net/cpanel/preferences/password-and-security/)
- [WHM API 1: forcepasswordchange](https://api.docs.cpanel.net/openapi/whm/operation/forcepasswordchange/)
## Prerequisites
- A WHM login with root access, or a reseller account whose privileges include the **Force Password Change** interface. Resellers only see this interface if the server owner has enabled it under **Resellers** >> **Edit Reseller Nameservers and Privileges**.
- The cPanel usernames you intend to target. It is worth listing them before you start, because the interface makes it very easy to select everything.
- A way to reach the account owners (email or phone), so the prompt does not arrive as a surprise.
This guide applies to cPanel & WHM specifically. If your Noiz service uses a different control panel, the equivalent option lives elsewhere and the steps below will not match. Contact Noiz support if you are not sure which panel your plan runs on.
## Force a Password Change in WHM
### Step 1: Open the Force Password Change interface
1. Log in to WHM.
2. Go to **Account Functions** >> **Force Password Change**. The quickest route is to type `Force Password` into the menu filter box at the top left, then click the result.

### Step 2: Select the accounts
1. Tick the **Forced?** checkbox beside each cPanel user you want to prompt. Select as many as you need.
2. To act on everything at once, use the select and deselect buttons at the top of the list rather than ticking each row.
3. Click **Submit**.

The setting takes effect immediately. There is no confirmation email and no grace period to configure.
## What the User Sees Next
Nothing changes for the user until they next log in to cPanel. Their current password still works to get in. Once they are in, cPanel presents a password change prompt and withholds full access to the interface until a new password is set. They cannot dismiss it and carry on.
Two details catch people out:
- The **Forced?** checkbox stays ticked in WHM until that user has actually changed their password. A still-ticked box is not a failed submission, it is an outstanding prompt. Use the interface as a to-do list to see who has complied.
- The prompt is tied to cPanel login. Logging in to an account from WHM using the account entry does not use the account password, so it does not clear the flag. The user has to log in to cPanel directly, or change the password from **cPanel** >> **Password & Security**.
## Plan the Change Before You Submit It
Forcing a change on a single suspicious account is low risk. Forcing it on every account at once is a different exercise, and these are the things that break.
- **Stored credentials stop working.** Anything holding the old cPanel password breaks the moment the user changes it: backup tools, deployment scripts, monitoring checks, migration utilities and remote file managers. Warn the account owners so they know to update these too.
- **The main FTP account follows the cPanel password.** The primary FTP login shares the cPanel account password, so an FTP client saved with the old password will start failing. Additional FTP accounts created inside cPanel keep their own passwords and are unaffected.
- **Email account passwords are separate.** Forcing a cPanel password change does not touch individual mailbox passwords, so mail clients keep working. If a mailbox itself is compromised, change that mailbox password in cPanel instead.
- **Database users and API tokens are separate.** MySQL users and any cPanel or WHM API tokens keep working. If the concern is a full compromise rather than a weak password, revoke tokens and rotate database passwords as well.
- **SSH keys are unaffected.** Key-based SSH access continues to work, which is worth remembering when the goal is to lock someone out rather than tidy up passwords.
- **There is no scheduled expiry.** cPanel & WHM does not rotate passwords on a timer. The flag you set is a one-off. If you want periodic rotation, repeat this manually or script it.
## Set the Password Rules First
Forcing a change is only useful if the replacement password has to be a good one. Before a bulk run, check **Security Center** >> **Password Strength Configuration** in WHM. That interface sets the minimum strength score cPanel will accept, both as a default and per feature, so you can raise the bar for everyone in one place. Otherwise a user under pressure will simply replace a weak password with another weak password.
## Doing It at Scale
For more than a handful of accounts, or for a rotation you want to repeat, the same action is available through WHM API 1 as the `forcepasswordchange` call, listed in the API reference linked above. Run it with an API token rather than a stored root password, and test against one account before looping over a server list.
## Troubleshooting
**Symptom**: **Force Password Change** does not appear in WHM. On a reseller account, the interface is only visible when the server owner has granted it under **Resellers** >> **Edit Reseller Nameservers and Privileges**. Ask the server owner to enable it, or use **Password Modification** if you only need to reset one password directly.
**Symptom**: the checkbox is still ticked days later. The user has not logged in to cPanel yet, or has only been reaching the account through WHM. Contact them and ask them to log in to cPanel directly and complete the prompt.
**Symptom**: the user is stuck on the prompt and cannot set a new password. The password they are choosing is failing the strength requirement. Have them use the password generator on the prompt, or lower the requirement in **Password Strength Configuration** if it has been set unreasonably high.
**Symptom**: the user cannot log in at all to complete the change. Reset the account password yourself in WHM under **Account Functions** >> **Password Modification**, send it to them over a channel you trust, then force the change again so they replace it with something only they know.
**Symptom**: a website or script broke straight after the change. Something was authenticating with the old cPanel password, most often an FTP deployment or a backup job. Update the stored credential, and consider moving that integration to an API token or SSH key so a future password change does not break it.
## Need a Hand?
If you suspect an account has been compromised rather than simply carrying a weak password, forcing a password change is one step of several. Open a ticket with Noiz support from your client area and the team can help you review access, revoke tokens and check for anything left behind.
# How to Limit Bandwidth Usage for a cPanel Account in WHM
Source: https://docs.noiz.ie/whm/how-to-limit-bandwidth-usage-for-a-cpanel-account-in-whm/
Bandwidth is the amount of data a hosting account transfers to visitors each month. In WHM you can raise, lower or remove that monthly allowance for any cPanel account you own, without touching the account's hosting package. This guide shows you where the setting lives, explains what actually happens when an account runs out of bandwidth, and covers how to lift the block once it has been applied.
It is written for resellers and server administrators managing cPanel accounts through WHM. A reseller can change the bandwidth of the accounts they own; the root user can change it for any account on the server.
**Last reviewed:** 27 July 2026, against the current stable cPanel & WHM release. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel documentation: WHM Limit Bandwidth Usage](https://docs.cpanel.net/whm/account-functions/limit-bandwidth-usage/)
- [cPanel documentation: Account Suspension Versus Bandwidth Limiting and Account Termination](https://docs.cpanel.net/knowledge-base/accounts/account-suspension-versus-bandwidth-limiting-and-account-termination/) (exactly which services stop when a limit is hit)
- [cPanel documentation: WHM Unsuspend Bandwidth Exceeders](https://docs.cpanel.net/whm/account-functions/unsuspend-bandwidth-exceeders/)
- [cPanel documentation: WHM View Bandwidth Usage](https://docs.cpanel.net/whm/account-information/view-bandwidth-usage/)
- [cPanel documentation: WHM Edit a Package](https://docs.cpanel.net/whm/packages/edit-a-package/)
## Prerequisites
- WHM access with reseller or root privileges. If you are not sure how to reach WHM, see [How to Access the Web Host Manager or WHM](/whm/how-to-access-and-log-in-to-whm-web-host-manager/).
- Ownership of the cPanel account you want to change. Resellers only see their own accounts in the list.
- The **Limit Bandwidth Usage** privilege on your reseller account. The server administrator controls this under **Resellers** >> **Edit Reseller Nameservers and Privileges**, so if the tool does not appear in your WHM at all, ask for it to be enabled.
- The figure you want to set, in **megabytes**. cPanel measures bandwidth in MB, so a 50 GB monthly allowance is `51200`.
## Change an Account's Bandwidth Limit in WHM
### 1. Log in to WHM
Sign in to WHM with your reseller or root credentials.
### 2. Open Limit Bandwidth Usage
Go to **Account Functions** >> **Limit Bandwidth Usage**, or type **Limit** into the menu filter box at the top left and click the result that appears.

### 3. Select the account
In the **Search Box**, type the cPanel username, or pick the account from the drop-down list. Then click **Limit**.
WHM shows a summary of the selected account first, including its IP address, owner, contact address, creation date, theme, package and disk usage. Check the username here before you change anything, because usernames on a busy server are often only a character or two apart.

### 4. Set the new limit and save
Under **Bandwidth Limit**, either tick the **Unlimited** option for an unmetered account, or type the new figure in megabytes into the text box. Click **Change** to save.

The new allowance applies to the current month and every month after it, until you change it again. Setting **Unlimited** removes the technical cap in cPanel only; the account is still bound by the terms of the hosting plan it sits on.
## What Happens When the Limit Is Reached
Once an account passes its monthly figure, cPanel applies a bandwidth limitation automatically. This is not the same thing as suspending an account, and the difference matters when a customer is on the phone:
- **Only web traffic stops.** The limitation applies to services reached over `http` and `https`. Visitors to the account's websites get a bandwidth limit exceeded page instead of the site.
- **Email, FTP and WebDAV keep working.** The account can still send and receive mail, and can still connect over FTP. That is why "my site is down but my email is fine" is so often a bandwidth limit rather than an outage or a suspension.
- **Nothing is deleted.** Files, databases and mailboxes are untouched. The limitation is a temporary block on serving the site, not a termination.
- **It clears itself at the start of the next month.** cPanel removes the limitation the first time it processes bandwidth statistics in the new month, at which point the account is no longer over its allowance.
Account suspension is a separate, manual action with different effects: a suspended site redirects to a suspension page, and the account's logins are locked. cPanel never suspends an account on its own for bandwidth. See [How to Suspend a cPanel User in the WHM Account](/whm/how-to-suspend-a-cpanel-user-in-the-whm-account/) if suspension is what you actually want.
## Lifting a Bandwidth Limitation Before Month End
If an account is already blocked and the customer needs the site back now, you have three options:
- **Raise that one account's limit** using the steps above. Set a figure above its current usage, not merely above the old limit.
- **Raise the package limit** under **Packages** >> **Edit a Package** if every account on that plan needs more. See [How to Edit a Hosting Package in WHM](/whm/how-to-edit-a-hosting-package-in-whm/).
- **Clear every blocked account at once** with **Account Functions** >> **Unsuspend Bandwidth Exceeders**. This releases all accounts currently held by a bandwidth limitation, so use it deliberately rather than as a routine fix.
**The timing gotcha:** cPanel only checks bandwidth limits once per day, in a run between midnight and 06:00. Raising a limit therefore does not always release a blocked site immediately. If the site is still showing the bandwidth page after you have raised the figure, use **Unsuspend Bandwidth Exceeders** to clear it straight away instead of waiting for the nightly run.
## Per-Account Limit Versus Package Limit
An account's bandwidth normally comes from its hosting package. **Limit Bandwidth Usage** writes a per-account override on top of that, which is convenient but has two consequences worth knowing:
- WHM will flag the account as differing from its package. That is expected, not an error, but it makes the account harder to reason about later.
- Re-applying the package to the account, for example by changing its package and changing it back, overwrites your custom figure with the package value.
Use a per-account override for a one-off or a temporary reprieve. If several customers keep needing more bandwidth, change the package instead, or move them onto a larger plan.
## Checking Usage Before You Set a Number
Pick the new figure from real numbers rather than guesswork. **Account Information** >> **View Bandwidth Usage** in WHM shows each account's transfer for the current month and its history, which tells you whether a spike is a one-off or a trend. Account holders can see their own figures from inside cPanel; see [How to Check Disk and Bandwidth Usage in cPanel](/cpanel/how-to-check-disk-and-bandwidth-usage-in-cpanel/).
Bear in mind that WHM's totals and the figures in log analysers such as AWStats or Webalizer are measured differently and will not match exactly. WHM's number is the one that enforces the limit.
## Troubleshooting
- **Symptom**: **Limit Bandwidth Usage** is missing from the WHM menu. The privilege is not enabled on your reseller account. Ask the server administrator to grant it under **Resellers** >> **Edit Reseller Nameservers and Privileges**.
- **Symptom**: the account is not in the list. Resellers only see accounts they own. Confirm the ownership of the account, or ask the server administrator to make the change.
- **Symptom**: the site is still blocked after raising the limit. The daily bandwidth check has not run yet. Use **Unsuspend Bandwidth Exceeders** to release it immediately.
- **Symptom**: the site is down but email still works. That pattern points to a bandwidth limitation rather than a suspension or a server fault. Check the account's usage under **View Bandwidth Usage**.
- **Symptom**: the account keeps hitting the limit every month. Look for the cause before raising the number again. Large uncompressed images and video served directly, hotlinked files, an unthrottled backup job pulling over HTTP, or aggressive bot traffic account for most surprise overages.
- **Symptom**: the custom figure reverted to the package value. The package was re-applied to the account. Set the value on the package itself, or re-apply the per-account override.
## Related Articles
- [How to Access the Web Host Manager or WHM](/whm/how-to-access-and-log-in-to-whm-web-host-manager/)
- [How to Edit a Hosting Package in WHM](/whm/how-to-edit-a-hosting-package-in-whm/)
- [How to Suspend a cPanel User in the WHM Account](/whm/how-to-suspend-a-cpanel-user-in-the-whm-account/)
- [How to Check Disk and Bandwidth Usage in cPanel](/cpanel/how-to-check-disk-and-bandwidth-usage-in-cpanel/)
If an account keeps exceeding its bandwidth and you want help working out what is consuming it, or you need a limit lifted outside the nightly check, open a ticket from the Noiz client area with the cPanel username and the Noiz support team will take a look with you.
# How to Remove a Feature List from WHM
Source: https://docs.noiz.ie/whm/how-to-remove-a-feature-list-from-whm/
A feature list in WHM is a named set of cPanel features (File Manager, Cron Jobs, Email Filters, and so on) that you attach to a hosting package. Deleting a list you no longer use keeps the Feature Manager tidy and stops stale lists being picked by mistake when a package is created. This guide is for Noiz reseller and dedicated customers who have WHM access.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel & WHM. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [WHM Feature Manager](https://docs.cpanel.net/whm/packages/feature-manager/) (full field reference)
- [WHM Edit a Package](https://docs.cpanel.net/whm/packages/edit-a-package/) (reassigning a package to a different feature list)
## Prerequisites
- A WHM login for your Noiz reseller or dedicated account.
- A reseller-created feature list you want gone. The built-in `default` and `disabled` lists are part of WHM and cannot be deleted.
- A quick check of which packages currently point at the list. See the warning below before you delete anything.
## Before You Delete: What Happens to Packages Using the List
This is the part the button does not tell you. A feature list is not owned by a package, it is referenced by it. When the list disappears, any package still pointing at it falls back to the `default` feature list, and every account created on that package from then on inherits the default feature set instead of the one you designed.
In practice that means features you had deliberately switched off can quietly come back, and features you had switched on for a premium package can quietly go away. Existing accounts keep working, but their available cPanel icons change to whatever `default` allows, which is the kind of thing that surfaces as a confused support ticket a week later rather than as an error on screen.
To avoid it, do this first:
1. Go to **Packages** >> **Edit a Package**.
2. Open each package in turn and look at the **Feature List** setting.
3. Any package pointing at the list you are about to remove should be reassigned to another list, or to `default` deliberately, and saved.
Once no package references the list, deleting it has no side effects at all. If you are removing a list because you want a different feature set instead, create the replacement list first, reassign the packages to it, and only then delete the old one. See [How to Create a Feature List in WHM](/whm/how-to-create-a-feature-list-in-whm/).
## Remove the Feature List
### 1. Log in to WHM
Sign in to WHM with your reseller or root credentials.
### 2. Open Feature Manager
Go to **Packages** >> **Feature Manager**, or type **Feature Manager** into the menu filter box at the top left and click the result.

### 3. Select the List to Remove
Under **Manage feature list**, choose the feature list you want to remove from the drop-down. Check the name carefully, because WHM does not show you which packages use it at this point.

### 4. Click Delete
Click **Delete** and confirm. WHM removes the list immediately, and the drop-down refreshes without it.
The feature list has now been removed. Deleting a list never deletes a package or an account, it only removes the named feature set.
## Troubleshooting
**Symptom**: The list you want is not in the drop-down. It has either already been deleted, or it belongs to a different reseller account. A reseller only sees the feature lists they own, plus the built-in ones.
**Symptom**: **Delete** is greyed out or refuses. You have selected `default` or `disabled`. These are built into WHM and cannot be removed. If you want to change what the default set allows, edit it rather than trying to delete it.
**Symptom**: Customers report cPanel icons appearing or disappearing after the deletion. A package was still pointing at the deleted list and has fallen back to `default`. Recreate the feature list with the settings you want, then reassign the affected packages under **Packages** >> **Edit a Package**.
**Symptom**: You need to change features for one account only, not for a whole package. Deleting or editing a feature list is the wrong tool for that. See [How to Enable/Disable Features of cPanel Account From WHM](/whm/how-to-enable-or-disable-cpanel-account-features-in-whm/).
## Related Articles
- [How to Create a Feature List in WHM](/whm/how-to-create-a-feature-list-in-whm/)
- [How to Enable/Disable Features of cPanel Account From WHM](/whm/how-to-enable-or-disable-cpanel-account-features-in-whm/)
- [How to Delete a Package in WHM](/whm/how-to-delete-a-package-in-whm/)
If you are unsure which packages reference a feature list, or an account has lost features after a change, open a ticket from your Noiz client area and the Noiz support team will check the package and feature list mapping on your server for you.
# How to Set Up Custom Private Nameservers in WHM
Source: https://docs.noiz.ie/whm/how-to-set-up-custom-private-nameservers-in-whm/
Private nameservers (also called custom nameservers, branded nameservers or child nameservers) let you hand your clients `ns1.yourdomain.com` and `ns2.yourdomain.com` instead of your provider's nameservers. This guide shows you how to set them in WHM, and, just as importantly, what has to be in place at your domain registrar first so that they actually resolve.
You need this article if you have a reseller, VPS or dedicated server with WHM access. If you are on Noiz shared hosting and simply need the nameservers to point a domain at your account, you do not need private nameservers at all: use `ns1.noiz.co.za` and `ns2.noiz.co.za`.
**Last reviewed:** 27 July 2026, against the current stable cPanel & WHM release. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [WHM: Basic WebHost Manager Setup](https://docs.cpanel.net/whm/server-configuration/basic-webhost-manager-setup/) (the interface used in this guide)
- [WHM: DNS Zone Manager](https://docs.cpanel.net/whm/dns-functions/dns-zone-manager/) (creating and editing the A records your nameservers need)
- [WHM: Nameserver Selection](https://docs.cpanel.net/whm/service-configuration/nameserver-selection/) (which DNS server software the machine runs)
- [WHM: DNS Cluster](https://docs.cpanel.net/whm/clusters/dns-cluster/) (if your nameservers live on more than one machine)
- [cPanel product versions and the release process](https://docs.cpanel.net/knowledge-base/cpanel-product/product-versions-and-the-release-process/)
## Prerequisites
- WHM access, either as root or as a reseller with the **Basic WebHost Manager Setup** privilege.
- A domain you control that will carry the nameserver hostnames, for example `yourdomain.com`. Replace this placeholder with your own domain everywhere below.
- Access to that domain's registrar control panel, so that you can register the nameserver hostnames as host records.
- The public IP address (or addresses) your nameservers will answer on.
## Understand the Three Pieces First
This is where most private nameserver setups go wrong. Setting the values in WHM is only one of three pieces, and on its own it does nothing for the outside world. All three have to line up:
1. **Registration at the registrar.** The hostnames `ns1.yourdomain.com` and `ns2.yourdomain.com` must be registered as host records (often labelled "register a nameserver", "child nameservers", "host records" or "glue records") against the parent domain, each mapped to an IP address. Without this the wider internet has no way to find your nameservers, because it would have to ask your nameservers where your nameservers are.
2. **A records on the server.** The DNS zone for `yourdomain.com` on your server needs A records for `ns1` and `ns2` pointing at the same IPs you registered. Add AAAA records too if you serve IPv6.
3. **The WHM setting.** This tells WHM which nameservers to write into the DNS zones of accounts you create from that point on, and which nameservers to display to your clients.
Do the registrar step first if you can. Registrar host records can take up to 24 hours to appear in the registry, so starting there means the delay runs in the background while you finish the server side.
## Set the Nameservers in WHM
### 1. Log in to WHM
Sign in at `https://yourdomain.com:2087`, or at the hostname or IP address Noiz supplied for your server. Use your root credentials, or your reseller credentials if you are a reseller.
### 2. Open Basic WebHost Manager Setup
Go to **Server Configuration** ยป **Basic WebHost Managerยฎ Setup**. The quickest route is to type `Basic` into the menu filter box at the top left of the WHM sidebar and click the result.

### 3. Choose Explicitly Set the Nameservers and enter your values
Scroll to the **Nameservers** section. Depending on your cPanel & WHM version and whether you are logged in as root or as a reseller, you will either see the nameserver fields straight away, or a selector that you must set first:
- **Explicitly Set the Nameservers**: choose this. It is the option that lets you type your own hostnames.
- **Inherit Nameservers from root** (resellers only): the reseller uses whatever the server owner has configured. Leave this if you do not have your own branded nameservers.
- **Configure Automatically Based on IP Addresses** or **Disable Nameservers** (root only): neither of these gives you branded nameservers.
Enter your hostnames in the **Primary** and **Secondary** nameserver boxes, for example `ns1.yourdomain.com` and `ns2.yourdomain.com`. The **Tertiary** and **Quaternary** boxes are optional and can be left empty. Then click **Save Changes**.

### 4. Configure the address records
Next to each nameserver field WHM offers a **Configure Address Records** control. Use it to create the A record (and the AAAA record, if you run IPv6) that maps each nameserver hostname to its IP address. WHM writes these into the DNS zone for `yourdomain.com` on the server.
If the zone for `yourdomain.com` is not hosted on this server, WHM cannot create the records for you. Add them manually wherever that zone actually lives, whether that is another server or an external DNS provider.
## Register the Nameservers at Your Registrar
Log in to the registrar that holds `yourdomain.com` and find the section for registering nameservers. The wording varies by registrar, but look for "Register a Nameserver", "Child Nameservers", "Host Records", "Private Nameservers" or "Glue Records".
Create one entry per nameserver:
- `ns1.yourdomain.com` pointing to your first IP address
- `ns2.yourdomain.com` pointing to your second IP address
Once the host records exist, set the domain's own nameservers to `ns1.yourdomain.com` and `ns2.yourdomain.com` if you want the domain itself served by them. This is a separate field from the host record registration, and forgetting it is a common cause of "I registered them but nothing changed".
**Note:** some registries require two nameservers on distinct IP addresses and will reject a pair that shares one IP. If you only have a single IP, ask Noiz support about an additional address, or point the second nameserver at a secondary DNS service.
## What This Setting Does and Does Not Do
- **It applies going forward.** The nameservers you save become the default written into DNS zones for accounts you create (or migrate in) after the change. Zones that already exist keep their old NS records until you update them.
- **Existing accounts need updating separately.** Edit each zone in **WHM** ยป **DNS Functions** ยป **DNS Zone Manager**, or ask Noiz support to run a bulk update across your accounts.
- **The domains themselves still have to be pointed.** A client's domain only starts using your nameservers once the NS records are changed at that domain's registrar.
- **It does not create the DNS service.** Your server must actually be running a DNS server. Check **WHM** ยป **Service Configuration** ยป **Nameserver Selection** if in doubt.
## Verify the Setup
Give the change time to propagate, then confirm from a machine outside your server. Domain propagation commonly takes a few hours and can take up to 24 to 48 hours, depending on the previous TTL values and the registry involved.
```
dig +short ns1.yourdomain.com
dig +short ns2.yourdomain.com
dig +short NS yourdomain.com
dig @ns1.yourdomain.com yourdomain.com SOA
```
The first two should return your IP addresses. The third should list your nameserver hostnames. The last confirms your nameserver is answering authoritatively for the zone rather than merely being reachable.
## Troubleshooting
**Symptom**: the nameservers resolve for you but not for clients. Your local resolver has cached the old answer, or propagation is still in progress. Test from an external DNS lookup service and wait out the TTL before changing anything else.
**Symptom**: the registrar rejects the host record with "nameserver already exists" or similar. The hostname is already registered, often from a previous setup. Edit the existing host record's IP address rather than creating a new one.
**Symptom**: `dig NS yourdomain.com` returns the old nameservers long after the change. The domain's NS delegation at the registrar was never updated, or the registry has not published it yet. Registering host records and delegating the domain are two separate actions.
**Symptom**: new accounts still get the old nameservers. Confirm you clicked **Save Changes**, and if you are a reseller confirm the selector is on **Explicitly Set the Nameservers** rather than inheriting from root.
**Symptom**: queries to the nameserver IP time out. A firewall is blocking DNS. Port 53 must be open on both UDP and TCP; blocking TCP breaks larger responses and zone behaviour even though small queries appear to work.
## Need a Hand?
Private nameservers touch the registrar, the registry and the server at the same time, which makes them one of the easier things to get half right. If yours are not resolving, open a ticket from the Noiz client area with your domain name and the nameserver hostnames you configured, and the Noiz team will check the delegation and the server side together. On Noiz managed plans the team can set the whole chain up for you.
# How to Suspend a cPanel User in the WHM Account
Source: https://docs.noiz.ie/whm/how-to-suspend-a-cpanel-user-in-the-whm-account/
Suspending a cPanel account is the reversible way to take a hosting account offline. It is the standard response to non-payment, abuse, a compromised site, or a customer who has asked to pause their service. This guide shows you how to suspend an account from WHM, explains exactly what a suspension does to the websites, mail and FTP on that account, and covers the gotchas that catch resellers out.
If you are a Noiz reseller, you can suspend any cPanel account you own from your own WHM login. You do not need to contact Noiz support to do it, and nothing is deleted.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel & WHM. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [WHM: Manage Account Suspension](https://docs.cpanel.net/whm/account-functions/manage-account-suspension/)
- [WHM: List Suspended Accounts](https://docs.cpanel.net/whm/account-information/list-suspended-accounts/)
- [WHM: Unsuspend Bandwidth Exceeders](https://docs.cpanel.net/whm/account-functions/unsuspend-bandwidth-exceeders/)
- [WHM API: `suspendacct`](https://api.docs.cpanel.net/openapi/whm/operation/suspendacct/)
## Prerequisites
- A Noiz reseller account with WHM access. See [How to Access the Web Host Manager or WHM](/whm/how-to-access-and-log-in-to-whm-web-host-manager/).
- The account you want to suspend must be owned by your reseller account. WHM only lists accounts you own.
- The **Suspend or Unsuspend Accounts** privilege enabled on your reseller ACL. This is on by default on Noiz reseller plans.
## What a Suspension Actually Does
Suspension is a lock, not a deletion. Every file, mailbox, database and DNS record stays exactly where it is. What changes is access:
- **Websites**: visitors no longer see the site. cPanel serves a suspended-account placeholder page instead of the document root, for the main domain and every addon domain, subdomain and parked domain on the account.
- **Email**: inbound mail for the account's domains is refused, and the account cannot send. Existing mailboxes and their contents are untouched, so nothing already delivered is lost. Mail that arrives during the suspension is rejected at the door rather than queued indefinitely, so senders will get a bounce.
- **FTP and SSH**: the underlying system user is locked. FTP logins fail, SFTP and SSH sessions are refused, and any active session is cut off.
- **cPanel login**: the account holder can no longer log in to cPanel or Webmail.
- **Cron jobs**: scheduled tasks owned by the account stop running. This matters for sites that rely on cron for queues, backups or scheduled publishing, because those jobs do not catch up when the account is restored.
- **DNS**: the zone stays live and the domain keeps resolving. That is why visitors reach a suspension page rather than a connection error.
- **Databases**: databases and their data are left intact.
**Suspension is reversible. Termination is not.** If there is any chance the customer will return, suspend the account and leave it suspended. Never terminate as a first step, because termination removes the account and its data permanently.
## How to Suspend a cPanel Account in WHM
1. Log in to your WHM account.
2. Go to **Account Functions** >> **Manage Account Suspension**, or type **Manage Account** into the menu filter box at the top left and click the result. 
3. Choose the account you want to suspend. You can pick it under **Select by domain** or under **Select by username**, whichever you know. Both lists refer to the same accounts, so use the one that is quicker for you. 
4. Type a suspension reason. This is optional, but always fill it in. The reason is stored against the account and shown to anyone in WHM who looks at it later, which is how you and your colleagues remember why an account was locked six months ago. Use something specific, such as `Unpaid invoice 10432, suspended 26 July 2026`, rather than `overdue`.
5. If the option to prevent automatic unsuspension is shown, tick it when the suspension must stay in place regardless of bandwidth resets. This stops WHM's automatic bandwidth-exceeder unsuspension from lifting a suspension you applied for a different reason, such as non-payment or abuse.
6. Click **Suspend**. WHM confirms with a suspension message and the account is locked immediately. There is no delay and no server restart involved.
## Confirming the Suspension
- In WHM, open **Account Information** >> **List Suspended Accounts** to see every account you currently have suspended, along with the reason and the date. Review this list periodically so accounts do not sit suspended and forgotten while still consuming disk space.
- In **Account Information** >> **List Accounts**, suspended accounts are flagged in the account list.
- Load the customer's domain in a private browsing window. You should get the suspended-account page rather than the site.
## Things Worth Knowing Before You Suspend
- **Suspension does not free up resources.** The account's files, mailboxes and databases remain on disk and still count towards your reseller disk allocation. If you are suspending to reclaim space, you are not going to.
- **AutoSSL skips suspended accounts.** A long suspension that spans a certificate renewal window can leave the domain with an expired certificate when the account is restored. If a suspension runs for weeks, check the certificate status after unsuspending.
- **Check your backup policy.** WHM's backup configuration has a setting that controls whether suspended accounts are included in backups. If it excludes them, a long-suspended account gradually loses its backup history. Confirm the setting before you suspend an account you may need to restore later.
- **You cannot suspend part of an account.** Suspension applies to the whole cPanel account, so every addon domain and subdomain on it goes down together. If a customer runs several sites under one account, suspending it takes all of them offline.
- **Warn the customer first where you can.** A suspension that arrives with no notice generates a support ticket within minutes, and inbound mail bounces immediately rather than waiting for the customer to notice. For non-payment, send a reminder with a date attached, then suspend on that date.
- **Consider a bandwidth limit instead.** Where the issue is a resource-hungry site rather than a policy or payment problem, capping the account may be a better answer than taking it offline. See [How to Limit Bandwidth Usage of cPanel User From WHM](/whm/how-to-limit-bandwidth-usage-for-a-cpanel-account-in-whm/).
## Reversing the Suspension
Unsuspending restores everything at once: the website, mail, FTP, SSH, cPanel login and cron jobs all come back with no data loss. The steps are covered in [How to Unsuspend cPanel User From WHM Account](/whm/how-to-unsuspend-a-cpanel-account-in-whm/).
## Troubleshooting
**Symptom**: the account you want does not appear in either drop-down list. You are logged in to the wrong reseller account, or the account is owned by a different reseller. WHM only shows accounts your login owns.
**Symptom**: **Manage Account Suspension** is missing from the menu, or the **Suspend** button does nothing. Your reseller ACL does not include the suspend privilege. Contact Noiz support to have it enabled.
**Symptom**: the site still loads after suspension. This is almost always caching. Test in a private browsing window, and if the domain is proxied through a CDN, purge the CDN cache. A CDN can keep serving a cached copy of the site long after the origin has been locked.
**Symptom**: mail is still being delivered. The domain's MX records point somewhere other than the hosting account, so mail never touches the suspended account. Suspension only stops mail that is handled on the server.
**Symptom**: the account was suspended automatically and you did not do it. Automatic suspensions come from bandwidth limits being exceeded. Check the account's bandwidth usage before unsuspending, or the same suspension will recur.
**Symptom**: you cannot find your own reseller account in the list. You cannot suspend the account you are logged in with. If a reseller account itself needs to be suspended, that has to be done at the server level by Noiz.
## Need a Hand?
If an account will not suspend, a suspension is not behaving as expected, or you need a reseller privilege changed, open a ticket from the [Noiz client area](https://www.noiz.co.za/clientarea.php) with the affected username and domain. Noiz support has server-level access and can confirm what state the account is actually in.
# How to Unsuspend a cPanel Account in WHM
Source: https://docs.noiz.ie/whm/how-to-unsuspend-a-cpanel-account-in-whm/
Unsuspending a cPanel account in WHM lifts a suspension and puts the account back into normal service: the website loads again instead of the Account Suspended page, cPanel and FTP logins work, and mail delivery resumes. Nothing is restored from backup, because nothing was deleted. Suspension only switches an account off. This guide is for Noiz reseller and dedicated customers who have WHM access.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel & WHM. This guide is written for Noiz hosting and is kept current against cPanel & WHM. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [WHM Manage Account Suspension](https://docs.cpanel.net/whm/account-functions/manage-account-suspension/) (full field reference and interface limitations)
- [What Happens When You Suspend an Account](https://docs.cpanel.net/knowledge-base/accounts/what-happens-when-you-suspend-an-account/) (exactly which services stop)
- [Account Suspension Versus Bandwidth Limiting and Account Termination](https://docs.cpanel.net/knowledge-base/accounts/account-suspension-versus-bandwidth-limiting-and-account-termination/)
- [WHM List Suspended Accounts](https://docs.cpanel.net/whm/account-information/list-suspended-accounts/) (finding every suspended account at once)
## Prerequisites
- A WHM login for your Noiz reseller or dedicated account.
- The username or primary domain of the account you want back in service.
- Confidence that whatever caused the suspension has been dealt with. Read the next section before you click anything.
## Deal With the Cause First
Unsuspending is a ten second job. Deciding whether to unsuspend is the part worth thinking about, because an account that goes back online with the original problem still present usually ends up suspended again, sometimes within the hour.
- **Suspended for non-payment.** If your billing system suspended the account automatically, unsuspending it by hand in WHM does not tell the billing system anything. The account status in billing stays as suspended, and the next automation run can simply suspend it again. Settle or write off the invoice and unsuspend from the billing side, so that both systems agree.
- **Suspended for abuse, spam or a compromise.** Clean the account first. Rotate the cPanel and email passwords, remove the malicious files, and update the outdated plugin or theme that let it in. Putting a compromised account straight back online tends to produce a second suspension plus a damaged sending reputation.
- **Suspended for resource usage.** Confirm the account is under its disk and inode limits before restoring it, otherwise the first thing the customer sees is a site that loads and immediately breaks on writes.
If you are unsuspending purely because a customer has paid or an investigation has closed, none of this applies and you can go straight to the steps below.
## Unsuspend the Account
### 1. Log in to WHM
Sign in to WHM with your reseller or root credentials.
### 2. Open Manage Account Suspension
Go to **Account Functions** >> **Manage Account Suspension**, or type **Manage Account** into the menu filter box at the top left and click the result when it appears.

### 3. Select the Suspended Account
Pick the account under **Select by domain** or **Select by username**, whichever you know. Both lists cover the same accounts.
WHM colour codes this list, and the colour is the quickest way to confirm you have the right account. Active accounts are shown in white or plain text. **Suspended accounts are shown in red.** When you are unsuspending, red is exactly what you are looking for. If the account you expected to fix is not red, it is not currently suspended, and whatever is wrong with it has another cause.

### 4. Click Unsuspend
Leave **Retain Service Proxying** unticked unless you specifically set service proxying up for this account and want it kept. Almost nobody needs it, and the safe default is to leave it alone.
Click **Unsuspend**. WHM restores the account and reports success, or shows an error explaining why it could not.
## What Happens the Moment You Unsuspend
The change is immediate on the server, and no data has to be restored:
- The Account Suspended page stops being served and the real site loads again.
- The cPanel and FTP passwords start working again. Suspension does not change the customer's password, it invalidates the stored hash, so unsuspension brings the original password back. There is no need to issue a new one.
- Incoming mail is accepted again, and cron jobs, databases and shell access return to whatever state they were in before the suspension.
The one thing that does not come back is mail that arrived while the account was suspended. Depending on how the server is configured to treat mail for suspended accounts, those messages were either queued, bounced or rejected outright. Anything rejected or bounced is gone, and the sender will have received a failure notice. It is worth telling the customer to expect a gap rather than letting them discover it.
## Troubleshooting
**Symptom**: **Unsuspend** fails, or WHM says only a root user can unsuspend this account. The account was locked when it was suspended, using the option that prevents resellers from unsuspending. That is deliberate, and it is usually set when the suspension came from the server administrator rather than from you. Open a ticket with Noiz support rather than trying to work around it.
**Symptom**: The account is not in the list at all. You are signed in as a reseller and the account belongs to a different reseller, or it has been terminated rather than suspended. Termination deletes the account and its data, and there is nothing to unsuspend.
**Symptom**: The account is not shown in red, but the site is still down. It is not suspended. Check for a bandwidth limit instead. Bandwidth limiting and suspension are separate mechanisms in WHM, and **Manage Account Suspension** will not clear a bandwidth block. Use **Account Functions** >> **Unsuspend Bandwidth Exceeders** for that, or check DNS and the site's own error logs if bandwidth is not the issue.
**Symptom**: The suspended page still appears after a successful unsuspension. It is almost always cached, either in the browser or at a CDN in front of the site. Do a hard refresh, try a private window, and purge the CDN cache if the domain sits behind one.
**Symptom**: The account is suspended again a few hours later. Something automated is putting it back. That is normally a billing system acting on an unpaid invoice, or an abuse rule that has re-triggered because the underlying problem was never fixed.
## Related Articles
- [How to Suspend a cPanel User in the WHM Account](/whm/how-to-suspend-a-cpanel-user-in-the-whm-account/)
- [How to Limit Bandwidth Usage of cPanel User From WHM](/whm/how-to-limit-bandwidth-usage-for-a-cpanel-account-in-whm/)
If an account will not unsuspend, keeps re-suspending, or you are not sure why it was suspended in the first place, open a ticket from your Noiz client area. The Noiz support team can read the suspension reason and the server logs for that account and tell you exactly what triggered it.
# How to Access Your Email From DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-access-your-email-from-directadmin/
Webmail lets you read and send mail from your Noiz mailbox in an ordinary browser, with nothing to install and nothing to configure. This guide shows you the two ways to reach it from DirectAdmin: a one-click sign in from inside the control panel, and a direct sign in using the mailbox address and password.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: Webmail](https://docs.directadmin.com/other-hosting-services/webmail/) (covers one-click, or single sign-on, webmail login).
- [DirectAdmin Docs: Autodiscover information for mail clients](https://docs.directadmin.com/other-hosting-services/email/autodiscover.html) (for setting the same mailbox up in a desktop or phone mail app).
- [Roundcube User Guide](https://github.com/roundcube/roundcubemail/wiki/User-Guide) (what the webmail interface itself can do once you are signed in).
## Prerequisites
- A Noiz hosting plan on DirectAdmin, and the DirectAdmin sign-in URL and credentials from your Noiz welcome email. DirectAdmin normally answers on port `2222`, for example `https://yourdomain.com:2222` (replace `yourdomain.com` with your own domain).
- At least one mailbox already created. If you have not made one yet, see [How to Create an Email Account in DirectAdmin](/directadmin/how-to-create-an-email-account-in-directadmin/).
- For Method 2 only: the mailbox password. If it has been lost, see [How to Change an Email Account's Password in DirectAdmin](/directadmin/how-to-change-an-email-accounts-password-in-directadmin/).
## Which Method Should You Use?
Both methods open the same mailbox in the same webmail application. The difference is who is signing in and what they hold:
- **Method 1 (one-click)** suits you, the account holder. You are already signed in to DirectAdmin, so DirectAdmin hands you straight through to the mailbox without asking for the mailbox password again. This is handy when you administer several mailboxes and do not memorise each password.
- **Method 2 (direct sign in)** suits everyone else, and suits you when you are away from the control panel. A staff member who has a mailbox but no DirectAdmin login uses this route, and so does any device where you would rather not sign in to the control panel at all.
## Method 1: One-Click Sign In From DirectAdmin
### Step 1: Open the E-mail Accounts page
Sign in to DirectAdmin. In the **E-mail Manager** section, click **E-mail Accounts**. If you cannot see the section, type **E-mail Accounts** into the navigation filter box at the top of the sidebar and the item will appear.

### Step 2: Expand the mailbox row
The **Account list** shows every mailbox on the domain. Each row carries a **plus icon** on the right-hand side, which reveals the per-mailbox actions.

### Step 3: Sign in to webmail
Click the **plus icon**, then click **Sign In to Webmail**.

### Step 4: Allow the popup
Webmail opens in a new tab or window, so your browser may block it the first time and show a popup notice in the address bar. Allow the popup and you are taken straight into the mailbox, with no password prompt.
This pass-through is DirectAdmin's single sign-on feature, added in DirectAdmin 1.59.0. It works by issuing a short-lived, one-time token, which is why the resulting webmail address is useless as a bookmark: return to DirectAdmin and click **Sign In to Webmail** again each time.
## Method 2: Sign In to Webmail Directly
### Step 1: Open webmail
From inside DirectAdmin, look in the **Extra Features** section and click the **Roundcube** icon, or type **Webmail** into the navigation filter box.

You do not have to go through the panel at all. Once you know the webmail address for your domain, bookmark it and share it with the person who owns the mailbox. Many DirectAdmin servers publish a shortcut at `webmail.yourdomain.com`; if that address does not resolve for your domain, open webmail once through DirectAdmin and copy the address from your browser's address bar.
### Step 2: Enter the mailbox credentials
Enter the **full email address** as the username, for example `you@yourdomain.com`, and then the mailbox password. Entering only the part before the `@` is the single most common reason a correct password is rejected.

### Step 3: Click Login
Click **Login**. You can now read, reply to, forward and file mail, and manage folders, contacts and an out-of-office reply, entirely in the browser.
### A Note on SquirrelMail
Older guides and older screenshots offer a choice between SquirrelMail and Roundcube at this point. Noiz servers now offer **Roundcube** only. SquirrelMail has not had a maintained release in many years, and DirectAdmin's own documentation now describes it as outdated and installs Roundcube on new servers, so it was retired rather than left running unpatched. If you have an old SquirrelMail bookmark, replace it: the mailbox, the folders and the mail are unchanged, only the interface in front of them differs.
## Webmail Is Not a Substitute for a Mail Client
Webmail is ideal for occasional access, for a machine that is not yours, and for confirming quickly that mail is arriving at the server rather than being lost in transit. For daily use on your own devices, connect the mailbox to a proper mail client over **IMAP** instead. IMAP keeps the mail on the server and mirrors the same folders across your laptop and phone, so nothing is trapped on one device. DirectAdmin lists the exact incoming and outgoing server settings for each mailbox in the **E-mail Accounts** page.
One caution if you are migrating a domain to Noiz: webmail always shows you the mailbox on the server your domain's DNS currently points at. If mail seems to be missing, check where the domain's MX records resolve before assuming it has been deleted.
## Troubleshooting
**Symptom: clicking Sign In to Webmail does nothing.** The browser blocked the new window. Look for a blocked-popup icon in the address bar, allow popups for the DirectAdmin address, then click the link again.
**Symptom: "Login failed" or "Invalid username or password" in Roundcube.** Use the full email address as the username, not the mailbox name on its own. If it still fails, reset the mailbox password in DirectAdmin and try the new one immediately, so a saved password in the browser cannot overwrite what you typed.
**Symptom: the webmail link worked yesterday but not today.** You bookmarked a one-click sign-in URL. Those tokens expire by design. Bookmark the plain webmail sign-in page instead, or start from DirectAdmin each time.
**Symptom: the mailbox is not in the Account list.** Check the domain selector at the top of DirectAdmin. On accounts holding several domains, the list only shows mailboxes for the domain currently selected.
**Symptom: you can read mail but sending fails.** That usually points at a sending limit or an outbound block rather than at webmail. Check the mailbox's sending limit first, then contact Noiz support if the limit is not the cause.
**Symptom: the browser warns the connection is not private.** Do not enter the password. Reach webmail through DirectAdmin instead, and let Noiz support know which address produced the warning.
## Need a Hand?
If webmail will not accept a password you know is correct, or mail is reaching the server but not reaching you, open a ticket with Noiz support from the client area. Include the full mailbox address and the exact wording of any error, and the Noiz team will check the mailbox on the server directly.
# How to Add a Subdomain in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-add-a-subdomain-in-directadmin/
A subdomain is an extra name in front of a domain you already host, separated by a dot. If your site is `yourdomain.com`, then `blog.yourdomain.com`, `shop.yourdomain.com` and `staging.yourdomain.com` are all subdomains of it. They cost nothing extra, they do not have to be registered anywhere, and they are the standard way to run a second site, a test copy or a separate application alongside your main website. Read `yourdomain.com` throughout as your own domain name.
This guide shows you how to create one on your Noiz DirectAdmin hosting account, where DirectAdmin puts the files, and the two things that catch people out afterwards: the certificate and the wait.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: the Evolution skin](https://docs.directadmin.com/directadmin/skins-and-templates/evolution.html)
- [DirectAdmin Docs: DNS](https://docs.directadmin.com/other-hosting-services/dns/index.html)
- [DirectAdmin Docs: ACME and SSL certificates for domains](https://docs.directadmin.com/webservices/ssl/ssl-and-letsencrypt-for-domains.html)
- [DirectAdmin changelog 1.648: choosing a document root when adding a subdomain](https://docs.directadmin.com/changelog/version-1.648.html)
## Prerequisites
- An active Noiz DirectAdmin hosting account, and your DirectAdmin username and password.
- The parent domain already set up on the account. A subdomain attaches to a domain that exists, it does not create one.
- The parent domain resolving to your hosting, normally through the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za`.
- A free subdomain allowance on your hosting package. Most packages allow a generous number, some allow unlimited, and a few are capped.
## Create the Subdomain
1. Log in to your DirectAdmin account.
2. In the **Account Manager** section, click **Subdomain Management**. If you cannot see it in the menu, type `Subdomain` into the navigation filter box at the top of the sidebar and the option appears. Click it. 
3. Click **Add Subdomain**, at the top right of the page. 
4. Under **Subdomain**, type the prefix only. To create `blog.yourdomain.com`, enter `blog`, not the whole address. The parent domain is shown beside the field and is added for you. If your account holds more than one domain, check the domain selector at the top of the page before you type. The subdomain is created under whichever domain is currently selected. 
5. Leave the document root at its default unless you have a reason to change it. DirectAdmin offers a choice here: the traditional location inside the parent domain's web folder, or a separate folder of your own. The default is the safe answer for almost everyone, and the section below explains what the difference means in practice.
6. Click **Add Subdomain**.
A success message confirms the subdomain has been created, and it appears in the list on the Subdomain Management page. Allow a few minutes before it responds in a browser.
## Where the Files Go
With the default document root, DirectAdmin creates a folder named after the subdomain inside your main web folder. For `blog.yourdomain.com` that is:
```
domains/yourdomain.com/public_html/blog/
```
Upload the subdomain's site into that folder using the DirectAdmin File Manager or FTP. Anything already sitting in a folder of that name is picked up immediately, which is why an existing folder can make a brand new subdomain load unexpected content.
One consequence of the default layout surprises people: the same files are reachable by two addresses. `blog.yourdomain.com` and `yourdomain.com/blog` both serve that folder. That is usually harmless, but if the subdomain is a real site rather than a section of the main one, search engines seeing two addresses for identical content is untidy. Either set a canonical address inside the application, or choose a document root outside `public_html` when you create the subdomain so only the subdomain name reaches it.
## Things Worth Knowing
- **The DNS record is created for you.** Because Noiz hosts the parent domain's DNS zone, DirectAdmin adds the record for the new name automatically. You do not need to touch DNS at your registrar for a subdomain. The exception is if you have moved the domain's DNS to a third party such as Cloudflare, in which case the zone that counts lives there and you must add an `A` record for the subdomain yourself, pointing at your hosting IP address.
- **Give it five minutes.** A newly created subdomain is not instant. The web server configuration has to be written and reloaded, and DNS caches need a moment. If it does not answer straight away, that is normal rather than a fault.
- **HTTPS is a separate step.** A certificate issued for `yourdomain.com` and `www.yourdomain.com` does not cover `blog.yourdomain.com`. Visitors reaching the subdomain over `https://` will see a certificate name mismatch warning until you reissue. Go to **SSL Certificates** under **Account Manager**, select the parent domain, and tick the new subdomain in the list of names to include before requesting the certificate. The subdomain must already resolve for validation to succeed, so create it first and issue the certificate afterwards.
- **Nested subdomains work.** DirectAdmin accepts multiple levels, such as `dev.blog.yourdomain.com`. Enter the whole prefix, `dev.blog`, in the Subdomain field. Bear in mind that a standard certificate covering `*.yourdomain.com` does not cover a second level, because a wildcard matches one label only.
- **Email is not affected.** Creating a subdomain does not create mailboxes on it and does not change mail for the parent domain. Subdomains are a web feature.
- **Prefix rules.** Use letters, numbers and hyphens. No underscores, no spaces, no leading or trailing hyphen. Avoid names already used as system hosts, such as `mail`, `ftp`, `webmail` and `ns1`, because those already exist in the zone and creating a subdomain with the same name will collide with the service.
- **Deleting is not automatic housekeeping.** Removing a subdomain later gives you the choice of deleting its folder or keeping it. Leaving the files behind is useful when you are only taking a site offline, but they still count against your disk quota.
## Troubleshooting
- **Symptom**: the subdomain shows the main website instead of its own content. The folder is empty, so the server has fallen back to the parent site or to a default page. Upload the subdomain's files into `public_html/subdomain-name/` and it will serve them.
- **Symptom**: the browser reports "server not found". Either the subdomain has not finished being set up, or the domain's DNS is hosted somewhere other than Noiz. Wait five minutes first. If it still fails and you use an external DNS provider, add the `A` record for the subdomain there.
- **Symptom**: a certificate warning naming the wrong site. Expected until the certificate is reissued to include the subdomain. Reissue it from **SSL Certificates** with the subdomain ticked.
- **Symptom**: DirectAdmin refuses to create it and reports that the subdomain already exists. The name is already present in the DNS zone or as a subdomain on the account. Check the Subdomain Management list, and check the DNS records for the parent domain for an existing entry with that name.
- **Symptom**: the **Add Subdomain** button is missing, or creation fails on a limit message. The package allowance for subdomains is used up. Open a ticket with Noiz support about raising it, or remove a subdomain you no longer need.
- **Symptom**: a content management system on the subdomain redirects to the main domain. The application stores its own site address and rewrites requests to it. Update the site address inside the application, not in DirectAdmin.
## Related Guides
- [How to Remove Subdomain in DirectAdmin](/directadmin/how-to-remove-a-subdomain-in-directadmin/)
- [How to Create a Domain Alias in DirectAdmin](/directadmin/how-to-create-a-domain-alias-in-directadmin/)
- [How to Create a Domain Pointer in DirectAdmin](/directadmin/how-to-create-a-domain-pointer-in-directadmin/)
## Need a Hand?
If the subdomain is created but will not load, or you need the certificate reissued to cover it, open a ticket from your Noiz client area. Include the full subdomain name and what you expect to see, and the support team will check the zone, the web server configuration and the certificate for you.
# How to Block Emails by Size Using Spam Filters in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-block-emails-by-size-using-spam-filters-in-directadmin/
DirectAdmin lets you reject incoming mail that is larger than a size you choose, using the **SPAM Filters** tool in the E-Mail Manager. This guide shows you how to set that rule on Noiz DirectAdmin hosting, and, just as importantly, how to pick a threshold that stops bulk rubbish without bouncing the invoices and artwork your customers actually send you.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its default Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: Filtering incoming spam](https://docs.directadmin.com/other-hosting-services/preventing-spam/incoming-spam.html)
- [DirectAdmin Docs: E-mail troubleshooting](https://docs.directadmin.com/other-hosting-services/email/troubleshooting.html)
## Prerequisites
- Login details for your DirectAdmin account on Noiz hosting.
- At least one domain with email hosted on the account.
- A decision on the largest message you are willing to accept. Read the sizing section below before you commit to a number.
## What the Size Filter Actually Does
The size filter is applied per domain, not per mailbox. Once you set it, every address on that domain is covered, including any catch-all, forwarders and aliases. There is no way to exempt a single mailbox from within this tool.
The rule is enforced while the message is still being delivered, so an oversized message is refused rather than accepted and quietly binned. That has two consequences worth knowing before you switch it on:
- **The sender is told.** A size limit is normally enforced while the message is still being transferred, so a genuine correspondent will often get a delivery failure telling them the message was too large. Do not rely on that, though: whether a notice reaches the sender depends on their mail server, so treat a blocked message as one they may never know about. That is better than silence, but it still means someone has to try again another way.
- **Nothing is kept.** A blocked message is not held in a quarantine, a spam folder or a queue. It cannot be released or recovered afterwards. If you block something you needed, the only remedy is to raise or remove the limit and ask the sender to resend.
The filter applies to mail arriving at the domain. It has no effect on messages you send out.
## How to Block Emails by Size in DirectAdmin
### Step 1: Open SPAM Filters
1. Log in to your DirectAdmin account.
2. In the **E-Mail Manager** section, click **SPAM Filters**. If you cannot see the section, type `SPAM Filters` into the navigation filter box at the top of the menu and the entry will appear. Click it.

### Step 2: Choose the domain and the rule type
1. If the account holds more than one domain, select the domain the rule should apply to from the domain selector at the top of the page. Rules do not carry across domains, so repeat the process for each one you want protected.
2. Under **Block By**, choose **Size** from the drop-down menu.
### Step 3: Set the size and save
1. In **Value**, choose the unit, **KB** or **MB**, and enter the number.
2. Click **Block**.

The rule takes effect on the next message that arrives, and the new entry is listed on the same page so you can review or remove it later. If you enter **MB** and the value `5`, every incoming message larger than 5 MB is refused.
## Choosing a Size Limit That Will Not Break Legitimate Mail
This is where most people get caught out. The limit is measured against the *whole message* as it travels over the wire, not against the size of the file the sender picked off their desktop.
- **Attachments are inflated in transit.** Files are encoded for email transport, and that encoding adds roughly a third to their size. A 5 MB PDF typically arrives as about 6.8 MB of message. On top of that sit the headers, the message body and any HTML signature or embedded logo.
- **Plan for about 1.4 times your intended ceiling.** If you genuinely want to accept attachments up to 10 MB, set the filter somewhere around 14 MB. Setting it to exactly 10 MB will reject a great many 8 MB and 9 MB files.
- **Several attachments count together.** The limit is on the whole message, so four 3 MB photos in one email are measured as one large message, not four small ones.
- **Threads grow.** A long reply chain that keeps quoting an attached document can cross a tight limit late in the conversation, long after the first message got through fine.
A practical starting point for a normal business mailbox is a limit in the region of 20 MB to 30 MB. That is comfortably above everyday invoices, contracts, purchase orders and photographs, while still turning away the very large payloads that are almost never legitimate.
Be aware that the Noiz mail platform already enforces its own overall message size ceiling. Your filter can only ever be stricter than that ceiling, never more permissive. Setting a very high value here does not raise the platform limit.
If your business regularly needs to receive genuinely large files such as video, design source files or print-ready artwork, a size filter is the wrong tool. Ask senders to share a download link instead. It is faster for them, it does not sit in your mailbox quota, and it removes the size question entirely.
## Testing the Rule
Do not assume the threshold behaves the way you expect. Confirm it:
1. From an external address, such as a personal webmail account, send a message with an attachment comfortably below your limit. It should arrive normally.
2. Send a second message with an attachment comfortably above the limit. It should not arrive. Check the sending account for a delivery failure notice, which usually appears within a few minutes, but do not treat its absence as proof the limit is not working: check the mailbox itself.
3. Send a third with an attachment just under the limit. This is the one that exposes encoding overhead. If it bounces, your limit is tighter in practice than the number suggests, and you should raise it.
Test from an outside provider rather than from another mailbox on the same domain, so that the message travels the same path a real sender's message would.
## Troubleshooting
**Symptom**: A customer says an important email bounced with a size or message-too-large error. Raise or remove the size rule, then ask them to resend. The original message cannot be recovered, so it has to be sent again.
**Symptom**: The rule appears to do nothing. Check that you set it against the correct domain. Rules are per domain and do not apply to other domains on the same account. Also confirm the unit, since a value entered in KB is a thousand times smaller than the same value in MB.
**Symptom**: Small messages are being blocked. You have almost certainly set the value in **KB** when you meant **MB**. Remove the rule and add it again with the correct unit.
**Symptom**: Large mail still gets through after the limit was raised. The platform-wide message size ceiling still applies. A domain filter cannot lift it.
**Symptom**: You want the rule gone entirely. Follow [How to Remove Email Spam Filters in DirectAdmin](/directadmin/how-to-remove-email-spam-filters-in-directadmin/).
## Related Articles
- [How to Remove Email Spam Filters in DirectAdmin](/directadmin/how-to-remove-email-spam-filters-in-directadmin/)
- [How to Block Emails Containing the Stop Word in DirectAdmin](/directadmin/how-to-block-emails-by-stop-word-in-directadmin/)
## Need a Hand?
If you are unsure what threshold suits your mail flow, or you suspect a size rule is blocking mail you need, open a support ticket from your Noiz client area. The Noiz team can review what is arriving at your domain and help you set a limit that holds back the junk without costing you real business mail.
# How to Block Emails by Stop Word in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-block-emails-by-stop-word-in-directadmin/
This guide shows you how to block incoming mail that contains a particular word or phrase, using the **Stop Word** option in the DirectAdmin spam filters on your Noiz hosting account. It is the right tool when the unwanted mail is not tied to one sender or one domain, but keeps repeating the same recognisable text, such as a scam subject line or a phrase used by a bulk sender who changes address constantly. You may see the feature called a stop word, a block word, or a keyword filter; all three describe the same setting.
Stop word blocking is powerful and blunt in equal measure. Read [Choosing a Stop Word That Will Not Cost You Mail](#choosing) before you add one, because a badly chosen word silently discards wanted mail, with no warning to you and and often no warning to the person who sent it either.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: Preventing SPAM](https://docs.directadmin.com/other-hosting-services/preventing-spam/)
- [DirectAdmin Docs: Filtering incoming spam](https://docs.directadmin.com/other-hosting-services/preventing-spam/incoming-spam.html)
- [DirectAdmin Docs: The Evolution interface](https://docs.directadmin.com/directadmin/skins-and-templates/evolution.html)
## Prerequisites
- Your DirectAdmin username and password for your Noiz hosting account.
- The domain the rule should apply to, if the account hosts more than one.
- A few samples of the unwanted mail open in front of you, so you can choose text that genuinely appears in it.
## What a Stop Word Actually Does
DirectAdmin turns the entry you save into a mail server rule that inspects incoming messages for that text before they reach any mailbox on the domain. Five behaviours are worth understanding before you add one:
- **It matches text, not senders.** The rule ignores who sent the message. If the text is present, the message is blocked, whoever it came from. That is exactly why it works on spam that rotates through hundreds of throwaway addresses, and exactly why it is risky.
- **It is a substring match, not a whole-word match.** A stop word of `cash` also matches `cashflow`, `cashier` and the surname `Cashmore`. This is the single most common cause of mail going missing after someone adds a stop word.
- **The text does not have to be in the subject line.** A match anywhere in the message counts, so the word can be hiding in a quoted reply, a signature block, a marketing footer, or a link in the body.
- **Blocked mail is discarded, not quarantined.** A message caught by a stop word does not land in a Spam or Junk folder for you to review. It is dropped. There is nothing to check, nothing to release and nothing to recover, and the sender is not told that the message failed to arrive.
- **Settings are stored per domain.** DirectAdmin keeps the spam filter configuration against the domain, not against an individual mailbox. A stop word added while `yourdomain.com` is selected applies to every address on `yourdomain.com`, including `info@`, `accounts@` and any address a colleague reads.
## Block Emails by Stop Word in DirectAdmin
1. Log in to your DirectAdmin account.
2. In the **E-mail Manager** section, click **SPAM Filters**. If you cannot see the section, type `SPAM Filters` into the navigation filter box at the top of the sidebar and the item will appear. Click it. 
3. If the account hosts more than one domain, choose the correct domain from the selector at the top of the page before you add anything. The rule applies to the domain that is selected at the moment you click **Block**.
4. Under **Block By**, select **Stop Word** from the drop-down menu.
5. In the **Value** field, type the word or phrase you want to block. To reduce partial matches, type a space before and after the word, for example ` cash ` rather than `cash`. See the caveat on that technique below. 
6. Click **Block**. The entry appears in the list of active filters on the same page, and it takes effect for mail arriving from that point onward.
7. Repeat the process for each additional stop word. You can add as many as you need, and each one is stored as a separate entry so you can remove them individually later.
## Choosing a Stop Word That Will Not Cost You Mail
Because a blocked message is discarded rather than filed away, a bad stop word is invisible. Nobody complains, nothing appears in a folder, and you find out weeks later when a customer asks why you never replied. These rules keep that from happening:
- **Prefer a distinctive phrase over a single word.** Blocking `claim your prize now` is far safer than blocking `prize`. The longer and odder the string, the less chance it collides with real correspondence.
- **Search your existing mail first.** Before you save a candidate, search your mailbox for that exact text. If it turns up in messages you were glad to receive, choose something else. Two minutes of searching is cheaper than a lost invoice.
- **Never block a word from your own trade.** An accountant blocking `invoice`, a recruiter blocking `vacancy` or a letting agent blocking `deposit` will lose the exact mail the business runs on.
- **Understand what the space trick does and does not do.** Wrapping the word in spaces gives you a rough word boundary and stops `cash` matching `cashflow`. It also means the word will no longer match when it sits at the very start of a line, immediately before a full stop or comma, or wrapped in HTML formatting. Expect it to trade some false blocks for some misses.
- **Do not rely on it to catch every message.** Mail is often sent as formatted HTML, and a word can be broken up by markup or encoded in a way the rule does not see. A stop word is a reasonable way to cut down a nuisance, not a guarantee.
- **Keep a note of what you blocked and why.** The filter list shows you the value but not the reason or the date. A short note in your own records makes it obvious later which entries are still earning their place.
## Test the Filter Before You Trust It
Send yourself two test messages from an outside address, ideally a personal webmail account. Put the stop word in the first and leave it out of the second. The second should arrive normally. The first should never appear anywhere, including the Spam folder, and do not assume the sender will be told: depending on how the rule is applied they may get a delivery failure or nothing at all. That silence is the confirmation that the rule is working, and it is also the reason to be careful with it.
If the test message with the stop word does arrive, check that you were editing the right domain and that the entry is listed on the **SPAM Filters** page. Give it a minute or two and try again before assuming it has failed.
## Remove or Change a Stop Word
Stop words cannot be edited in place. To change one, remove the old entry and add a new one. Removal is done from the same **SPAM Filters** page, and the steps are covered in [How to Remove Email Spam Filters in DirectAdmin](/directadmin/how-to-remove-email-spam-filters-in-directadmin/). Removing a stop word restores normal delivery for new mail, but it does not bring back anything that was already discarded.
## When a Different Filter Suits the Job Better
- **One persistent sender or one bad domain.** Blocking the address or the domain is far more precise than blocking text. See [How to Block Email Using Spam Filters in DirectAdmin](/directadmin/how-to-block-an-email-address-using-spam-filters-in-directadmin/).
- **General, everyday spam.** Scoring-based filtering handles the broad volume far better than any keyword list, and it files suspected spam somewhere you can review it rather than deleting it. See [How to Enable Apache SpamAssassin in DirectAdmin](/directadmin/how-to-enable-apache-spamassassin-in-directadmin/).
- **Mail you want to see but file separately.** A stop word cannot sort mail, only destroy it. Use a rule in your mail client or webmail to move messages into a folder instead.
## Troubleshooting
**Symptom**: Legitimate mail has stopped arriving since you added a stop word. Assume the stop word is the cause until proven otherwise. Remove the entry, then work out which text in the missing messages matched it. Mail discarded while the rule was active cannot be recovered, so ask the sender to resend once the rule is gone.
**Symptom**: The unwanted mail still gets through. The exact text may not be present in every message, or it may be broken up by HTML formatting. Open one of the messages that got through, view its source or original, and confirm the string really is there in the form you typed it.
**Symptom**: **Stop Word** is not listed in the **Block By** drop-down. Confirm you are on the **SPAM Filters** page rather than **SpamAssassin Setup**, which is a separate item with its own options.
**Symptom**: **SPAM Filters** does not appear in the sidebar. The feature may not be included on your hosting package, or you may be logged in at reseller or admin level rather than user level. Switch to the user-level view, and open a ticket with Noiz if it is still missing.
**Symptom**: A colleague on the same domain has lost mail and you never touched their mailbox. Spam filter settings are held per domain, so any stop word you added affects them too. Review the full list of entries on the **SPAM Filters** page.
## Need a Hand?
If mail has gone missing and you are not sure whether a stop word is responsible, Noiz can check the mail logs for the message and tell you precisely where it was dropped, which is usually faster than removing rules one at a time and waiting to see what changes. Open a ticket from your Noiz client area with the sending address, the receiving address, and roughly when the message was sent.
# How to Block a Domain Using Spam Filters in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-block-a-domain-using-spam-filters-in-directadmin/
If the same spammer keeps mailing you from a stream of throwaway addresses that all share one domain, blocking individual addresses becomes a losing game. DirectAdmin lets you block the whole sending domain in one entry, so every current and future address at that domain is refused. This guide shows you how to do that on your Noiz DirectAdmin hosting, and, just as importantly, when not to.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: Filtering incoming spam](https://docs.directadmin.com/other-hosting-services/preventing-spam/incoming-spam.html)
- [DirectAdmin Docs: Email maintenance and customisation](https://docs.directadmin.com/other-hosting-services/email/index.html)
## Prerequisites
- Your DirectAdmin login details, supplied by Noiz when your hosting was set up.
- At least one domain with e-mail hosted on the account.
- The exact sending domain taken from the spam itself, not from a link inside the message.
## Read This Before You Block a Whole Domain
A domain block is a blunt instrument. It is the right tool for a domain that exists only to send you rubbish, and the wrong tool for almost everything else.
- **Never block a large mail provider.** Blocking `gmail.com`, `outlook.com`, `yahoo.com`, `icloud.com` or any other shared provider silently cuts off every legitimate person who happens to use that provider, including clients, suppliers and your accountant. If the spam comes from a shared provider, block the individual address instead.
- **Sender addresses are easy to forge.** Spam frequently carries a fake **From** domain, sometimes a real business that has nothing to do with the sender. Blocking a forged domain stops nothing and may block a genuine contact later on.
- **Blocked mail is refused, not filed away.** A block causes the mail server to reject the message rather than drop it into a Junk or Spam folder, so there is no quarantine to review and nothing to restore if you get it wrong. Treat the block list as something you check occasionally rather than something you set and forget.
If the spam is arriving from one or two specific addresses, or you want to filter on a word or phrase in the message, use [How to Block Email Using Spam Filters in DirectAdmin](/directadmin/how-to-block-an-email-address-using-spam-filters-in-directadmin/) instead.
## Block a Domain in DirectAdmin
### 1. Open the SPAM Filters tool
Log in to DirectAdmin. In the **E-mail Manager** section, click **SPAM Filters**. If you cannot see the section, type `SPAM Filters` into the navigation filter box at the top of the menu and the entry will appear.

The page that opens is headed **E-mail Filters**. That is the same tool: the menu entry and the page title use different names, which catches people out when they are following older instructions.
### 2. Choose the right domain
Filters are stored per domain, not per account. If more than one domain is hosted on your account, use the domain selector at the top of the page to switch to the domain that is receiving the spam before you add anything. A filter added under the wrong domain will look correct and do nothing.
### 3. Set Block By to Domain
Under **Block By**, choose **Domain** from the drop-down menu.
### 4. Enter the sending domain
In the **Value** field, type the domain on its own: no `http://`, no `www.`, no `@` and no address in front of it. For example, type `example.net`, not `sales@example.net` and not `www.example.net`.

### 5. Click Block
Click the green **Block** button. The domain is added to the list below and takes effect on the next message that arrives. Mail already sitting in your mailbox is not touched, so delete anything that got through before the block.
To block further domains, repeat steps 3 to 5. Each entry covers one domain, so add subdomains such as `mail.example.net` as separate entries if spam keeps arriving from them.
## Troubleshooting
**Symptom**: spam from the same domain still arrives after the block. Check that you added the filter under the correct domain, and compare the domain in the block list against the sender address on the newest message. Spammers rotate domains constantly, so `example.net` today is often `example-net-mail.co` tomorrow. If the domain changes with every message, blocking domains will not keep up and the spam score filter is the better answer.
**Symptom**: a client or supplier says their mail bounces. Check the block list for their domain, and for any large provider you may have blocked in frustration. Remove the entry using [How to Remove Email Spam Filters in DirectAdmin](/directadmin/how-to-remove-email-spam-filters-in-directadmin/), then ask them to resend.
**Symptom**: the block list keeps growing and the spam keeps coming. That is the signal to stop adding entries. A long list of dead domains slows nothing down but protects nothing either. Contact Noiz support so the server-side spam scoring can be reviewed for your domain.
## Related Articles
- [How to Block Email Using Spam Filters in DirectAdmin](/directadmin/how-to-block-an-email-address-using-spam-filters-in-directadmin/)
- [How to Remove Email Spam Filters in DirectAdmin](/directadmin/how-to-remove-email-spam-filters-in-directadmin/)
If spam is getting through in volume, or you are not sure whether a domain is safe to block, open a ticket with Noiz support. Noiz can review the mail logs for your domain and tune the server-side filtering rather than leaving you to fight it one entry at a time.
# How to Block an Email Address Using Spam Filters in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-block-an-email-address-using-spam-filters-in-directadmin/
If one particular sender keeps mailing you and you want the messages stopped at the server rather than in your mail client, you can block that address from the **SPAM Filters** page in DirectAdmin. This guide shows you how, and explains what a sender block does and does not achieve, so you pick the right tool for the problem.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin: Filtering incoming spam](https://docs.directadmin.com/other-hosting-services/preventing-spam/incoming-spam.html), including the wildcard formats accepted by the block list
- [DirectAdmin: Preventing SPAM overview](https://docs.directadmin.com/other-hosting-services/preventing-spam/index.html)
- [DirectAdmin: E-mail maintenance and customisation](https://docs.directadmin.com/other-hosting-services/email/index.html)
## Prerequisites
- A Noiz hosting account on a DirectAdmin server, and your DirectAdmin login details (sent in your welcome e-mail).
- The exact sender address you want to block, copied from the message headers rather than typed from memory.
- The e-mail domain in question must be hosted on the same account. Filters are stored per domain, so a block on one domain does not cover another.
## Before You Block: Is a Sender Block the Right Fix?
A sender block is an exact-match rule. It is the right tool for a specific, persistent, real sender: a mailing list that ignores unsubscribe requests, a former supplier, a single nuisance address. It is a poor tool for general spam, for two reasons:
- **Senders rotate.** Bulk spam is sent from a fresh address, and often a fresh domain, every few days. Blocking one address means the next message simply arrives from another.
- **Sender addresses are forged.** The visible **From** address on a spam message is frequently someone else's, so a block can end up silencing an innocent third party while the spam keeps arriving.
For volume spam, score-based filtering on the same **SPAM Filters** page does far more work: it judges each message on many signals at once and acts on the total score, which is why it keeps working when the sender changes. Use score-based filtering as the everyday defence, and sender blocks as targeted additions on top of it.
## Block a Sender Address in DirectAdmin
### Step 1: Open SPAM Filters
1. Log in to your DirectAdmin account.
2. In the **E-mail Manager** section, click **SPAM Filters**. If you cannot see it, type **SPAM Filters** into the **navigation filter** box at the top of the menu and click the result.

If your account hosts more than one domain, check the domain selector at the top of the page before you make any changes, so the filter lands on the domain that is actually receiving the mail.
### Step 2: Add the Address to the Block List
1. In the **E-mail Filters** area, open the **Block By** drop-down menu and choose **Email**.
2. In **Value**, type the full e-mail address you want to block, for example `spam-email-address@example.net`.
3. Click **Block**.

The address appears in the list of active filters straight away and takes effect on the next message that arrives. Mail already sitting in your mailbox is not affected, so delete anything you have already received from that sender yourself.
To block further addresses, repeat this step for each one. There is no need to reopen the page between entries.
### Step 3: Use Wildcards Where One Address Is Not Enough
DirectAdmin accepts wildcard patterns in the same **Value** field, which is what makes sender blocking practical when an address keeps shifting. Useful forms include:
- `*@example.com`, every sender at that domain
- `sales@*.com`, that mailbox name across any .com domain
- `sales@example.*`, that mailbox name across every top-level domain variant
Wildcards are powerful and easy to over-apply. A pattern such as `@*.com` blocks a very large share of legitimate business mail, so start narrow, and widen only if the nuisance mail continues. If your goal is to block a whole domain rather than a pattern, use the **Domain** option instead, which is covered in its own guide below.
## What Happens to Blocked Mail
Blocked messages are stopped at the mail server, before they reach your mailbox or your Spam folder. You do not get a notification, and there is nothing to review later. That is the point of the feature, but it is also the risk: if you block an address in error, mail from that sender disappears silently until you remove the entry. Keep a note of what you have blocked and why, especially on shared or role mailboxes, and review the filter list occasionally.
If you also maintain a whitelist, whitelist entries take priority over block entries. An address that appears in both lists is delivered.
## Troubleshooting
- **Symptom**: mail from the sender is still arriving. Check the address in the message headers against the entry you created, character for character. Spammers commonly vary the mailbox name or use a look-alike domain. Confirm too that the filter is on the domain that is actually receiving the message.
- **Symptom**: the block worked for a few days, then the mail returned. The sender changed address. Either move to a wildcard pattern or a domain block, or lean on score-based filtering instead of chasing individual addresses.
- **Symptom**: a legitimate sender has gone quiet since you added a filter. Remove the entry, then ask the sender to resend. Nothing was queued, so the original messages are gone.
- **Symptom**: the page or the option labels look different from the screenshots. DirectAdmin skins and versions vary slightly, and this page is named **SpamAssassin Setup** in some builds. The **Block By** and **Value** fields work the same way.
- **Symptom**: **SPAM Filters** does not appear in the menu at all. The feature may not be enabled on your hosting package. Contact Noiz support and it can be checked for you.
## Related Guides
- [How to Block a Spammy Domains Using Spam Filters in DirectAdmin](/directadmin/how-to-block-a-domain-using-spam-filters-in-directadmin/)
- [How to Block Emails Containing the Stop Word in DirectAdmin](/directadmin/how-to-block-emails-by-stop-word-in-directadmin/)
- [How to Remove Email Spam Filters in DirectAdmin](/directadmin/how-to-remove-email-spam-filters-in-directadmin/)
If spam is getting through despite your filters, or you would rather have the filtering tuned for you, open a ticket with Noiz support and the mail filtering on your account can be reviewed.
# How to Change a Database Password in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-change-a-database-password-in-directadmin/
Changing a database user's password is one of the fastest ways to lock an attacker out of a compromised site, and it is also the change most likely to take a working site offline by accident. This guide shows you how to reset a MySQL/MariaDB user password from **MySQL Management** in DirectAdmin on Noiz hosting, and, just as importantly, what you must update immediately afterwards so your website keeps connecting.
The password you are changing belongs to a **database user**, not to the database itself. Databases have no password of their own. A user account holds the credentials, and the database grants that user access.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: MariaDB and MySQL](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/index.html)
- [DirectAdmin Docs: phpMyAdmin](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/phpmyadmin.html)
- [DirectAdmin Docs: MariaDB/MySQL Troubleshooting](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/troubleshooting.html)
## Prerequisites
- Your DirectAdmin login details for your Noiz hosting account.
- An existing database and database user. If you have not created one yet, start with [How to Create a Database in DirectAdmin](/directadmin/how-to-create-a-mysql-database-in-directadmin/).
- File Manager or FTP access, so you can edit your application's configuration file straight after the change.
- A password manager or another safe place to store the new password before you leave the page.
## Before You Change Anything: Read This
The new password takes effect the moment you save. There is no grace period and no fallback to the old password. Any live website, cron job, or script still using the old credentials will start failing immediately, typically with `Error establishing a database connection` or `Access denied for user`.
Two habits make this painless:
- **Open your configuration file first.** Have the file ready to edit in another browser tab before you save the new password, so the gap between the two changes is seconds rather than minutes.
- **Remember the change is per user, not per database.** If the same database user has access to several databases, every one of those connections now needs the new password. Check each application that uses that user, not just the site you had in mind.
## Change the Database Password in DirectAdmin
1. Log in to your DirectAdmin account.
2. In the **Account Manager** section, click **MySQL Management**. If you cannot see it, type `MySQL Management` into the navigation filter box at the top of the sidebar and the option will appear. Click it. 
3. From the list of **databases**, click the one you want to work with. Database names on DirectAdmin are prefixed with your account username, so they look like `youruser_wordpress` rather than just `wordpress`. 
4. Under the **Users** list you will find the database users attached to that database. Click **Change Password** next to the user whose password you want to reset. 
5. Enter your new **password**, or click the **generate password** icon to have DirectAdmin create a strong random one for you. Confirm with **Save**. 
**Copy the new password somewhere safe before you close the dialog.** DirectAdmin will not show it to you again, and there is no way to read an existing MySQL password back out of the server. If you lose it, your only option is to set another new one and update your configuration again.
## Update Your Application Configuration Immediately
This is the step people skip, and it is the reason a routine password change turns into an outage. Your website stores the old database password in a plain configuration file on the server. Until you edit that file, your site is broken.
Open **File Manager** in DirectAdmin (or connect over FTP/SFTP), find the file for your application, and replace the old password value with the new one:
- **WordPress**: `wp-config.php` in the site root. Update the `DB_PASSWORD` line.
- **Joomla**: `configuration.php` in the site root. Update `public $password`.
- **Drupal**: `sites/default/settings.php`. Update the `password` key inside the `$databases` array.
- **Laravel and most modern PHP frameworks**: the `.env` file. Update `DB_PASSWORD`.
- **Magento 2**: `app/etc/env.php`. Update the `password` value in the `db` section.
- **Custom or in-house scripts**: check for an includes, config, or connection file. Search your site files for the old password string if you are not sure where it lives.
Save the file, then load your website in a fresh browser tab to confirm it connects.
### Two Gotchas Worth Knowing
- **Special characters can break config files.** A generated password containing a backslash, a single quote, a dollar sign, or a hash can be mangled depending on how your configuration file quotes strings. In a PHP double-quoted string a `$` is interpreted as a variable. In a `.env` file a `#` can start a comment and spaces can truncate the value, so wrap the value in double quotes. If you hit an unexplained authentication failure straight after editing, this is usually the cause. Regenerating a password that avoids awkward characters is a legitimate fix.
- **Caching plugins and object caches can mask the result.** A heavily cached site may keep serving pages for a while after the credentials break, so a page loading correctly is not proof that the new password works. Load the admin area or a logged-in page to test a real database connection.
## Troubleshooting
**Symptom**: The site shows `Error establishing a database connection` after the change. The configuration file still holds the old password, or the edit was not saved. Re-open the file, confirm the new password is present and correctly quoted, and save again.
**Symptom**: `Access denied for user 'youruser_dbuser'@'localhost'`. The username or the host is wrong as well as the password. Confirm the exact username in **MySQL Management**, remembering the account prefix, and confirm the host in your configuration is `localhost` for a site hosted on the same server.
**Symptom**: One site works but another has broken. That second site shares the same database user. Update its configuration file with the new password too.
**Symptom**: phpMyAdmin will not let you in with the new password. Log out fully and clear the phpMyAdmin session cookie, or use a private browsing window. An old session can hold stale credentials.
**Symptom**: The user can connect but cannot read or write data. That is a privileges problem, not a password problem. The password change does not alter grants, so review the user's permissions in **MySQL Management**.
## Related Guides
- [How to Create a Database in DirectAdmin](/directadmin/how-to-create-a-mysql-database-in-directadmin/)
- [How to Create a New Database User in DirectAdmin](/directadmin/how-to-create-a-new-database-user-in-directadmin/)
## Need a Hand?
If your site is down after a password change and you would rather not go hunting through configuration files, open a support ticket from your Noiz client area. The Noiz support team can identify which files hold the credentials, apply the new password, and confirm the site is connecting again.
# How to Change an Email Account's Disk Quota in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-change-an-email-accounts-disk-quota-in-directadmin/
Every mailbox on a DirectAdmin hosting account has its own disk quota, which is separate from the disk space of the hosting account as a whole. When a mailbox reaches that quota it stops accepting new mail, and senders start getting bounce messages. This guide shows you how to change the disk quota on an individual email account in DirectAdmin, and explains what the quota actually controls so you can choose a sensible figure rather than guessing.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: E-mail](https://docs.directadmin.com/other-hosting-services/email/) covers how DirectAdmin stores and serves mail behind the panel.
- [DirectAdmin Docs: E-mail Troubleshooting](https://docs.directadmin.com/other-hosting-services/email/troubleshooting.html) is the reference for diagnosing delivery failures, including over-quota rejections.
## Prerequisites
- Your DirectAdmin username and password for the hosting account that holds the domain.
- At least one mailbox already created on the domain. If you have not created one yet, see [How to Create an Email Account in DirectAdmin](/directadmin/how-to-create-an-email-account-in-directadmin/).
- Enough unused disk space on the hosting plan to cover the larger quota you intend to set.
## What the Mailbox Quota Actually Controls
The quota is a storage ceiling on the messages held on the server for that one mailbox. It is worth understanding what happens at the ceiling before you change the number:
- **Incoming mail bounces.** Once the mailbox is full, the mail server rejects new deliveries and the sender receives a bounce message along the lines of "mailbox is full" or "quota exceeded". The message is not held and delivered later, and it is not silently discarded either. It goes back to whoever sent it, which is why a full mailbox is usually reported to you by a frustrated customer rather than noticed by the mailbox owner.
- **Sending often still works.** Because outbound mail does not need space in the inbox, the account holder can frequently still send email while quietly receiving nothing. That is what makes a full mailbox so easy to miss.
- **Everything stored counts, not just the inbox.** If the mailbox is connected over IMAP, the Sent, Drafts, Junk and Trash folders all live on the server and all consume the quota. Emptying Trash and Junk is usually the fastest way to recover space without buying more.
- **The quota lives inside the plan.** A mailbox quota carves space out of the hosting account's total disk allowance. Raising one mailbox to a very large figure, or to unlimited, does not create extra space. It simply lets that mailbox consume the whole plan and starve the website and the other mailboxes.
- **Storage and sending are two different limits.** The disk quota governs how much mail can be stored. The number of messages an account may send per day is a separate setting. If your problem is outbound rather than inbound, see [How to Change the Email Sending Limit in DirectAdmin](/directadmin/how-to-change-the-email-sending-limit-in-directadmin/).
## Changing the Quota in DirectAdmin
1. Log in to your DirectAdmin account.
2. In the **E-mail Manager** section, click **E-mail Accounts**. If you cannot see the section, type `E-mail Accounts` into the **navigation filter** box at the top of the menu and click the result when it appears. 
3. The **Account list** shows every mailbox on the domain, along with how much space each one is currently using against its quota. Find the address you want to change. A **plus icon** sits at the right-hand side of its row. 
4. Click the **plus icon** and choose **Change Limits** from the menu that opens. 
5. Set the **E-mail Quota** field to the size you want, in megabytes. If your hosting plan allows it, an **Unlimited** option is offered here as well. Read the note below before choosing it. 
6. Click **Save**.
The new limit applies immediately. There is no mail server restart and no waiting period, so a mailbox that was rejecting mail because it was full will start accepting deliveries again as soon as the larger quota is saved. Senders whose earlier messages already bounced will need to send those again, because a bounced message is gone rather than queued.
## Choosing a Sensible Quota
- **Do not simply set everything to unlimited.** An unlimited mailbox will happily grow until it consumes the entire hosting plan, at which point the website can no longer write files, logs stop rotating and backups start failing. A generous fixed number gives you a warning shot instead of an outage. Reserve unlimited for accounts you actively monitor.
- **Lowering a quota does not delete mail.** If you set a quota below what the mailbox is already storing, nothing is erased, but the mailbox is instantly over its limit and stops accepting new mail until enough is removed. Clear the mailbox down first, then lower the number.
- **Watch the POP3 trap.** A mail client set up as POP3 with "leave a copy of messages on the server" enabled will download mail and still leave it on the server forever. The user sees a tidy inbox on their laptop while the server-side mailbox quietly fills. If a mailbox keeps hitting its quota for no obvious reason, this is the usual cause.
- **Large attachments are the real consumer.** Sorting the mailbox by size and clearing a handful of old attachment-heavy threads usually frees more space than deleting hundreds of ordinary messages.
## Troubleshooting
**Symptom: the quota is saved but the mailbox still rejects mail.** Confirm the mailbox is genuinely under its new limit by checking the usage figure in the **Account list**. If usage is still at or above the quota, the mailbox needs space cleared. Also check that the hosting account as a whole is not out of disk space, because a full account blocks delivery regardless of the individual mailbox quota.
**Symptom: the Unlimited option is not offered.** The hosting plan does not permit unlimited mailbox quotas. Set the largest fixed figure the plan will accept, or contact Noiz about a plan with more disk space.
**Symptom: the quota will not save, or the panel rejects the value.** The figure requested exceeds the disk space remaining on the hosting account, or exceeds a limit set on the package. Free space elsewhere on the account or lower the requested figure.
**Symptom: mail disappeared after the quota was raised.** Raising a quota never removes mail. Check the mail client instead, particularly whether it is configured as POP3 without leaving copies on the server, which moves mail off the server to a single device.
## Need a Hand?
If a mailbox keeps filling faster than you can raise the quota, or you are not sure whether the hosting plan has room for the size you need, open a support ticket from the Noiz client area with the domain and the mailbox address. The Noiz support team can check the account's real disk usage and advise on the right quota rather than leaving you to guess.
# How to Change an Email Account's Password in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-change-an-email-accounts-password-in-directadmin/
Changing the password on a mailbox is one of those jobs that is easy in the panel and then catches people out everywhere else. This guide shows you how to set a new password for an email account on your Noiz hosting account in DirectAdmin, and, just as importantly, what else has to be updated the moment you do it so that your mail does not stop working on your phone and desktop.
Do this whenever a password has been shared, guessed, or found in a breach, when someone leaves the organisation, or when a mailbox starts sending spam. Changing the mailbox password is the single fastest way to cut off an attacker who has been logging in and sending mail as you.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin: E-mail](https://docs.directadmin.com/other-hosting-services/email/index.html)
- [DirectAdmin: system email accounts](https://docs.directadmin.com/other-hosting-services/email/system-accounts.html)
- [DirectAdmin: autodiscover information for mail clients](https://docs.directadmin.com/other-hosting-services/email/autodiscover.html)
- [DirectAdmin: webmail](https://docs.directadmin.com/other-hosting-services/webmail/index.html)
## Prerequisites
- An active Noiz hosting account with DirectAdmin access, and your DirectAdmin username and password.
- The mailbox you want to change already created on the account. If it does not exist yet, see [How to Create an Email Account in DirectAdmin](/directadmin/how-to-create-an-email-account-in-directadmin/).
- Access to every device and mail client that currently collects mail from that address, because each one needs the new password before it will connect again.
- Somewhere safe to store the new password, ideally a password manager rather than a note or a spreadsheet.
## Change the Mailbox Password
### 1. Log in to DirectAdmin
Sign in to your DirectAdmin account with the username and password on your Noiz welcome email.
### 2. Open E-mail Accounts
In the **E-mail Manager** section, click **E-mail Accounts**. If the section is collapsed or you cannot see the entry, type `E-mail Accounts` into the navigation filter box at the top of the menu and the option will appear. Click it.

If your account holds more than one domain, check the domain selector at the top of the page before you go any further. The list only shows mailboxes on the domain currently selected, and it is easy to change the password on the right username at the wrong domain.
### 3. Find the mailbox in the account list
The **Account list** shows every mailbox on the selected domain. At the right-hand end of each row is a small control that opens the actions for that mailbox, shown here as a plus icon.

### 4. Choose Change Password/Username
Click the icon and choose **Change Password/Username** from the menu that opens.

The same screen handles both jobs. Change only the password field and leave the username alone unless you genuinely want to rename the address, which has consequences of its own. See [How to Rename an Email Address in DirectAdmin](/directadmin/how-to-rename-an-email-address-in-directadmin/) if that is what you are actually after.
### 5. Enter the new password
In the **Password** field, type the new password, or click the **Generate Random Password** icon to have DirectAdmin create a strong one for you. The strength indicator next to the field tells you whether what you have typed will be accepted.

### 6. Save
Click **Save**. If you used the generator, the password is shown to you in a pop-up box. Copy it somewhere safe before you close that box, because DirectAdmin will not show it to you again. Nobody, including Noiz support, can read an existing mailbox password back out of the server; it can only be set to something new.
The change takes effect immediately. There is no propagation delay and no need to restart anything.
## Update the Password Everywhere the Mailbox Is Used
This is the step that generates most of the support tickets. The server now expects the new password, and every client that still holds the old one will keep trying it. Work through all of them straight away:
- **Phones and tablets.** Mail apps on iOS and Android hold the password in the account settings and retry silently in the background. Update the password in the account entry rather than deleting and re-adding the account, which risks removing locally stored mail.
- **Desktop mail clients.** Outlook, Thunderbird, Apple Mail and the rest each store the password separately, and several store it twice, once for incoming mail and once for outgoing. If mail arrives but will not send after a password change, the outgoing entry is the one still holding the old password.
- **Webmail.** Nothing to update, but you will be asked to log in again with the new password.
- **Websites and applications that send mail through the mailbox.** Contact forms, WordPress SMTP plugins, shop order confirmations, invoicing systems and monitoring scripts all authenticate as a mailbox. Any of these configured with the old password will stop sending, usually silently.
- **Other people.** If a shared mailbox is collected by more than one person, everyone needs the new password at the same time, otherwise the ones who have not been told will lock themselves out.
Repeated failed logins from a device still holding the old password can get that device's IP address blocked by the server's brute force protection. If a phone or laptop stops connecting entirely a few minutes after a password change, that is usually what has happened. Correct the password first, then contact Noiz support if the connection is still refused.
## Choosing a Password That Holds Up
Mailbox credentials are attacked constantly and automatically, because a working mailbox login is worth money to a spammer. Treat it as seriously as a banking password.
- Use the **Generate Random Password** option unless you have a good reason not to. It produces something no dictionary attack will reach.
- If you type your own, make it long. Length beats complexity: a four-word passphrase is stronger and easier to type on a phone than eight characters of punctuation.
- Never reuse a password from another service. Credential stuffing, where breached passwords are replayed against mail servers, is one of the most common ways mailboxes are compromised.
- Do not build the password from the address, the domain or the business name. Those are the first things tried.
- Store it in a password manager. A mailbox password that has to be memorable enough to remember is usually weak enough to guess.
## Things Worth Knowing
- **The mailbox password and your DirectAdmin login are different things.** Changing a mailbox password here does not change your DirectAdmin account password, and changing your DirectAdmin password does not change the passwords on mailboxes you have created.
- **The mailbox that matches your DirectAdmin username is a special case.** DirectAdmin always keeps a system email account named after your DirectAdmin username, and it cannot be deleted because system messages such as cron output are delivered to it. Its mail login is the bare username with your DirectAdmin account password, so it is not changed from this screen.
- **Changing the password does not sign out an existing session.** An attacker with a mail session already open may stay connected until that session drops. If you are changing the password because a mailbox has been compromised, check the account afterwards for forwarders, filters and autoresponders that were not put there by you. Attackers routinely add a hidden forwarder so they keep receiving mail after being locked out.
- **Sent mail, folders and settings are untouched.** A password change does not affect stored mail, folder structure, forwarders, autoresponders or quota. Only the credential changes.
- **Aliases and forwarders have no password of their own.** If an address forwards elsewhere rather than storing mail, there is nothing to change; the password belongs to the destination mailbox.
- **Whoever knew the old password can still see the mail already delivered** if they had it downloaded to their own device. Changing the password stops future access, it does not recall what has already been collected.
## Troubleshooting
- **Symptom**: DirectAdmin rejects the new password. It has not met the minimum strength the server requires. Make it longer, mix in numbers and symbols, or use **Generate Random Password**.
- **Symptom**: mail arrives but will not send. The outgoing server settings in the mail client still hold the old password. Update the outgoing entry as well as the incoming one; they are stored separately in most clients.
- **Symptom**: a client keeps prompting for the password and refuses the new one. Check for the password saved in the operating system's keychain or credential store, which can be handed back to the client automatically and override what you typed. Remove the stored entry, then enter the new password once.
- **Symptom**: the device connected fine, then stopped connecting a few minutes after the change. Repeated failed logins have most likely triggered a temporary IP block. Fix the password on every client on that connection first, then contact Noiz support if it does not clear.
- **Symptom**: you closed the pop-up before copying the generated password. It cannot be retrieved. Repeat the procedure and set the password again.
- **Symptom**: the mailbox is not in the list. You are looking at the wrong domain. Change the domain selector at the top of the page.
- **Symptom**: the mailbox still sends spam after the password change. The credential was probably not the only route in. Check for unfamiliar forwarders and filters on the account, change the password on any website or script that sends through the mailbox, and open a ticket with Noiz support so the mail logs can be examined.
## Related Guides
- [How to Create an Email Account in DirectAdmin](/directadmin/how-to-create-an-email-account-in-directadmin/)
- [How to Rename an Email Address in DirectAdmin](/directadmin/how-to-rename-an-email-address-in-directadmin/)
## Need a Hand?
If a mailbox will not accept the new password, a device has been blocked after repeated failed logins, or you suspect the account has been compromised and want the mail logs checked, open a ticket with Noiz support. Include the email address concerned and the device or client that is failing, and the support team will take it from there.
# How to Change an FTP Account Password in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-change-an-ftp-account-password-in-directadmin/
FTP accounts are the credentials that let a person, a design agency, a deployment script or a backup plugin write files into your hosting space. Rotating one of those passwords is the fastest way to cut off access you no longer want, or to recover after a password has been shared too widely. This guide shows you how to change the password on an additional FTP account from the DirectAdmin control panel on your Noiz hosting, and what else you need to update afterwards so nothing silently breaks.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin documentation: FTP](https://docs.directadmin.com/other-hosting-services/ftp/)
- [DirectAdmin documentation home](https://docs.directadmin.com/)
## Prerequisites
- Your DirectAdmin login details for the hosting account. Noiz sends these in your welcome email, and they are also listed in your Noiz client area.
- At least one additional FTP account already created. If you have not created one yet, see [How to Create an FTP Account in DirectAdmin](/directadmin/how-to-create-an-ftp-account-in-directadmin/).
- A password manager or another safe place to store the new password. DirectAdmin does not show it again once you leave the page.
- A list of anything that logs in with this account, such as an FTP client, an IDE, a backup plugin or a deployment job.
## Which FTP Account Are You Changing?
DirectAdmin treats two kinds of FTP login differently, and picking the wrong one is the most common reason this task goes sideways.
- **The main FTP account.** This shares its username with your DirectAdmin account and cannot be given a separate password. To change it you change your DirectAdmin account password itself, which also changes the password you use to log in to the control panel and to any shell access on the account. Only do this if that is genuinely what you want.
- **Additional FTP accounts.** These are the ones you created yourself, usually in the `username@yourdomain.com` form, each scoped to a folder. Their passwords are independent of your panel login, and they are the accounts the steps below apply to. If you are handing access to a contractor, this is the type of account you should be using.
If the goal is to stop someone accessing your files permanently rather than to rotate a password, suspending or deleting the account is cleaner than changing the password. See [How to Suspend an FTP Account in DirectAdmin](/directadmin/how-to-suspend-an-ftp-account-in-directadmin/) or [How to Remove an FTP Account in DirectAdmin](/directadmin/how-to-remove-an-ftp-account-in-directadmin/).
## Change the Password
### Step 1: Open FTP Management
Log in to your DirectAdmin account. In the **Account Manager** section, click **FTP Management**. If the menu is long, type `FTP Management` into the navigation filter box at the top of the sidebar and the entry will appear.

If **FTP Management** is not listed at all, the feature is switched off on your hosting package. Contact Noiz support and it can be enabled for you.
### Step 2: Select the FTP account
The page lists every FTP account on the hosting account, along with the directory each one is restricted to. Click the account you want to change. Check the path in the same row before you click, because usernames on similar domains are easy to confuse and there is no undo once the password is replaced.

### Step 3: Set the new password
Type the new password into the **Enter Password** field and repeat it in the confirmation field, or click **Generate Random Password** to have DirectAdmin create a strong one for you. The random option is the better choice: FTP accounts are a favourite target for automated login attempts, and a generated password will not be guessed.
Copy the password into your password manager *now*, before you go any further. DirectAdmin stores the password as a hash, so neither you nor Noiz support can read it back afterwards. If you lose it, the only fix is to set it again.

### Step 4: Save the change
Click **Modify**. DirectAdmin confirms the change and the new password takes effect immediately for new connections.
An FTP session that is already open stays authenticated until it disconnects, so close and reopen your FTP client if you want to be certain the old password is out of use.
## Update Everything That Used the Old Password
This is the step people skip, and it is where the support tickets come from. Changing the password in DirectAdmin does nothing to the copies of it saved elsewhere, and every one of those will start failing on its next connection attempt. Work through:
- **FTP clients**, including saved entries in a site manager or bookmark list.
- **Code editors and IDEs** with publish or deploy profiles pointed at the site.
- **Backup and migration plugins** in WordPress or another CMS that push archives over FTP.
- **Deployment pipelines and scheduled jobs** that upload builds. These usually fail silently and only surface as a stale website.
- **Anyone you shared the old password with**. Send the new one over a channel that is not email if you can, or better, give them their own FTP account so the next rotation affects only them.
One practical warning: a script or plugin that retries a failed login on a schedule can rack up dozens of failures in a few minutes, and the brute-force protection on the server will block the source IP address. Update or disable the automated jobs before they start retrying, not after.
## Connect Using Explicit FTP over TLS
Plain FTP sends your username and password across the network in clear text. On a shared office network, a public hotspot or an untrusted uplink, anyone in a position to watch the traffic can read the credentials you have just changed, which defeats the point of changing them.
Noiz hosting supports **explicit FTP over TLS**, usually shown in FTP clients as *Require explicit FTP over TLS* or *FTPES*. Set your connection up like this:
- **Protocol:** FTP, with encryption set to explicit FTP over TLS.
- **Host:** your domain name, for example `yourdomain.com`, replacing that with your own domain.
- **Port:** `21`. Explicit TLS upgrades the standard FTP port rather than using a separate one.
- **Username:** the full FTP username exactly as it appears in **FTP Management**, including the `@yourdomain.com` part where present.
- **Transfer mode:** passive, which is what most networks and firewalls expect.
Set the client to refuse an unencrypted fallback rather than to "use TLS if available". A client that quietly downgrades gives you the appearance of encryption without the substance. If your client offers a plain FTP option and an FTPES option side by side, always choose FTPES.
## Troubleshooting
**Symptom**: the client reports `530 Login authentication failed`. The username is usually the culprit rather than the password. Additional FTP accounts need the full `user@yourdomain.com` form, not just the part before the `@`. Copy it straight from the **FTP Management** list.
**Symptom**: the login worked a moment ago and now every attempt times out or is refused outright. Repeated failures have most likely tripped the server's brute-force protection and your IP address is blocked for a period. Stop retrying, and contact Noiz support with your current public IP address if you need it cleared sooner.
**Symptom**: the connection succeeds but the directory listing is empty or hangs. This is almost always a passive-mode or firewall issue rather than an authentication one. Switch the client to passive mode and try again from a different network to confirm.
**Symptom**: the certificate warning names a different hostname than your domain. This happens when the FTP service presents the server's own certificate. Verify the details before accepting, and contact Noiz support if you are unsure whether the certificate is legitimate.
**Symptom**: the website has stopped updating since the password change. A deployment job or backup plugin is still using the old credentials. Check the tool's own logs, update the stored password and run it manually once to confirm.
## Need a Hand?
If an FTP password change has locked out a live deployment, or you suspect an FTP account was used by someone who should not have had it, open a support ticket from your Noiz client area. The Noiz team can confirm what connected and when, clear a brute-force block on your IP address, and help you move contractors onto separate, directory-scoped FTP accounts so future rotations affect one person rather than everyone.
# How to Change the Email Sending Limit in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-change-the-email-sending-limit-in-directadmin/
Every mailbox on a DirectAdmin account carries a **send limit**: a cap on how many messages that address is allowed to send in a day. This guide shows you where to change it, and, just as importantly, explains what the number actually controls so you set it to something useful rather than guessing.
The limit you set on an individual mailbox is a ceiling *within* the allowance your hosting plan already has. You can lower it, and you can raise it up to the maximum the server administrator permits, but you cannot push a single mailbox past the account-wide allowance.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: E-Mail maintenance and customisation](https://docs.directadmin.com/other-hosting-services/email/index.html)
- [DirectAdmin Docs: Preventing outgoing spam (how send limits are enforced)](https://docs.directadmin.com/other-hosting-services/preventing-spam/outgoing-spam.html)
- [DirectAdmin Docs: Reducing sending spam score](https://docs.directadmin.com/other-hosting-services/email/reducing-sending-spam-score.html)
## Prerequisites
- Your DirectAdmin login details, supplied by Noiz when the hosting account was set up.
- At least one mailbox already created on the domain. If you have not created one yet, see [How to Create an Email Account in DirectAdmin](/directadmin/how-to-create-an-email-account-in-directadmin/).
- The sending allowance that applies to your hosting plan. If you are not sure what it is, ask Noiz support before you start rather than discovering it when a change silently fails to take effect.
## What the Send Limit Actually Controls
Before you change the number, it is worth knowing what it counts. Getting this wrong is the usual reason a mailbox keeps hitting its limit even after it has been raised.
- **It is a daily cap, not a total.** The counter resets, so a mailbox that stops sending will start working again on its own once the day rolls over. You do not need to do anything to unblock it.
- **Every send route counts against the same allowance.** Webmail, Outlook or Thunderbird, a phone's mail app, and any website script or plugin authenticating as that address over SMTP all draw from one pool.
- **Recipients matter, not just messages.** One message addressed to fifty people is not one send. Treat a mailing list as consuming a large share of the allowance, not a single unit of it.
- **The mailbox limit sits under an account-wide ceiling.** The server keeps a separate cap covering everything sent by your hosting account. If you set one mailbox to a very high figure, that mailbox still stops when the account total is reached, so raising one address can quietly starve the others.
- **The limit exists to contain damage.** If a mailbox password is ever compromised, the send limit is what stops a spam run at a few hundred messages instead of a few hundred thousand, and it is what protects the sending reputation of every other domain on the platform. That is why the ceiling is enforced rather than advisory.
## Changing the Send Limit
### 1. Log in to DirectAdmin
Sign in to your DirectAdmin account using the details Noiz provided.
### 2. Open E-mail Accounts
In the **E-mail Manager** section, click **E-mail Accounts**. If you cannot see the section, type **E-mail Accounts** into the **navigation filter** box at the top of the sidebar and the option will appear. Click it.

### 3. Find the mailbox in the account list
Under the **Account list**, each email address appears on its own row with a **plus icon** on the **right-hand side**.

### 4. Open Change Limits
Click the **plus icon** for the address you want to change and choose **Change Limits**.

### 5. Set the new send limit
Adjust the **Send Limit** field to the figure you need. The value shown in the screenshot below is only an example of what the field looks like in use; it is not a Noiz limit and it is not a recommendation. Set it to what your own plan allows and what the mailbox genuinely needs.
If an **Unlimited** option is available and your plan permits it, you can select that instead. Where the option is greyed out or missing, your hosting plan has a fixed ceiling and the field is capped accordingly.

The same dialog also holds the mailbox disk quota. If you need to adjust that at the same time, see [How to Change the Email Account Disk's Quota in DirectAdmin](/directadmin/how-to-change-an-email-accounts-disk-quota-in-directadmin/).
### 6. Save
Click **Save**. The new limit applies immediately to messages sent from that point onward. It does not retroactively clear a mailbox that has already hit the old limit today, so if the address is currently blocked, expect it to resume after the daily counter resets.
## Choosing a Sensible Number
Higher is not better. A send limit set far above what a mailbox realistically needs removes the only automatic brake on a compromised account.
- **Ordinary staff mailbox:** a modest daily figure covers normal correspondence comfortably. Most people never come close.
- **Website or application sender** (contact forms, order confirmations, password resets): size it against actual traffic and leave headroom for a busy day, not for a hypothetical one.
- **Newsletters and bulk mail:** do not solve this with a large send limit. Shared hosting mail is not built for bulk campaigns, and pushing volume through it damages deliverability for your own domain. Use a dedicated bulk email service and keep the hosting mailbox for individual correspondence.
You can see what a mailbox is actually sending in the **E-mail Manager** section, under **E-mail Usage**. Check the real figures before deciding a limit is too low.
## Troubleshooting
**Symptom: the new limit will not save, or reverts to a lower figure.** You have asked for more than your hosting plan allows. The account-wide ceiling wins. Contact Noiz support to discuss the allowance on your plan.
**Symptom: mail still stops sending after raising the limit.** The account-wide daily total has most likely been reached by the other mailboxes on the account, not by this one. Review usage across all addresses rather than raising a single mailbox further.
**Symptom: a mailbox burns through its limit unexpectedly.** This is the classic signature of a compromised password or an insecure website script being abused as a relay. Change the mailbox password immediately, check for a script sending on that address, and contact Noiz support. Raising the limit in this situation makes the problem worse.
**Symptom: messages send fine but land in recipients' spam folders.** That is a deliverability issue, not a limit issue, and raising the send limit will not help. SPF, DKIM and DMARC records for the domain are what determine whether receiving servers trust your mail.
## Need a Hand?
If you are unsure what allowance your plan carries, or a mailbox is hitting its limit and you cannot see why, contact Noiz support through the client area. On managed plans Noiz will review the sending pattern on the account, confirm the ceiling that applies, and advise whether a higher limit or a different approach is the right fix.
# How to Change the PHP Version via CloudLinux Selector in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-change-the-php-version-via-cloudlinux-selector-in-directadmin/
The CloudLinux **Select PHP Version** tool lets you change the PHP version your websites run on, from inside your DirectAdmin account, without opening a support ticket and without any server-level access. This guide shows you where the tool lives on Noiz DirectAdmin hosting, how to switch versions safely, and what the switch does and does not change.
You will see this feature referred to by several names: **Select PHP Version**, **PHP Selector**, and **CloudLinux Selector**. They all mean the same tool.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and the CloudLinux PHP Selector. PHP branch support was checked the same day against the official PHP release feed, where **8.2, 8.3, 8.4 and 8.5** are the actively supported branches. This guide is written for Noiz hosting and is kept current against DirectAdmin and CloudLinux. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [CloudLinux OS: PHP Selector component reference](https://docs.cloudlinux.com/shared/cloudlinux_os_components/#php-selector)
- [DirectAdmin documentation](https://docs.directadmin.com/)
- [PHP: supported versions and end-of-life dates](https://www.php.net/supported-versions.php)
## Prerequisites
- An active Noiz hosting account on a DirectAdmin server with CloudLinux PHP Selector enabled.
- Your DirectAdmin username and password.
- A recent backup of the site you are about to change, or at least the confidence that you can roll back by selecting the previous version again.
## Change the PHP Version
### Step 1: Log in to DirectAdmin
Log in to your DirectAdmin account using the URL and credentials supplied in your Noiz welcome email.
### Step 2: Open Select PHP Version
In the **Extra Features** section, click **Select PHP version**. If you cannot see the section, type **Select PHP** into the navigation filter box at the top of the sidebar and click the result when it appears.

### Step 3: Choose the version you want
To the right of **Current PHP version**, click the drop-down menu and choose the version you want to use.

Older branches are usually still listed. Being listed is not the same as being supported: PHP branches that have reached end of life no longer receive security patches from the PHP project, so treat them as a short-term compatibility crutch rather than a place to sit. Pick the newest branch your application, theme and plugins are tested against.
### Step 4: Apply the change
Click **Set as current**. The change takes effect within a few seconds for new requests, so there is no need to restart anything.

Reload your website and confirm it still loads correctly. If your application exposes a PHP info page or a system status screen, use that to confirm the version actually reported by the web server.
## What the Change Affects
- **Scope.** The PHP Selector setting applies at the DirectAdmin account level, so every domain and subdomain under that account inherits it unless a per-domain override is in place. If you host several sites under one account and only one of them needs an older branch, move that site to its own account rather than holding everything back.
- **Extensions.** Each PHP branch keeps its own extension set. After switching, extensions you enabled on the previous branch are not carried across automatically, so recheck them. See [How to Enable or Disable PHP Extensions Using the CloudLinux Selector in DirectAdmin](/directadmin/how-to-enable-or-disable-php-extensions-using-cloudlinux-selector-in-directadmin/).
- **PHP settings.** Values such as `memory_limit`, `max_execution_time` and `upload_max_filesize` are also held per branch in the Selector, so a limit you raised on the old version may read back at its default on the new one.
- **Command line and cron.** Scheduled tasks that call `php` directly may still resolve to a different binary than your websites use. If a cron job starts behaving differently after a switch, call the version explicitly in the cron command rather than relying on the default path.
- **Caching.** Opcode caches are per version. Expect the first few requests after a switch to be slightly slower while the cache is rebuilt.
## Troubleshooting
**Symptom**: **Select PHP version** is missing from the dashboard. The navigation filter is the fastest check; if the tool genuinely does not appear, the account is either on a server without PHP Selector or on a plan where the option is not exposed. Open a ticket with Noiz support and the version will be set for you.
**Symptom**: the site returns a blank page or an HTTP 500 error straight after the switch. The new branch has almost certainly removed a function or syntax your code still uses. Select the previous version and click **Set as current** to roll back, then update the application, theme and plugins before trying again.
**Symptom**: the application complains that an extension is missing. The extension was enabled on the old branch only. Re-enable it for the branch you have just moved to.
**Symptom**: the version in the Selector does not match what a PHP info page reports. A handler directive in a `.htaccess` file, or a per-domain override, is taking priority over the account setting. Remove or correct the directive, or ask Noiz support to check the domain-level configuration.
**Symptom**: a site works but is noticeably slower after the change. Confirm that the opcode cache has warmed up, then recheck the per-branch PHP settings, since a much lower `memory_limit` on the new branch is the usual cause.
## Need a Hand?
If you are not sure which PHP branch your site can safely run on, or a switch has broken something you cannot roll back cleanly, contact Noiz support with your domain name and the version you were moving from and to. On managed plans, Noiz will test the change and apply it for you.
# How to Check or Optimise a Database in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-check-or-optimise-a-database-in-directadmin/
Databases pick up two kinds of wear over time: internal inconsistencies that make queries return errors, and wasted space left behind by deleted or updated rows. DirectAdmin exposes two one-click maintenance actions for exactly this. **Check** examines a database and reports whether its tables are sound, and **Optimize** rebuilds the tables to reclaim unused space and tidy up the on-disk layout. Some guides call the first action "examining" the database. It is the same thing.
This guide shows you how to run both from the DirectAdmin control panel on your Noiz hosting account, explains what each action actually does so you know which one you need, and covers the results you are likely to see.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin: MariaDB and MySQL](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/index.html)
- [DirectAdmin: MariaDB and MySQL troubleshooting](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/troubleshooting.html)
- [MariaDB: CHECK TABLE](https://mariadb.com/kb/en/check-table/)
- [MariaDB: OPTIMIZE TABLE](https://mariadb.com/kb/en/optimize-table/)
- [MySQL: OPTIMIZE TABLE](https://dev.mysql.com/doc/refman/8.4/en/optimize-table.html)
## Prerequisites
- An active Noiz hosting account with DirectAdmin access, and your DirectAdmin username and password.
- At least one database on the account. If you have not created one yet, see [How to Create a Database in DirectAdmin](/directadmin/how-to-create-a-mysql-database-in-directadmin/).
- A current backup, if the database is behind a live site. Optimising rebuilds tables, so take a copy first: [How to Download a Database Backup from DirectAdmin](/directadmin/how-to-download-a-database-backup-from-directadmin/).
## Check or Optimise a Database
### 1. Log in to DirectAdmin
Sign in to your DirectAdmin account with the username and password on your Noiz welcome email.
### 2. Open MySQL Management
In the **Account Manager** section, click **MySQL Management**. If you cannot see it, type `MySQL Management` into the navigation filter box at the top of the menu and the option will appear. Click it.

### 3. Select the databases you want to work on
From the list of databases, tick the one you want. You can tick more than one, and DirectAdmin will run the same action against every database you have selected.

### 4. Run Check or Optimize
Click **Check** to examine the selected databases, or **Optimize** to rebuild and compact them. A report is displayed once the action finishes, listing every table that was processed and the result for each one.
## Which One Do You Need?
The two buttons solve different problems, and running the wrong one wastes time without changing anything.
- **Check** is a read-only health test. It reports whether each table's data and indexes are internally consistent. Nothing is modified. Run it when a site throws database errors, when a page returns partial data, or when you simply want confirmation that the database is sound. Check never repairs anything. If it reports a problem, follow up with [How to Repair a Database in DirectAdmin](/directadmin/how-to-repair-a-database-in-directadmin/).
- **Optimize** is a housekeeping action. Deleting rows does not automatically shrink a table file, and heavily updated tables end up fragmented, so the table occupies more disk than the data inside it actually needs. Optimising rebuilds the table, reclaims that space and refreshes the index statistics the query planner uses. It does not fix corruption.
## What to Expect in the Report
- `OK` against a table means the action completed with nothing to report. This is the normal result.
- `Table is already up to date` is a success message, not an error. You will see it often when optimising, and it is the standard response for storage engines that handle their own space reuse internally.
- `note: Table does not support optimize, doing recreate + analyze instead` is also normal and also a success. The table is rebuilt and its statistics are recalculated, which achieves the same goal by a different route.
- Anything reporting a table as corrupt, crashed or in need of repair is a genuine fault. Do not keep running **Optimize** against it. Move to the repair procedure instead.
## Things Worth Knowing Before You Optimise
- **Optimising needs free disk space.** The rebuild writes a fresh copy of the table before swapping it in, so you need roughly as much free space as the largest table being processed. If your account is close to its disk quota, clear space first or the operation can fail part way through.
- **Tables are busy while the work runs.** Depending on the storage engine, the table can be locked or under heavy input and output for the duration. On a large database this is noticeable to visitors. Run it during a quiet period rather than at peak traffic.
- **Once in a while is enough.** Optimising after a large deletion, a bulk import or a plugin clear-out is sensible. Scheduling it nightly is not: the churn costs more in disk activity than the fragmentation it removes.
- **Optimising is not a performance fix on its own.** If a site is slow, the cause is far more often a missing index, an oversized options or metadata table, or an application accumulating expired temporary records, than it is fragmentation. Optimise by all means, then look at what the application is actually storing.
- **Only your own databases are listed.** DirectAdmin shows the databases belonging to your account. A database created under a different hosting account will not appear here.
## Troubleshooting
- **Symptom**: MySQL Management is missing from the menu. Type `MySQL Management` into the navigation filter box. If it still does not appear, the feature is not enabled on your package, so contact Noiz support.
- **Symptom**: the Check report flags a table as crashed or corrupt. Optimising will not help. Use the repair procedure, and if repair does not clear it, restore the most recent backup.
- **Symptom**: **Optimize** runs but the database size barely changes. That is expected on engines that reuse freed space internally, and expected again if you optimised recently. The space is available for new rows even though the file on disk has not shrunk.
- **Symptom**: the page appears to hang on a very large database. The action is still running server side. Give it time rather than clicking again, because a second request against the same tables only adds load.
- **Symptom**: an error mentioning disk space or quota. Free space on the account, then retry. The rebuild cannot complete without room for a temporary copy of the table.
## Need a Hand?
If a check reports damage you are not comfortable acting on, or a database is large enough that you would rather not run maintenance against it during business hours, open a ticket with Noiz support. The support team can run the maintenance for you, confirm the results and restore from backup if anything needs undoing.
# How to Create a Domain Alias in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-create-a-domain-alias-in-directadmin/
A domain alias lets a second domain name serve the same website as your main domain, while keeping its own name in the browser address bar. If your main site is `example.com` and you add `example.net` as an alias, a visitor who types `example.net` sees the same site and the address bar still reads `example.net`. DirectAdmin creates aliases through the **Domain Pointers** tool, so the two names are often confused. This guide shows you how to create one on your Noiz DirectAdmin hosting, and explains what the alias does and does not share with the main domain.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: general panel usage](https://docs.directadmin.com/directadmin/general-usage/)
- [DirectAdmin Docs: DNS](https://docs.directadmin.com/other-hosting-services/dns/)
- [DirectAdmin Forums: the difference between an alias and a pointer](https://forum.directadmin.com/threads/what-is-difference-between-an-alias-and-a-pointer.20483/)
## Alias or Pointer: Decide Before You Click
Both are created from the same screen, and the single **Create as an Alias** tick box is what separates them. Choose deliberately, because the visitor experience is different.
- **Alias** (tick box ticked): the second domain keeps its own name in the address bar and behaves as a full alternative name for the account. Mail, FTP and the website all answer on the alias name.
- **Pointer** (tick box left clear): the second domain redirects the visitor to your main domain, and the address bar changes to the main domain. Use this when you have bought a misspelling or an old trading name and want everyone funnelled to one canonical address. That procedure is covered in [How to Create a Domain Pointer in DirectAdmin](/directadmin/how-to-create-a-domain-pointer-in-directadmin/).
A useful rule of thumb: if you care about the second domain being visible as a brand, create an alias. If you only want the traffic and do not want the second name showing anywhere, create a pointer.
## Prerequisites
- An active Noiz DirectAdmin hosting account, with a main domain already set up.
- The alias domain registered and under your control.
- The alias domain delegated to the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za` at its registrar, or its DNS pointed at your hosting IP address if you keep DNS elsewhere.
- A free domain pointer allowance on your hosting package. Each alias consumes one pointer slot.
- The alias domain must not already exist as a full domain anywhere on the server, including under another account.
## Create the Domain Alias
1. Log in to your DirectAdmin account.
2. In the **Account Manager** section, click **Domain Pointers**. If you cannot see it, type `Pointers` into the navigation filter box at the top of the sidebar and the option appears. 
3. Click **Create Domain Pointer** at the top right of the page. 
4. Under **Source Domain**, enter the domain you want to add as an alias, for example `yourdomain.com`. Enter it without `www.` and without `http://`. DirectAdmin adds the `www` variant for you. 
5. Tick **Create as an Alias**. This is the step that makes the difference between an alias and a redirect, and it cannot be changed afterwards. To switch later you have to remove the entry and create it again.
6. Click **Create**.
The alias appears in the pointer list against your main domain and starts working as soon as DNS for the alias domain resolves to your hosting.
## What the Alias Shares With Your Main Domain
An alias is not a second hosting account. It is a second name for the one you already have, and that has practical consequences worth knowing before you rely on it.
- **Website files:** shared. Both names serve the same document root, so there is one website to update, not two. You cannot give the alias its own separate content.
- **Email:** shared. Mail sent to `sales@aliasdomain.com` is delivered to the `sales@` mailbox on the main domain. You do not create separate mailboxes for the alias, and you cannot give the same local part two different destinations across the two names.
- **Databases, FTP and cron:** shared, because they belong to the account rather than to the domain name.
- **DNS:** DirectAdmin creates a DNS zone for the alias so it resolves to your hosting. If you manage the alias domain's DNS at a third party such as Cloudflare, the records there are what count, and you need an A record pointing at your hosting IP address.
- **SSL:** not automatic. A certificate issued for your main domain does not cover the alias. You need to reissue the certificate with the alias name included, otherwise visitors on the alias see a certificate name mismatch warning.
If you need the second domain to have its own website content, its own mailboxes or its own statistics, do not use an alias. Add it as a separate domain under **Domain Setup** instead, assuming your package allows more than one domain.
## Troubleshooting
**Symptom**: the alias domain shows a browser security warning about the certificate name. The certificate covers the main domain only. Reissue it with the alias included, using **SSL Certificates** under **Account Manager** and selecting the alias in the list of names to include. The alias must already resolve to your hosting before validation will succeed.
**Symptom**: the alias still loads the old site, or does not load at all. DNS has not caught up. Confirm the alias domain is delegated to `ns1.noiz.co.za` and `ns2.noiz.co.za` at its registrar, then allow for propagation. Changes are usually visible within a few hours and can take up to 48 hours worldwide.
**Symptom**: DirectAdmin refuses to create the pointer and reports that the domain already exists. The name is already present on the server, either as a full domain under your account or under a different account. Remove it from wherever it lives first, or contact Noiz support if it is not under your control.
**Symptom**: the address bar changes to your main domain when you visit the alias. The **Create as an Alias** tick box was not ticked, so a redirecting pointer was created instead. Remove the entry and create it again with the box ticked.
**Symptom**: the site loads on the alias but internal links and images still use the main domain. That is the application, not DirectAdmin. Content management systems such as WordPress store an absolute site address and rewrite links to it. Aliases are best suited to sites that use relative links, or to cases where a single canonical address is acceptable.
## Related Articles
- [How to Remove a Domain Alias in DirectAdmin](/directadmin/how-to-remove-a-domain-alias-in-directadmin/)
- [How to Create a Domain Pointer in DirectAdmin](/directadmin/how-to-create-a-domain-pointer-in-directadmin/)
- [How to Remove a Domain Pointer in DirectAdmin](/directadmin/how-to-remove-a-domain-pointer-in-directadmin/)
- [How to Add a Subdomain in DirectAdmin](/directadmin/how-to-add-a-subdomain-in-directadmin/)
If you are not sure whether an alias or a separate domain is the right fit, or you need the SSL certificate reissued to cover the new name, open a ticket from your Noiz client area and the support team will set it up for you.
# How to Create a Domain Pointer in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-create-a-domain-pointer-in-directadmin/
A **domain pointer** lets a second domain name send visitors to a site you already host. If your primary domain is `yourdomain.com` and you create a pointer for `yourdomain.net`, anyone who types `yourdomain.net` lands on the `yourdomain.com` site. This is the usual way to catch spelling variants, an old domain you have replaced, or the other extension of a name you have registered twice. Both names above are examples, so read them as your own two domains throughout.
DirectAdmin handles pointers and aliases on the same screen, separated by a single tick box, and the two behave quite differently. This guide shows you how to create a pointer on your Noiz hosting account, explains exactly how a pointer differs from an alias so you pick the right one, and covers the DNS step that catches most people out.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin: DNS](https://docs.directadmin.com/other-hosting-services/dns/index.html)
- [DirectAdmin: maintaining DNS records](https://docs.directadmin.com/other-hosting-services/dns/maintaining-records.html)
- [DirectAdmin: ACME and SSL certificates for domains](https://docs.directadmin.com/webservices/ssl/ssl-and-letsencrypt-for-domains.html)
## Prerequisites
- An active Noiz hosting account with DirectAdmin access, and your DirectAdmin username and password.
- The primary domain already set up and working on the account. The pointer attaches to an existing site, it does not create one.
- A second domain name that you have registered and can change nameservers or DNS records for.
- The second domain must not already exist as a full domain on the server, on your account or anyone else's. DirectAdmin will refuse to create a pointer for a name that is already hosted.
## Create the Domain Pointer
### 1. Log in to DirectAdmin
Sign in to your DirectAdmin account with the username and password on your Noiz welcome email.
### 2. Open Domain Pointers
In the **Account Manager** section, click **Domain Pointers**. If you cannot see it, type `Pointers` into the navigation filter box at the top of the menu and the option will appear. Click it.

### 3. Start a new pointer
Click **Create Domain Pointer**, at the top right of the page.

### 4. Enter the source domain
Under **Source Domain**, type the second domain name, the one you want visitors to arrive on. Enter it as the bare name, such as `yourdomain.net`, with no `www.` and no `http://`. Replace `yourdomain.net` with your own domain.
If your account holds more than one site, check the domain selector at the top of the page first. The pointer is created against whichever domain is currently selected, and that is the site visitors will end up on.

### 5. Leave Create as an Alias unticked
Make sure **Create as an Alias** is **not** ticked. That box is what turns a pointer into an alias, and the two are not the same thing. Then click **Create**.
The new pointer appears in the list on the Domain Pointers page straight away. The web side of the job is now done, and the DNS side is next.
## Point the Domain's DNS at Noiz
Creating the pointer only tells the server what to do with requests for that domain once they arrive. It does nothing at the domain's registrar, so the domain still needs to be sent to the server before anything happens in a browser.
The straightforward way is to set the pointer domain to the same nameservers as the site it points to. At the registrar for the pointer domain, set the nameservers to the Noiz client nameservers:
```
ns1.noiz.co.za
ns2.noiz.co.za
```
DirectAdmin creates a DNS zone for the pointer domain automatically when you create the pointer, so once the delegation is in place there is nothing further to configure.
If you would rather leave the pointer domain's DNS with a third party, that also works. In that case do not change the nameservers, and instead create an `A` record at the current DNS host for the bare domain and for `www`, both aimed at your hosting account's IP address. You will find that address on the DirectAdmin home page or in your Noiz welcome email.
Nameserver changes propagate at their own pace. Allow up to 24 hours, and up to 48 in the worst cases, before deciding something is wrong.
## Pointer or Alias: Which Do You Want?
Both are created from the same screen. The **Create as an Alias** tick box is the only difference, and it changes the behaviour completely.
- **Pointer** (box unticked). The second domain redirects. A visitor who types `yourdomain.net` is sent on to `yourdomain.com`, and the address bar changes to show `yourdomain.com`. The site has one address as far as the visitor and search engines are concerned. Under the bonnet DirectAdmin gives the pointer domain its own web server entry that does nothing but issue the redirect. Choose this for old domains, misspellings, and alternative extensions you own defensively.
- **Alias** (box ticked). The second domain serves the same site under its own name. A visitor who types `yourdomain.net` sees your site with `yourdomain.net` still in the address bar, because the alias is added as an extra name on the primary domain's existing web server entry rather than as a separate redirecting one. Some panels and hosts call this a parked domain. Choose this when both names need to be genuinely usable, for example a brand trading under two names.
To create an alias instead, follow [How to Create a Domain Alias in DirectAdmin](/directadmin/how-to-create-a-domain-alias-in-directadmin/).
## Things Worth Knowing
- **A pointer is a web redirect, not a mailbox.** Creating a pointer does not give you email addresses on the second domain, and mail sent to that domain is not aliased across to the primary domain's mailboxes. Aliases do mirror email in that way. If you need working email on the second name and nothing else about the alias behaviour suits you, add it as a full domain under **Domain Setup** instead of pointing it.
- **HTTPS still needs a certificate.** If visitors reach the pointer domain over `https://`, the certificate presented has to cover that name, otherwise the browser shows a security warning before the redirect ever happens. Include the pointer domain when you request or renew the certificate in **SSL Certificates**. A certificate issued only for the primary domain will not silently cover the pointer.
- **The www version is included.** DirectAdmin sets up both the bare name and the `www` host for a pointer, so you do not need a second pointer for `www.yourdomain.net`.
- **Force Redirect applies to pointers too.** The `www` or non-`www` preference you set under **Domain Setup** for the primary domain is applied to its pointers as well. If you have forced one form on the main site, expect the same behaviour on the pointer.
- **Pointers are counted by your package.** Hosting packages carry a limit on how many domain pointers an account may hold. If the **Create Domain Pointer** button is missing or the creation fails on a limit message, the allowance is used up. Contact Noiz support about raising it.
- **Redirect, not duplicate content.** Because a pointer sends visitors on to the primary domain, search engines see one site rather than two copies. That is usually what you want. If you specifically need the second name to stay in the address bar, you want an alias, and you should then decide how to handle canonical tags on the site itself.
## Troubleshooting
- **Symptom**: the pointer domain shows a "server not found" or registrar parking page. DNS has not been changed or has not propagated yet. Confirm the nameservers at the registrar are `ns1.noiz.co.za` and `ns2.noiz.co.za`, then wait. Nothing on the hosting side can speed this up.
- **Symptom**: DirectAdmin refuses the pointer and says the domain already exists. The name is already set up as a full domain, either on your account under **Domain Setup** or on another account on the server. Remove it as a full domain first, or contact Noiz support if it is not on your account.
- **Symptom**: the browser warns about the certificate before redirecting. The certificate does not cover the pointer domain. Reissue it from **SSL Certificates** with the pointer domain included.
- **Symptom**: the address bar keeps showing the primary domain when you wanted the second name visible. That is a pointer working exactly as designed. You need an alias instead. Remove the pointer, then create it again with **Create as an Alias** ticked.
- **Symptom**: a redirect loop, or the page never finishes loading. Check for a competing redirect in the site's own `.htaccess` file or in a content management system's site address setting. An application that rewrites every request to its configured domain can fight with the panel level redirect.
- **Symptom**: email to the pointer domain bounces. Expected. A pointer does not carry mail. Add the domain properly under **Domain Setup** if it needs mailboxes.
## Related Guides
- [How to Create a Domain Alias in DirectAdmin](/directadmin/how-to-create-a-domain-alias-in-directadmin/)
- [How to Remove a Domain Pointer in DirectAdmin](/directadmin/how-to-remove-a-domain-pointer-in-directadmin/)
## Need a Hand?
If the pointer is created but the domain still will not resolve, or you are not sure whether your situation calls for a pointer, an alias or a full second domain, open a ticket with Noiz support. Include the domain name and what you expect visitors to see, and the support team will check the DNS delegation and the account configuration for you.
# How to Create a MySQL Database in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-create-a-mysql-database-in-directadmin/
Almost every dynamic website needs a database behind it. WordPress, Joomla, Magento, Laravel and most custom PHP applications all expect a MySQL or MariaDB database to be waiting for them before installation begins. This guide shows you how to create one from your DirectAdmin control panel on Noiz hosting, and explains the two things that catch people out afterwards: the account name prefix DirectAdmin adds to the database name, and which host name your application should connect to.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin: MariaDB and MySQL](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/index.html), including remote access hosts and server-level behaviour.
- [DirectAdmin: phpMyAdmin](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/phpmyadmin.html), for working inside a database once it exists.
- [DirectAdmin: database backup, restore and recovery](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/backup-restore-recovery.html).
## Prerequisites
- An active Noiz hosting account on a DirectAdmin server, plus your DirectAdmin username and password. Both are in your Noiz welcome email, along with the control panel address to log in at.
- A free database slot on your hosting package. Each plan allows a set number of databases, and the counter includes any you created earlier and forgot about.
- Somewhere safe to record the credentials, ideally a password manager. The database password is shown to you once, at creation, and is not retrievable afterwards.
## Creating the Database
### Step 1: Open MySQL Management
Log in to DirectAdmin. In the **Account Manager** section of the menu, click **MySQL Management**. If the menu is long, type `MySQL Management` into the **navigation filter** box at the top of the sidebar and the entry will filter into view.

### Step 2: Start a new database
The MySQL Management page lists every database on your account. Click **Create New Database** at the top right of the page.

### Step 3: Fill in the Create Database form
DirectAdmin asks for three things:
1. **Database Name**: type only the suffix you want. The greyed-out box to its left already contains your account name and the underscore that DirectAdmin adds automatically.
2. **Database User**: leave **Same as database name** ticked and DirectAdmin creates a matching user and grants it full rights on the new database in one step. Untick it only if you want a differently named user.
3. **Database Password**: type one, or click the generator icon at the left of the field to have DirectAdmin produce a strong random password. The eye icon at the right of the field reveals the value so you can copy it accurately.
Click **Create Database**.

### Step 4: Record the credentials before you leave the page
The confirmation screen shows the finished database name, the user name and the password. Copy all three somewhere safe now. DirectAdmin stores the password as a hash, so nobody at Noiz can read it back to you later. If it is lost, the only route forward is to set a new one, which is covered in [How to Change a Database Password in DirectAdmin](/directadmin/how-to-change-a-database-password-in-directadmin/).
## Understanding the Account Name Prefix
This is the single most common source of confusion, so it is worth being precise about it.
DirectAdmin prefixes every database and every database user with your account name and an underscore. If your account name is `example` and you type `shop` into the form, the database that actually exists on the server is `example_shop`, and the matching user is `example_shop`. The prefix is not optional and cannot be removed. It is what keeps your databases separate from every other account on a shared server.
Three practical consequences follow:
- **Use the full name everywhere.** In `wp-config.php`, `configuration.php`, a Laravel `.env` file or any installer, enter `example_shop`, not `shop`. A plain `shop` produces an "Unknown database" or "Error establishing a database connection" message.
- **Migrations need the connection details rewritten.** A site moved from another host almost certainly used a different account name, so its old database name will not exist here. Import the data, then update the site's configuration file to the new name, user and password. The table contents and table names do not change, only the connection details.
- **Mind the length.** MySQL and MariaDB cap identifiers at 64 characters, and the prefix counts towards that limit. Keep the suffix short and stick to letters, numbers and underscores. Other characters are either rejected by the form or become awkward to quote in SQL and shell commands later.
## Connecting Your Application
Once the database exists, an application hosted on the same Noiz server connects with these four values:
- **Database host**: `localhost`. This is correct for anything running on your own hosting account, which covers virtually every website install. Do not use your domain name or the server's IP address.
- **Database name**: the full prefixed name, for example `example_shop`.
- **Database user**: the full prefixed user name.
- **Password**: the one you set or generated in step 3.
Connecting from your own PC, from a desktop tool or from a server elsewhere is a different matter. Remote MySQL access is blocked by default, and it stays blocked until the connecting IP address is added to the database user's **Allowed Hosts** list in MySQL Management. Treat this as a last resort rather than a convenience: a database reachable from the open internet is a far larger target than one reachable only from its own web server. For routine work on the data itself, use phpMyAdmin from inside DirectAdmin, which needs no remote access at all.
## Troubleshooting
**Symptom**: the **Create New Database** button is missing, or creation fails with a limit message. Your package's database allowance is already used up. Delete a database you no longer need, or contact Noiz support about moving to a plan with a higher allowance.
**Symptom**: the form rejects the name you typed. The suffix contains a space, a full stop or another disallowed character, or the combined name exceeds 64 characters. Shorten it and use only letters, numbers and underscores.
**Symptom**: a database with that name already exists. Database names are unique per server, and your prefix makes them unique across accounts, so this means you have used the suffix before on this account. Check the list on the MySQL Management page before choosing another.
**Symptom**: "Error establishing a database connection" after installing your site. In nearly every case the configuration file is missing the account name prefix on the database name, the user name, or both. Check those first, then confirm the host is set to `localhost` and that the password was copied without a trailing space.
**Symptom**: the application connects but reports missing tables or permission errors. The database exists but its user has no rights on it, which happens if **Same as database name** was unticked and a user was created separately. Assign the privileges as described in [How to Modify a Database User's Privileges in DirectAdmin](/directadmin/how-to-modify-a-database-users-privileges-in-directadmin/).
## Next Steps
- [How to Create a New Database User in DirectAdmin](/directadmin/how-to-create-a-new-database-user-in-directadmin/), for adding a second user to an existing database.
- [How to Modify a Database User's Privileges in DirectAdmin](/directadmin/how-to-modify-a-database-users-privileges-in-directadmin/), for granting or restricting what a user may do.
- [How to Change a Database Password in DirectAdmin](/directadmin/how-to-change-a-database-password-in-directadmin/), for when a password is lost or needs rotating.
If the database will not create, or an application still refuses to connect after you have checked the prefix and the host, open a ticket from your Noiz client area with the database name and the exact error message. Noiz support can confirm what exists on the server and get the connection working with you.
# How to Create a New Database User in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-create-a-new-database-user-in-directadmin/
A database user is the account your website or application uses to log in to MySQL/MariaDB. Creating a database on its own is not enough: nothing can read or write to it until a user is attached to it. This guide shows you how to create a new database user in DirectAdmin on Noiz hosting, and covers the naming rules, password handling and connection details that trip people up afterwards.
DirectAdmin refers to this area as **MySQL Management**. You may also see it described as "database management" or "MySQL databases" in application install guides. It is the same screen.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: MariaDB / MySQL](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/)
- [DirectAdmin Docs: Evolution skin](https://docs.directadmin.com/directadmin/skins-and-templates/evolution.html)
- [MariaDB Knowledge Base: GRANT and privilege reference](https://mariadb.com/kb/en/grant/)
## Prerequisites
- An active Noiz hosting account on a DirectAdmin server, and your DirectAdmin login details.
- An existing database to attach the user to. If you have not created one yet, start with [How to Create a Database in DirectAdmin](/directadmin/how-to-create-a-mysql-database-in-directadmin/).
- Somewhere safe to store the username and password, such as a password manager. The password is shown once and is not recoverable in plain text afterwards.
## Create the Database User
### Step 1: Log in to DirectAdmin
Sign in to your DirectAdmin account. If you are unsure of the control panel address for your hosting package, it is listed on your Noiz welcome email and in the Noiz client area under your hosting service.
### Step 2: Open MySQL Management
In the **Account Manager** section, click **MySQL Management**. If you cannot see the icon, type `MySQL Management` into the **navigation filter** box at the top of the menu and click the result that appears.

### Step 3: Select the database
From the list of **databases**, click the database you want to create the user for. Database names carry your account username as a prefix, in the form `youruser_dbname`, so pick carefully if you host several sites on one account.

### Step 4: Choose Create New User
Under **Users**, click **Create New User**. The existing users attached to this database are listed here too, so this is also the screen you return to if you need to change a password or remove an old user later.

### Step 5: Set the username and password
Enter the new username, then either type a password into the **password** field or click the **Generate Random Password** icon to have DirectAdmin create a strong one for you. Click **Create** to finish.

Copy the newly created database user details to a safe place before you leave the page.
## What to Know Before You Use the New User
- **The username is prefixed automatically.** DirectAdmin prepends your account username, so a user you name `shop` becomes something like `youruser_shop`. Always use the full prefixed name in your application configuration, not the short part you typed.
- **Keep the suffix short.** MySQL and MariaDB impose a maximum length on user names, and the prefix counts towards it. A short, descriptive suffix such as `wp`, `shop` or `crm` avoids the name being rejected or truncated.
- **The connection host is normally `localhost`.** When the website and the database live on the same Noiz server, your application connects using `localhost` as the database host. Only use a hostname or IP address if you are connecting from somewhere else, and see the remote access note below.
- **Generated passwords are safer than invented ones.** Database credentials sit in a plain text configuration file such as `wp-config.php`, so they are only ever typed once. There is no benefit to a memorable password, and a long random one removes the risk of a brute force attempt against the database.
- **Avoid special characters that break configuration files.** If you set the password yourself, characters such as `$`, `'` and `\` can be interpreted by PHP or by shell scripts rather than passed through as part of the password. The generated password is the safer route.
- **Give each application its own user.** If one site is compromised, a shared database user hands the attacker access to every database that user can reach. One user per application keeps the damage contained.
## Set the Privileges
Creating the user attaches it to the database you opened it from. Review what the user is actually allowed to do before you put it into production: most applications need only the standard read and write privileges, and a user with fewer rights is a smaller target. To adjust them, follow [How to Modify a Database User's Privileges in DirectAdmin](/directadmin/how-to-modify-a-database-users-privileges-in-directadmin/).
## Troubleshooting
**Symptom**: The application reports "Access denied for user". Check that you used the full prefixed username, that the password was copied without a leading or trailing space, and that the host is set to `localhost`. A password containing a character your configuration file treats as special is the most common cause when everything else looks correct.
**Symptom**: The username is rejected as too long. Shorten the part you type. The account prefix and the underscore both count towards the database engine's limit.
**Symptom**: The user connects but cannot create or alter tables. The privileges granted are too narrow for what the application is doing, typically during an installation or an upgrade. Adjust them using the privileges guide linked above.
**Symptom**: An external tool or a remote server cannot connect. Database users are restricted to connections from the server itself by default. Remote connections require an access host entry for the database and an open route to the MySQL port, which Noiz keeps closed by default for security. Open a support ticket describing what needs to connect and from where, and Noiz will advise on the safest way to do it.
## Removing a Database User
Deleting a database user does not delete the database or its data, so it is safe to remove users you no longer need. Do it from the same **Users** list under the database. Retiring the credentials of a decommissioned site or a departed developer is good housekeeping and takes seconds.
## Need a Hand?
If you are unsure which privileges an application needs, or a database connection is failing after a migration, open a support ticket from the Noiz client area with the database name and the exact error message. Noiz support can check the user, its privileges and the server side of the connection for you.
# How to Create an Email Account in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-create-an-email-account-in-directadmin/
This guide shows you how to create a new email account (a mailbox) on a Noiz hosting plan that uses the DirectAdmin control panel. A mailbox is a real, self-contained account with its own password, its own storage and its own inbox, which is different from a forwarder (which only redirects mail to somewhere else) and different from a catch-all (which sweeps up mail sent to addresses that do not exist).
DirectAdmin calls this area **E-mail Manager**, and you may also see it referred to as "Email Manager" or "Mail Accounts" in older guides. The steps below are the same either way.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: E-mail overview](https://docs.directadmin.com/other-hosting-services/email/index.html)
- [DirectAdmin Docs: Autodiscover and autoconfig for mail clients](https://docs.directadmin.com/other-hosting-services/email/autodiscover.html)
- [DirectAdmin Docs: Reducing your sending spam score](https://docs.directadmin.com/other-hosting-services/email/reducing-sending-spam-score.html)
- [DirectAdmin Docs: E-mail troubleshooting](https://docs.directadmin.com/other-hosting-services/email/troubleshooting.html)
## Prerequisites
- A Noiz hosting plan on DirectAdmin, and the DirectAdmin login details from your welcome email.
- The domain you want the address on already added to the account. If you have several domains on the plan, note which one the new address belongs to.
- Room left in your plan for another mailbox. Plans cap both the number of email accounts and the total disk space, and a mailbox draws from the same disk allocation as your website files.
- A safe place to record the new password, such as a password manager. DirectAdmin does not show a password again after the account is created.
## Create the Email Account
### Step 1: Log in to DirectAdmin
Sign in to DirectAdmin using the panel URL, username and password from your Noiz welcome email. Make sure you are at **User** level rather than Reseller or Admin level. If the top of the screen shows a level switcher, set it to **User Level**, because the E-mail Manager only appears there.
### Step 2: Open E-mail Accounts
In the **E-mail Manager** section, click **E-mail Accounts**. If you prefer to search rather than scroll, type `E-mail Accounts` into the **navigation filter** box at the top of the page and the option appears immediately.

### Step 3: Click Create Account
The **E-mail Accounts** page lists every mailbox that already exists on the domain. Click **Create Account** at the top right of the page.

If you host more than one domain on the plan, check the domain selector at the top of the page first. DirectAdmin creates the mailbox on whichever domain is currently selected, and moving an address between domains later means creating it again and migrating the mail.
### Step 4: Enter the username and password
In the **Username** field, type only the part that goes before the `@` sign, for example `my-first-email`. DirectAdmin appends the domain for you, so the finished address reads `my-first-email@yourdomain.com` (replace `yourdomain.com` with your own domain).
Then set a password. Click the **Generate Random Password** icon if you would rather DirectAdmin produce a strong one for you.

A few things worth knowing before you commit to a name:
- **Use a long, unique, random password.** Mailboxes are the single most attacked part of any hosting account, because a working mailbox password lets an attacker send spam through the server and read password reset emails for every other service you own. Never reuse a password you already use elsewhere.
- **Keep the username simple.** Lower case letters, numbers, dots, hyphens and underscores are safest. Avoid spaces and accented characters, because some sending systems mishandle them.
- **Role addresses attract spam.** Generic addresses such as `info@`, `sales@` and `admin@` are guessed by spammers constantly. They are perfectly fine to use, but expect more junk on them than on a personal address, and never use one as the login for something sensitive.
- **You cannot rename a mailbox later.** DirectAdmin has no rename function for email accounts, so a typo means deleting the account and creating it again.
### Step 5: Set the quota and send limit, then create the account
Adjust the email **quota** and the **Send Limit**, or leave them at their defaults, then click **Create Account**.
- **Quota** is the maximum size of this mailbox in megabytes. In DirectAdmin a value of `0` means unlimited, which in practice means limited only by the total disk space on your plan. Setting a real number on each mailbox is the safer choice, because one runaway mailbox then cannot fill the whole account and take your website offline with it.
- **Send Limit** is the maximum number of messages this address may send per day. It exists to contain the damage if the password is ever stolen, so leaving a sensible limit in place protects the server's sending reputation and, by extension, your own deliverability. Raise it only if the address genuinely needs to send more, for example a shop sending order confirmations.
Once you click **Create Account**, copy the new address and password somewhere safe straight away. DirectAdmin stores the password as a hash and cannot show it to you again, so if you lose it you will need to set a new one.
## After the Mailbox Exists
The mailbox is usable immediately through webmail on the same server. Sending and receiving from the outside world also depends on your domain's DNS, so:
- **The domain's MX records must point at your Noiz DirectAdmin server** for mail from other people to arrive. If the domain's DNS is managed somewhere else, or its email is still pointed at a previous provider, the mailbox will exist but stay empty.
- **SPF and DKIM should be in place** before you send in volume, otherwise recipients are far more likely to treat your mail as spam.
- **Always connect over the secure ports.** For a mail client, use IMAP on port `993` with SSL/TLS and SMTP on port `465` with SSL/TLS, with authentication switched on and your full email address (not just the username) as the login name, unless your Noiz welcome email states otherwise.
## Troubleshooting
**Symptom: "Cannot create e-mail account" or a limit error.** Your plan's email account limit or disk quota is already reached. Delete a mailbox you no longer use, reduce another mailbox's quota, or ask Noiz support about a larger plan.
**Symptom: the address exists but receives nothing.** Mail for the domain is being delivered elsewhere. Check that the domain's MX records point at your Noiz DirectAdmin server, and allow for DNS propagation after any change.
**Symptom: the mail client refuses the password.** Log in to webmail with the same details first. If webmail works, the client is at fault: confirm the login name is the full email address, that SSL/TLS is enabled, and that SMTP authentication is turned on.
**Symptom: sending stops partway through the day.** The daily **Send Limit** for that address has been reached. Raise it if the volume is legitimate, and treat an unexpected limit hit as a possible sign that the mailbox has been compromised.
**Symptom: the mailbox fills up quickly.** Raise the quota, clear out large attachments, or empty the Junk and Trash folders. Bear in mind that mailbox storage comes out of the same disk allocation as your website.
## Related Guides
- [How to Change an Email Account's Password in DirectAdmin](/directadmin/how-to-change-an-email-accounts-password-in-directadmin/)
- [How to Change the Email Account Disk's Quota in DirectAdmin](/directadmin/how-to-change-an-email-accounts-disk-quota-in-directadmin/)
- [How to Access Your Email From DirectAdmin](/directadmin/how-to-access-your-email-from-directadmin/)
## Need a Hand?
If the mailbox will not create, mail is not arriving, or you are not sure whether your domain's MX records point at the right place, open a support ticket from your Noiz client area with the full email address and the exact error you see. On a managed plan, Noiz will create the mailbox and confirm the mail routing for you.
# How to Create an FTP Account in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-create-an-ftp-account-in-directadmin/
Your main DirectAdmin username and password already work as an FTP login, and that login lands in your home directory with access to every domain, every `public_html` and every log file on the account. That is fine for you, but it is far too much access to hand to a designer, a developer or a client who only needs one folder. This guide shows you how to create a separate FTP account in DirectAdmin, scoped to a single directory, and explains the account type choice that decides exactly what that account can reach.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: FTP](https://docs.directadmin.com/other-hosting-services/ftp/) (server-side reference: which FTP daemon runs and how it is debugged)
- [DirectAdmin Docs](https://docs.directadmin.com/) (full documentation index)
## Prerequisites
- A Noiz hosting account on DirectAdmin, and your DirectAdmin login details.
- The domain the new FTP account should be attached to, already added to the account.
- A decision about which folder the account holder actually needs. Read the account type section below before you fill in the form, because the type cannot be guessed later from the username.
## Create the FTP Account
1. Log in to your DirectAdmin account.
2. In the **Account Manager** section, click **FTP Management**. If you cannot see it, type **FTP Management** into the **navigation filter** box at the top of the sidebar and the entry will appear. Click it. 
3. Click **Create FTP Account**, at the top right of the FTP Management page. 
4. Enter the **FTP Username**, for example `firstuser`, then set and confirm a password. DirectAdmin appends the domain for you, so the finished login will be `firstuser@yourdomain.com` (replace `yourdomain.com` with your own domain). Then choose the account type: **Domain**, **FTP**, **User** or **Custom**. 
5. Click **Create**.
The account is created immediately and DirectAdmin displays the login details. Copy them somewhere safe, because the password is not shown again. If you lose it, you can set a new one rather than recreating the account.
## Choosing the Account Type
This is the real decision on the form. The type sets the directory the account is locked into, and the account holder cannot move above it. Assume your DirectAdmin username is `exampleuser`, your domain is `yourdomain.com` and the new FTP user is `firstuser`.
- **Domain**: lands in `/home/exampleuser/domains/yourdomain.com`. The account sees the whole domain folder, which includes `public_html`, `private_html`, the logs and the stats directories. Choose this for a developer who is working on the live site and may need to look at more than the web root.
- **FTP**: lands in `/home/exampleuser/domains/yourdomain.com/public_ftp`. This is the public FTP directory, not the website. Files placed here are not served by your website unless you deliberately link them. Choose this only when you are genuinely running a file drop, not when someone needs to edit the site.
- **User**: lands in `/home/exampleuser/domains/yourdomain.com/public_html/firstuser`, a subfolder inside the web root named after the FTP user. Choose this when someone should only touch one section of the site, such as a landing page or a microsite. Anything they upload is publicly reachable at `https://yourdomain.com/firstuser/`, so do not treat this folder as private storage.
- **Custom**: lands wherever you type. Choose this when none of the above match, for example an assets folder or a staging subdirectory. Point it at a path that already exists under the account's home directory; if the path is wrong or missing, the account will either be refused at login or drop into an empty folder with nothing to upload into.
If you are not sure, **Domain** is the usual answer for a person working on the website, and **User** is the usual answer for a person who should be kept to one corner of it.
## Connecting With the New Account
- **Host**: your domain, for example `yourdomain.com`, or the server hostname shown in your Noiz welcome email.
- **Username**: the full `firstuser@yourdomain.com`, not just `firstuser`. This is the single most common cause of a failed login.
- **Port**: `21`.
- **Encryption**: choose **Explicit FTP over TLS** (FTPS) in your FTP client. Plain FTP sends the username and password across the network in clear text, so there is no good reason to use it when your client supports FTPS.
- **Transfer mode**: passive. Most clients default to passive already, and active mode frequently stalls behind home and office routers.
## Troubleshooting
- **Login is rejected with an authentication failure**: you almost certainly entered the username without the domain. Use `firstuser@yourdomain.com` in full.
- **The account connects but the folder is empty, or the website files are missing**: the account type is pointing somewhere other than where you expected. A **User** account only sees its own subfolder, and an **FTP** account sees `public_ftp` rather than the website. Recreate the account with the correct type.
- **The account holder cannot move up out of their folder**: that is the intended behaviour. The directory chosen at creation is the ceiling, which is the entire point of a separate FTP account.
- **The connection hangs after login, when the directory listing should appear**: switch the FTP client to passive mode, and allow it through any local firewall.
- **The password was lost**: do not recreate the account and risk breaking someone's saved connection. Set a new password instead, using the guide linked below.
## Related Guides
- [How to Change an FTP Account Password in DirectAdmin](/directadmin/how-to-change-an-ftp-account-password-in-directadmin/)
- [How to Suspend an FTP Account in DirectAdmin](/directadmin/how-to-suspend-an-ftp-account-in-directadmin/)
- [How to Remove an FTP Account in DirectAdmin](/directadmin/how-to-remove-an-ftp-account-in-directadmin/)
If you would rather not hand out FTP access at all, or you are unsure which folder a contractor should be limited to, open a support ticket from your Noiz client area with the domain name and what the person needs to do. Noiz will set the account up with the narrowest access that still gets the job done.
# How to Create and Download a Full Backup of Your Account in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-create-and-download-a-full-backup-of-your-account-in-directadmin/
DirectAdmin lets you package your entire hosting account into a single compressed archive and download it to your own computer. In DirectAdmin's own terminology this is a **Site Backup**, the user-level version of the DirectAdmin backup system, and it is the same archive format used for account moves between servers. That matters, because a Site Backup is not just a copy of your files: it is a restorable snapshot of your websites, email accounts and their messages, FTP accounts, databases and DNS-adjacent settings, all in one `.tar.gz` file.
This guide covers creating the backup and then downloading it, which are two separate jobs in DirectAdmin. The backup is generated on the server first and dropped into your account's `backups` directory, and only then do you fetch it with File Manager. If you are looking for a smaller, targeted export rather than the whole account, or you already have an archive and want to put it back, see the related guides at the end.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its **Evolution** skin, which is the interface Noiz DirectAdmin accounts use. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: Backup / Restore / Migration overview](https://docs.directadmin.com/directadmin/backup-restore-migration/)
- [DirectAdmin Docs: User-level Backup/Restore settings (what each checkbox includes)](https://docs.directadmin.com/directadmin/backup-restore-migration/index.html#user-level-backup-restore-settings)
- [DirectAdmin Docs: File Manager](https://docs.directadmin.com/directadmin/customizing-workflow/filemanager.html)
- [DirectAdmin Docs: Message System (where the completion notice appears)](https://docs.directadmin.com/directadmin/general-usage/message-system.html)
- [DirectAdmin Docs: Evolution skin](https://docs.directadmin.com/directadmin/skins-and-templates/evolution.html)
## Prerequisites
- Your DirectAdmin login details and panel address, both of which are in your Noiz welcome email.
- Enough free disk space on the account to hold the archive. The backup is written into your own home directory before you download it, so an account sitting close to its quota cannot produce one. See the disk space note below.
- A few minutes. Backups are queued rather than produced instantly, and a large mailbox is usually what makes the wait noticeable.
## Part 1: Create the Backup
### Step 1: Log In to DirectAdmin
Sign in to DirectAdmin with the username and password from your welcome email. You land on the user-level dashboard, with the navigation menu grouped into sections such as **Account Manager**, **E-mail Manager**, **Advanced Features** and **System Info & Files**.
### Step 2: Open Create/Restore Backups
In the **Advanced Features** section, click **Create/Restore Backups**. If you would rather not hunt through the menu, type `backup` or `restore` into the navigation filter box at the top of the sidebar and the entry appears straight away.

### Step 3: Choose What to Include
Under **Site Backup**, tick the items you want in the archive. The options are grouped so you can take everything or trim the archive down:
- **Website Data**: the domains directory (all files for all your domains) and your subdomain lists.
- **E-mail**: the account list with passwords, the actual message data from Inbox and IMAP folders, filters and catch-all settings, forwarders, autoresponders and vacation messages.
- **FTP**: FTP accounts and their settings.
- **Database**: database settings and database users, plus the database data itself. These are two separate ticks, and taking the data without the settings gives you an archive that restores tables but not the users that connect to them.
- **Trash**: deleted trash data, which is rarely worth including.
For a genuine full backup, tick everything. If you are only after part of the account, leaving items unticked keeps the archive smaller and faster, and email data is almost always the bulk of it.

### Step 4: Start the Backup
Scroll to the bottom of the page and click **Create Backup**.
### Step 5: Wait for the Completion Notice
DirectAdmin responds immediately with a message along the lines of **Backup creation added to the queue**. That is confirmation the job was accepted, not that it has finished. The work happens in DirectAdmin's task queue in the background, so you can close the page and come back later.
When the archive is ready, DirectAdmin posts a message to its own internal message system, reachable from the **Support & Help** section under **Support Center** (also shown as a message or bell indicator in the header once something is waiting). Open it to confirm the backup completed rather than failing partway.

## What the Backup Does and Does Not Contain
This is the part people usually find out about at the worst possible moment, so it is worth two minutes now.
**It contains** the items you ticked in step 3, packaged so that DirectAdmin can restore them in one operation, either back into your own account or into a fresh DirectAdmin account elsewhere.
**It does not contain** anything DirectAdmin deliberately skips inside your home directory. The skipped list includes the backup directories themselves (`backups`, `user_backups`, `admin_backups`, which prevents a backup from recursively swallowing older backups) along with system-ish paths such as `usr`, `bin`, `etc`, `lib`, `lib64`, `tmp`, `var`, `sbin` and `dev`. The practical consequence: anything you have parked outside your domain directories, particularly under `~/var`, is not in the archive. If you keep files somewhere unusual, move or symlink them into `public_html` before backing up.
**It is a point-in-time snapshot.** If your site is taking orders or accepting form submissions while the archive is being written, activity during that window may or may not be captured. For a migration or a risky update, take the backup during quiet hours, or put the site into maintenance mode first.
**It is not a substitute for server-side backups.** A Site Backup you download and keep off the server is genuinely useful precisely because it lives somewhere the server cannot reach. Treat it as your own copy, taken before you change something, rather than as your only line of defence.
## Part 2: Download the Backup
The archive is now sitting on the server in your account's `backups` directory. Downloading it is a File Manager job.
### Step 1: Open File Manager
Back on the user-level dashboard, open the **System Info & Files** section and click **File Manager**. The navigation filter box works here too: type `file` and the entry appears.

### Step 2: Open the backups Directory
File Manager opens at the root of your home directory. Click into the **backups** folder. Your archive is the `.tar.gz` file with the most recent timestamp. If several are listed, check the date and size columns rather than trusting the order on screen.

### Step 3: Download the File
Right-click the archive and choose **Download** from the context menu. The file transfers to your computer over your browser's normal download mechanism.

Large archives are the one place this can go wrong. A multi-gigabyte download through a browser is at the mercy of your connection staying up, and there is no resume. If the account is large, connect over SFTP or FTP with a proper client instead, point it at the `backups` directory and pull the file that way, which gives you resume support and a checksum you can trust.
### Step 4: Verify, Then Tidy Up
Once the download has finished, open the archive locally to confirm it is not truncated. Any standard archive tool will do, and on macOS or Linux `tar -tzf yourbackup.tar.gz | head` lists the first entries without extracting anything. A file that will not open is a file that will not restore.
Then delete the copy on the server. Backups sit inside your home directory and count towards your account's disk quota, so leaving a few of them there is a common and entirely avoidable reason for an account to run out of space. They are excluded from future backups, but they are not excluded from your quota.
## Troubleshooting
**Symptom**: The backup never appears and no completion message arrives. The most likely cause is insufficient disk space. DirectAdmin has to build the archive inside your own home directory, so an account already near its quota cannot create one. Clear old backups, caches and logs, then try again. Check your usage under **System Info & Files**.
**Symptom**: The message system reports the backup finished with errors. Read the message body rather than acting on the summary. It normally names the specific component that failed, most often a database or a mailbox, and a partial archive will restore that component incorrectly or not at all.
**Symptom**: The download stops partway or the resulting file will not open. The browser transfer was interrupted. Retry, and if it fails again use an SFTP client against the `backups` directory instead.
**Symptom**: The file has a `.tar.zst` extension rather than `.tar.gz`. Some DirectAdmin servers are configured to use zstd compression, which produces smaller archives faster. It restores exactly the same way. On your own machine you need a tool that understands zstd, such as a current build of `tar` with `zstd` installed, or 7-Zip on Windows.
**Symptom**: You want the backup to run automatically every night. The user-level Site Backup interface has no scheduling option by design; scheduled backups are configured above user level. If you need a recurring account backup, raise it with the Noiz support team rather than trying to script it from inside the account.
**Symptom**: The archive is far larger than you expected. Email data is almost always the reason. Empty old Trash and Junk folders, archive mailboxes nobody reads, then take the backup again.
## Related Guides
- [How to Download Email, FTP, or a Database-only Backup from DirectAdmin](/directadmin/how-to-download-email-ftp-or-a-database-only-backup-from-directadmin/)
- [How to Restore a Backup you Generated Earlier in DirectAdmin](/directadmin/how-to-restore-a-previously-generated-backup-in-directadmin/)
## Need a hand?
Backups are the one task where it is worth being certain rather than hopeful, especially before a migration, a major update or a change you are not sure about. If the backup will not complete, the archive is too large to download comfortably, or you want a scheduled backup arranged for your account, contact the Noiz support team through the client area with your domain name and the exact wording of any error message, and the team will sort it out with you.
# How to Delete a Database in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-delete-a-database-in-directadmin/
This guide shows you how to permanently remove a MySQL or MariaDB database from your hosting account using the DirectAdmin control panel. It is written for the account (user) level of DirectAdmin, which is the level Noiz hosting customers log in to.
**Deleting a database is immediate and permanent.** DirectAdmin does not move the database to a recycle bin and there is no undo button. Take a backup first, every time, even when you are certain the database is unused.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: MariaDB and MySQL](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/)
- [DirectAdmin Docs: MySQL backup, restore and recovery](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/backup-restore-recovery.html)
- [DirectAdmin Docs: the Evolution interface](https://docs.directadmin.com/directadmin/skins-and-templates/evolution.html)
## Prerequisites
- Your DirectAdmin login details, from your Noiz welcome email or the Noiz client area.
- A current backup of the database. See [How to Download a Database Backup from DirectAdmin](/directadmin/how-to-download-a-database-backup-from-directadmin/).
- Confirmation that no live website or application still points at the database.
## Before You Delete Anything
Two minutes of checking here saves hours of recovery later.
- **Download a fresh backup.** Existing account backups may be days old, and they are not a substitute for a dump taken right before deletion. Follow [How to Download a Database Backup from DirectAdmin](/directadmin/how-to-download-a-database-backup-from-directadmin/) and keep the `.sql` or `.gz` file somewhere off the server.
- **Check the exact database name.** DirectAdmin prefixes every database with your account username, so your databases look like `username_wp1`, `username_wp2` and `username_shop`. The names are similar by design, and deleting the wrong one is the single most common mistake on this screen.
- **Confirm nothing is using it.** Open the application's configuration file and read the database name it actually uses: `wp-config.php` for WordPress, `configuration.php` for Joomla, `app/etc/env.php` for Magento, or `.env` for Laravel. Match that name against the one you are about to delete.
- **Note the database users.** Deleting a database does not necessarily tidy up the MySQL users that were created to access it. Make a note of which users are attached, so you can clean up afterwards.
## Delete the Database
### Step 1: Log in to DirectAdmin
Log in to your DirectAdmin account using the URL and credentials supplied by Noiz. If you cannot find them, they are available in the Noiz client area or from Noiz support.
### Step 2: Open MySQL Management
In the **Account Manager** section, click **MySQL Management**. If you cannot see the tile, type `MySQL Management` into the **navigation filter** box at the top of the sidebar and click the result.

### Step 3: Select the Database
The page lists every database on the account, along with its size and the users assigned to it. Tick the checkbox next to the database you want to remove. You can tick more than one, but be careful: the deletion applies to everything you have selected, and a single confirmation covers the whole selection.
Read the full name once more before continuing, including the `username_` prefix.

### Step 4: Confirm the Deletion
Click **Delete**. DirectAdmin asks you to confirm, so click **Delete** again on the confirmation prompt. This second click is the point of no return.

### Step 5: Verify and Tidy Up
The database disappears from the list and the storage it used is released back to your account quota. The database also stops counting against the database limit on your hosting plan, which frees a slot if you were at the ceiling.
Now review the remaining entries in **MySQL Management**. If a database user existed only to serve the database you just deleted, remove it as well so that no unused credentials are left active on the account. Leave any user that is still attached to another database.
## Troubleshooting
**Symptom**: your website shows "Error establishing a database connection" or a similar database error after the deletion. The site was still using that database. Recreate a database with the same name, recreate the database user with the same username and password, then import the `.sql` dump you took beforehand. See [How to Create a Database in DirectAdmin](/directadmin/how-to-create-a-mysql-database-in-directadmin/), and note that passwords are not stored inside a dump file, so the application's configuration file may also need updating.
**Symptom**: the **Delete** button does nothing. No database is selected. Tick the checkbox in the left-hand column of the row first, then click **Delete**.
**Symptom**: the database still appears in the list after deleting it. Refresh the page with a hard reload to clear the cached view. If it genuinely persists, contact Noiz support.
**Symptom**: **MySQL Management** is not present in **Account Manager**. Your hosting package may not include database access, or the feature may be disabled on the account. Contact Noiz support to check.
**Symptom**: you deleted the database and have no backup. Noiz keeps server-level backups on managed hosting, and a restore may be possible depending on the age of the loss. Open a support ticket immediately and stop making further changes to the account, because continued activity reduces what can be recovered.
## Getting Help
If you are unsure which database an application uses, or you need a deletion reversed, Noiz support can help. On managed Noiz hosting plans, support will identify the correct database, take a verified backup and perform the deletion for you. Open a ticket from the Noiz client area with the account username and the database name involved.
# How to Disable Apache SpamAssassin in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-disable-apache-spamassassin-in-directadmin/
This guide shows you how to switch off Apache SpamAssassin for your DirectAdmin account on Noiz hosting. Disabling it stops SpamAssassin scoring your incoming mail and stops any action you had built on that score, such as tagging subject lines or moving suspected spam to a separate folder. You may see the feature referred to as **SpamAssassin Setup**, spam filtering, or simply the spam filter; they all refer to the same tool inside DirectAdmin.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin and Apache SpamAssassin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: Preventing SPAM](https://docs.directadmin.com/other-hosting-services/preventing-spam/)
- [DirectAdmin Docs: Filtering incoming spam](https://docs.directadmin.com/other-hosting-services/preventing-spam/incoming-spam.html)
- [Apache SpamAssassin: Documentation](https://spamassassin.apache.org/doc.html)
- [Apache SpamAssassin: Configuration reference](https://spamassassin.apache.org/full/4.0.x/doc/Mail_SpamAssassin_Conf.html)
## Prerequisites
- Your DirectAdmin username and password for your Noiz hosting account.
- SpamAssassin currently enabled on the account. If it is already off, the **Disable SpamAssassin** button will not be shown.
- A note of your current spam score threshold and the action you have set, in case you want to restore the same configuration later.
## Read This Before You Disable Spam Filtering
Turning SpamAssassin off means **every message addressed to your account is delivered unfiltered**. Nothing is scored, nothing is tagged, and nothing is diverted to a spam folder. Phishing attempts, scam invoices, and bulk marketing all land in the same inbox as legitimate mail, and the volume increase on a long-published address can be substantial.
Disabling is the right move in a small number of cases, for example when you are diagnosing a delivery problem and need to prove that the spam filter is not the cause, or when a downstream system of your own already filters the mail. In most other situations, tuning the filter is a better answer than switching it off. See [Better Alternatives to Disabling](#alternatives) below.
## Disable SpamAssassin in DirectAdmin
1. Log in to your DirectAdmin account.
2. In the **E-mail Manager** section, click **SpamAssassin Setup**. If you cannot see the section, type `SpamAssassin Setup` into the navigation filter box at the top of the sidebar and the item will appear. Click it. 
3. Click **Disable SpamAssassin**. The button sits at the top right of the SpamAssassin Setup page. 
4. DirectAdmin confirms that SpamAssassin has been disabled. The change applies to mail arriving from that point onward.
## What Changes After You Disable It
- **New mail is no longer scored or tagged.** Subject-line tagging, spam headers, and any rule you had set to act on a score all stop.
- **Mail already in a spam folder stays there.** Disabling the filter does not move older messages back to your inbox, so check that folder before you empty it.
- **Anything already deleted stays deleted.** If your action was set to delete high-scoring mail, disabling stops future deletions but recovers nothing.
- **Server-side protections are separate.** Noiz applies mail platform protections at the server edge, and those are independent of your account-level SpamAssassin setting. Disabling SpamAssassin changes only the per-account filtering you control.
- **Your mail client keeps its own junk filter.** Outlook, Thunderbird, Apple Mail, and webmail junk folders work independently. If mail is still being filed as junk after you disable SpamAssassin, the client is doing it, not the server.
## Better Alternatives to Disabling
If the real problem is that legitimate mail is being caught, one of these usually solves it without leaving the account unprotected:
- **Raise the score threshold.** A higher required score makes the filter less aggressive while still catching obvious spam. Move in steps of one point rather than jumping several at once.
- **Change the action instead of the sensitivity.** Setting SpamAssassin to move suspected spam to a folder, rather than delete it, means nothing is ever lost while you tune the score.
- **Allowlist the sender.** If a single supplier or client keeps getting flagged, add that address or domain to the allowlist in **SpamAssassin Setup** and leave the rest of the filtering alone.
- **Block a specific nuisance sender.** If the goal is the opposite, stopping one persistent sender, see [How to Block Email Using Spam Filters in DirectAdmin](/directadmin/how-to-block-an-email-address-using-spam-filters-in-directadmin/).
## Re-enabling SpamAssassin
You can turn the filter back on at any time from the same **SpamAssassin Setup** page. Set your score threshold and delivery action again after enabling, then send yourself a test message to confirm the filter is running. Full steps are in [How to Enable Apache SpamAssassin in DirectAdmin](/directadmin/how-to-enable-apache-spamassassin-in-directadmin/).
## Troubleshooting
**Symptom**: There is no **Disable SpamAssassin** button. SpamAssassin is already disabled on the account. The page will offer an enable option instead.
**Symptom**: **SpamAssassin Setup** does not appear in the sidebar. The feature is not present on your hosting package, or you are logged in at the wrong level. Confirm you are in the user-level view rather than a reseller or admin view, then open a support ticket with Noiz if it is still missing.
**Symptom**: Mail is still going to a Spam or Junk folder after disabling. The filing is being done by your mail client or webmail junk filter, or by a forwarding rule elsewhere. Check the junk settings in the client you actually read mail in, and check for any account-level filters or forwarders in DirectAdmin.
**Symptom**: Spam volume becomes unmanageable within days. That is the expected outcome of unfiltered delivery on an exposed address. Re-enable SpamAssassin and tune the score threshold rather than leaving it off.
## Need a Hand?
If you are disabling SpamAssassin to chase down a delivery problem, Noiz can check the mail logs for the message in question and tell you exactly where it was filtered, which is usually faster than switching protection off and waiting. Open a ticket from your Noiz client area with the sending address, the recipient address, and the approximate time the message was sent.
# How to Download Email, FTP, or a Database-only Backup from DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-download-email-ftp-or-a-database-only-backup-from-directadmin/
DirectAdmin lets you back up part of your hosting account instead of all of it. If you only need a copy of your databases before an upgrade, or your email accounts before switching mail client, or your FTP users before handing a site to a developer, there is no need to generate a full account backup and wait for gigabytes of website files you already have.
This guide shows you how to generate a database-only, email-only or FTP-only backup on your Noiz hosting account in DirectAdmin, and then download the resulting file to your own computer.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: Backup / Restore / Migration](https://docs.directadmin.com/directadmin/backup-restore-migration/index.html)
- [DirectAdmin Docs: Backups](https://docs.directadmin.com/directadmin/backup-restore-migration/backups.html)
- [DirectAdmin Docs: Message System](https://docs.directadmin.com/directadmin/general-usage/message-system.html)
- [DirectAdmin Docs: Directories and Locations](https://docs.directadmin.com/directadmin/general-usage/directories-and-locations.html)
## Prerequisites
- Your DirectAdmin login details for your Noiz hosting account.
- Enough free disk space on the account to hold the backup file. The backup is written into your account before you download it, so it counts against your quota while it exists.
- A few minutes. Backups are queued and run in the background, so the file does not appear the instant you click the button.
## Why Take a Partial Backup Rather Than a Full One
A full account backup is the right tool when you are moving a whole site or recovering from a disaster. For everyday work it is usually overkill, and a targeted backup is faster to create, faster to download and far easier to find things in later.
- **Before a plugin, theme or core update:** a database-only backup takes seconds and is the piece you are most likely to need if the update goes wrong.
- **Before reconfiguring mail:** an email-only backup preserves the account names and passwords, so you are not rebuilding twenty mailboxes from memory.
- **Before handing a site to a developer:** an FTP-only backup records the FTP users and their settings, which is the part nobody documents and everybody loses.
- **When disk space is tight:** a full backup can be several times the size of a partial one, and it has to fit on the account before you can download it.
## How to Generate a Database-Only, FTP, or Email Backup
### Step 1: Log in to DirectAdmin
Log in to your DirectAdmin account.
### Step 2: Open Create/Restore Backups
In the **Advanced Features** section of the menu, click **Create/Restore Backups**. If you cannot see it, type **Restore** into the **navigation filter** box at the top of the menu and the option will appear. Click it.

### Step 3: Tick only the data you want
Under **Site Backup**, clear every tick box first, then tick only the items you actually want. For an email-only backup, tick only the options grouped under **E-mail**. For an FTP-only backup, tick only the options under **FTP**. For a database-only backup, tick only the options under **Databases**.

Take a moment over the labels, because they are more literal than they look and this is where most partial backups turn out to be missing the thing the person actually wanted:
- **E-mail Accounts** saves the mailbox names and passwords for all domains on the account. It does not save the messages inside those mailboxes.
- **E-mail Data** is the option that saves the actual messages. If your goal is to preserve mail, this is the one you need, and it is by far the largest of the email options.
- **E-mail Settings** covers filters, forwarders, autoresponders, vacation messages and the catch-all address.
- **Database Settings** saves your database users and their permissions. It does not save the contents of the databases.
- The individual databases are listed separately under **Databases**. Tick the database itself to back up its tables and data, and tick **Database Settings** as well if you want the user accounts that connect to it.
- **FTP Accounts** and **FTP Settings** cover the additional FTP logins you created, not the files they have access to. Website files come from the website data options.
If the page offers a choice of where to store the backup, leave it set to store the file locally in your account. Choosing a remote destination sends the file straight off the server, and it will not appear in your `backups` directory for downloading later.
### Step 4: Create the backup
Scroll to the bottom of the page and click **Create Backup**.
### Step 5: Wait for the confirmation message
DirectAdmin queues the job and shows a message such as *Backup creation added to the queue*. The file is not ready yet. When it is finished, DirectAdmin posts a message to your account saying your backups are now ready.
To check, click your **Username** at the top right and choose **Messages**, or open the **Support & Help** section and go to **Support Center** >> **Messages**.

Small backups usually complete in well under a minute. Large mailboxes and busy databases take longer. Do not click **Create Backup** a second time because nothing has appeared yet, as that simply queues a duplicate job and uses more disk space.
## How to Download the Generated Backup
### Step 1: Log in to DirectAdmin
Log in to your DirectAdmin account.
### Step 2: Open File Manager
In the **System Info & Files** section, click **File Manager**. If you cannot see it, type **File Manager** into the **navigation filter** box and the option will appear. Click it.

### Step 3: Open the backups directory
From the top of your account's file tree, open the **backups** directory. This sits in your home directory, alongside folders such as `domains`, and it is where DirectAdmin writes user-level backups.

### Step 4: Download the file
Right-click your newly generated backup file and choose **Download** from the context menu. The file downloads to your computer.

DirectAdmin names the archive after the date it was created, with a trailing number, and writes it as a `.tar.gz` file. The date is written month first, which catches people out when several backups from the same week are sitting side by side, so read the filename carefully rather than assuming the newest is at the top. The trailing number distinguishes multiple backups taken on the same day, so a `-2` is the second backup that day, not a second part of the first. Check the exact filename in the backups folder before you download.
A `.tar.gz` file is a compressed archive. On macOS and most Linux desktops it opens with a double-click. On Windows you need an archive tool that understands the format, such as 7-Zip. There is no need to unpack it if you are only storing it, and unpacking it is not how you put the data back.
## Tidy Up Afterwards
Backups sit in your account and count towards your disk quota until you remove them. It is easy to generate a handful over a busy month and quietly fill the account, which then starts breaking mail delivery and website uploads for reasons that look unrelated.
Once the file is safely downloaded and you have confirmed it opens, delete it from the server. See [How to Remove a Backup File Using DirectAdmin](/directadmin/how-to-remove-a-backup-file-in-directadmin/).
Keep the downloaded copy somewhere that is not the same machine you work on every day. A backup that lives only on the laptop you are about to spill coffee over is not really a backup.
## Troubleshooting
**Symptom**: the `backups` directory is empty. The job has not finished yet, or it failed. Check your messages first. If a message says the backup completed, make sure you are looking in the `backups` directory in your home directory rather than inside a domain folder.
**Symptom**: the backup failed and mentions disk space. The archive needs room on the account while it is being written. Remove older backup files or unused data and try again, or take the data in smaller pieces, for example one database at a time.
**Symptom**: the file downloaded but is far smaller than expected. You almost certainly ticked **E-mail Accounts** or **Database Settings** without ticking the option that carries the actual data. Generate the backup again with the data options selected.
**Symptom**: the download stalls or the archive will not open. Large files can fail part way through a browser download and still leave a file on disk. Download it again, and if the account is large, use an FTP client to fetch the file from the `backups` directory instead of the browser.
**Symptom**: no confirmation message ever arrives. Check the message area again after a few minutes, since the queue processes jobs in turn and a busy server can take longer. If nothing appears at all, open a ticket with Noiz support rather than repeatedly queueing more backups.
## Related Guides
- [How to Restore a Backup you Generated Earlier in DirectAdmin](/directadmin/how-to-restore-a-previously-generated-backup-in-directadmin/)
- [How to Remove a Backup File Using DirectAdmin](/directadmin/how-to-remove-a-backup-file-in-directadmin/)
## Need a Hand?
If you are backing up ahead of a migration, a major upgrade or a suspected compromise, it is worth getting the selection right the first time. Open a support ticket in the Noiz client area with your domain name and what you are trying to protect, and Noiz support can confirm which options cover it before you rely on the file.
# How to Download a Database Backup from DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-download-a-database-backup-from-directadmin/
DirectAdmin lets you download a copy of any MySQL or MariaDB database on your hosting account straight from the control panel, without needing shell access or a separate export tool. This guide shows you how to do it on your Noiz DirectAdmin hosting, explains the difference between the `.sql` and `.gz` download formats, and covers what the dump does and does not contain so that your backup is actually restorable when you need it.
If you have seen this feature called "database export", "SQL dump" or "mysqldump" elsewhere, it is the same thing. DirectAdmin simply wraps it in a one-click download.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution skin. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: MariaDB and MySQL](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/index.html)
- [DirectAdmin Docs: MySQL backup, restore and recovery](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/backup-restore-recovery.html)
- [DirectAdmin Docs: phpMyAdmin](https://docs.directadmin.com/other-hosting-services/mariadb-mysql/phpmyadmin.html)
## Prerequisites
- Login details for your DirectAdmin account at User level.
- At least one database on the account. If you have not created one yet, see [How to Create a Database in DirectAdmin](/directadmin/how-to-create-a-mysql-database-in-directadmin/).
- Enough free disk space locally for the download. Uncompressed dumps of busy sites can be several hundred megabytes.
## Download the Database Backup
### 1. Log in to DirectAdmin
Sign in to your DirectAdmin account. Make sure you are at **User** level, not Reseller or Admin level. Database downloads live at User level, because databases belong to a hosting account rather than to the server as a whole.
### 2. Open MySQL Management
In the **Account Manager** section, click **MySQL Management**. If you cannot see it on the dashboard, type `MySQL Management` into the **navigation filter** box at the top of the menu and click the result that appears.

### 3. Expand the database and choose a download format
The page lists every database on your account, along with its size and the users linked to it. On the right-hand side of each database row there is a **plus** (**+**) toggle. Click it to expand the row, then choose **Download as SQL** or **Download as GZ**.

Depending on which DirectAdmin build your server is running, the same two options may instead appear inside the database detail panel after you click the database name. The wording and the resulting file are identical either way.
### 4. Save the file
Your browser prompts for a download. Save the file somewhere sensible and, ideally, somewhere backed up. The filename follows the database name, so you will get something like `yourdomain_wp.sql` or `yourdomain_wp.sql.gz`, where `yourdomain_wp` is an example database name to replace with your own.
## SQL or GZ: Which Format to Choose
- **Download as SQL** gives you a plain-text `.sql` file. It is human readable, you can open it in a text editor to check a table or fix a stray value, and most import tools accept it directly. It is also the largest option.
- **Download as GZ** gives you the same dump, gzip-compressed. Database dumps are highly repetitive text, so compression commonly cuts the size by 80 to 90 per cent. Choose this for anything but a very small database, and especially if your connection is slow or metered.
To unpack a `.gz` file on macOS or Linux:
```
gunzip yourdomain_wp.sql.gz
```
On Windows, 7-Zip and similar archive tools open `.gz` files natively. Note that a gzip file is a single compressed file rather than a folder, so you get one `.sql` file back out.
## What the Dump Contains, and What It Does Not
This is the part that catches people out at restore time. The download is a dump of that one database: the table structures and the rows inside them. It does not include:
- **The database user or its password.** Database users are separate objects in DirectAdmin. If you restore this dump onto a fresh account, you must create the user again and link it to the database, then update your application's configuration file with the new credentials.
- **Your website files.** A database backup on its own will not restore a site. Pair it with a file backup of `public_html`, or take a full account backup from **Create/Restore Backups** in DirectAdmin, which bundles files, email and databases together.
- **Other databases on the account.** Each database is downloaded individually. If your account runs several sites, repeat the process for each one.
Also worth knowing: DirectAdmin prefixes database names and database usernames with your account username, in the form `account_dbname`. If you restore into an account with a different username, the prefix changes and every reference to the old name in your application config needs updating.
## Verify the Backup Before You Trust It
A backup you have never checked is a guess, not a backup. Two quick sanity checks:
- **Check the file size.** A dump measured in bytes rather than kilobytes almost always means the export failed or the database is empty. Compare it against the size DirectAdmin reports for the database in MySQL Management.
- **Look at the top and bottom of the file.** A complete dump starts with header comments and `CREATE TABLE` statements, and ends with a dump-completed line. If the file simply stops mid-statement, the export was truncated and should be taken again.
```
head -n 20 yourdomain_wp.sql
tail -n 5 yourdomain_wp.sql
```
## Troubleshooting
**Symptom**: The download stalls, times out or produces a truncated file on a large database. Very large exports can exceed the web server's response window. Use the **GZ** option to reduce transfer time, or take a full account backup from **Create/Restore Backups** instead, which is generated server-side and then downloaded as a single archive.
**Symptom**: You cannot find **MySQL Management** in the menu. Confirm you are logged in at User level rather than Reseller or Admin, and use the navigation filter box to search for it. If it is genuinely absent, MySQL access may not be enabled on your hosting package; contact Noiz support to confirm.
**Symptom**: The dump imports but the site shows garbled accented characters. Open the `.sql` file in an editor that handles UTF-8 correctly and make sure the import tool is set to the same character set the original database used. Re-saving a dump in a different encoding is a common cause of mangled text.
**Symptom**: The restored site cannot connect to the database. The dump does not carry users or passwords across. Recreate the database user, grant it access to the restored database, and update the credentials in your application's configuration file.
## Keep the Download Safe
A database dump is plain text containing everything in your database, which for most content management systems includes user records, order data and hashed passwords. Treat it as sensitive:
- Never leave a dump inside `public_html` or any other web-accessible folder, where it can be found and fetched by anyone who guesses the filename.
- Store it on encrypted storage, and delete old copies you no longer need.
- If you must send one to a developer, use a link that expires rather than email.
## Related Articles
- [How to Create a Database in DirectAdmin](/directadmin/how-to-create-a-mysql-database-in-directadmin/)
- [How to Delete a Database in DirectAdmin](/directadmin/how-to-delete-a-database-in-directadmin/)
If a database will not download, an import fails, or you would like Noiz to take and verify a restore on your behalf, open a support ticket from your Noiz client area with the database name and a description of what you are seeing. Noiz support can check server-side backups and assist with restores on managed plans.
# How to Enable Apache SpamAssassin in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-enable-apache-spamassassin-in-directadmin/
Spam filtering is not switched on by default for every domain, and a mailbox with no filtering in front of it will happily accept everything sent to it. This guide shows you how to turn on Apache SpamAssassin for a domain on your Noiz hosting account in DirectAdmin, and, more usefully, how to decide what it should actually do with the messages it catches so that you block the junk without quietly losing real mail.
A note on naming before you start. The upstream software is called **Apache SpamAssassin**, but the DirectAdmin menu simply labels it **SpamAssassin Setup**. They are the same thing, so search the panel for "SpamAssassin" rather than "Apache".
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface, and the current Apache SpamAssassin release. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official DirectAdmin and Apache SpamAssassin documentation linked below.
### Official Documentation Reference
- [DirectAdmin: filtering incoming spam](https://docs.directadmin.com/other-hosting-services/preventing-spam/incoming-spam.html)
- [DirectAdmin: preventing spam](https://docs.directadmin.com/other-hosting-services/preventing-spam/index.html)
- [DirectAdmin: e-mail](https://docs.directadmin.com/other-hosting-services/email/index.html)
- [Apache SpamAssassin: documentation](https://spamassassin.apache.org/doc.html)
- [Apache SpamAssassin: configuration reference, including scoring](https://spamassassin.apache.org/full/4.0.x/doc/Mail_SpamAssassin_Conf.html)
## Prerequisites
- An active Noiz hosting account on DirectAdmin, and your DirectAdmin username and password.
- At least one domain on the account with mail hosted on the Noiz server. If your MX records point somewhere else, the mail never reaches this server and enabling SpamAssassin here will have no effect.
- Access to the mailboxes on that domain, so you can check the spam folder for anything caught by mistake in the first week.
## Enable SpamAssassin
### 1. Log in to DirectAdmin
Sign in to your DirectAdmin account with the username and password on your Noiz welcome email.
### 2. Open SpamAssassin Setup
In the **E-mail Manager** section, click **SpamAssassin Setup**. If the section is collapsed or the entry is not visible, type `SpamAssassin Setup` into the navigation filter box at the top of the menu and the option will appear. Click it.

If your account holds more than one domain, check the domain selector at the top of the page before you go any further. SpamAssassin settings in DirectAdmin are held per domain, not per account, so enabling it on one domain does nothing for the others. Each domain you host has to be switched on separately.
### 3. Click Enable SpamAssassin
The button sits at the top right of the page. Click **Enable SpamAssassin**.

Filtering starts immediately on mail that arrives from this point onwards. There is no propagation delay and nothing to restart, but nothing already sitting in a mailbox is re-examined. SpamAssassin only ever sees messages as they arrive, so a full inbox stays exactly as it is.
### 4. Set what happens to spam, then save
Once SpamAssassin is enabled, the page expands into its settings. Two of them matter far more than the rest:
- **The score at which a message is treated as spam.** SpamAssassin does not answer yes or no. It runs each message through hundreds of tests and adds up a score. A higher score means more spam-like. The threshold you set here is the point at which a message is considered spam.
- **What to do with a message that reaches the threshold.** DirectAdmin lets you deliver it as normal, deliver it into each mailbox's own spam folder, send it to a single catch-all address, or delete it outright.
Choose your options and click the save or update control at the foot of the page. Nothing is applied until you do.
## Choosing a Threshold You Will Not Regret
This is the decision that determines whether SpamAssassin helps you or costs you a customer, so it is worth thirty seconds of thought.
- **A threshold of 5 is the long-standing default** and is where most people should start. It catches the great bulk of obvious spam and rarely touches legitimate mail.
- **Lowering the threshold catches more spam and more real mail with it.** Going below 5 gets aggressive quickly. Marketing newsletters, automated invoices, booking confirmations and mail from small senders with imperfect SPF or DKIM records all score a few points without being spam at all.
- **Raising the threshold is the safe direction if you are nervous.** Set it to 6 or 7, watch what still gets through for a week, then tighten it.
- **Do not set deletion on day one.** Deleted mail is gone. There is no copy on the server, nothing in a quarantine, and Noiz support cannot retrieve it. Run with the spam folder option for at least a fortnight, look at what lands there, and only consider deletion once you are confident the threshold is right for your mail.
If you do want a deletion rule eventually, the sensible pattern is to keep the normal threshold conservative and reserve deletion for very high scores only, where a message has failed so many tests that it cannot plausibly be genuine.
## What Enabling Actually Changes
- **It applies to every mailbox on the domain.** DirectAdmin holds these settings at domain level, so all addresses on that domain get the same threshold and the same spam handling. There is no per-mailbox override on this screen.
- **It only affects incoming mail.** Nothing you send is scored or filtered by this.
- **It sits on top of whatever the server already does.** Noiz servers already reject a large volume of mail at the connection stage, before it is ever accepted for delivery. SpamAssassin is the layer that judges what survives that first pass, which is why enabling it still makes a visible difference even though obvious junk was already being turned away.
- **Aliases and forwarders are a special case.** Filtering happens on delivery to this server. If an address simply forwards to an external mailbox, the message is scored here, but the forwarding destination applies its own filtering as well, and forwarded spam is a common reason for a forwarding address to get a poor reputation with the receiving provider.
## The First Two Weeks
Spam filtering is not a set-and-forget switch on the day you turn it on. Two habits make the difference:
- **Check the spam folder daily at first.** Anything legitimate sitting in there tells you the threshold is too low, or that a particular sender needs allowing. This is also the window in which a missed invoice or a customer enquiry is still recoverable.
- **Move messages to and from the spam folder rather than deleting them.** Where server-side training is running, moving a missed spam into the spam folder, and dragging a wrongly caught message back out, is what teaches the filter about your specific mail. Emptying the folder immediately teaches it nothing.
If a specific sender is repeatedly caught, an allow entry for that address or domain is a cleaner fix than raising the threshold for everything. Conversely, if one persistent sender keeps getting through, block that sender specifically rather than dropping the threshold and risking everything else. See [How to Block Email Using Spam Filters in DirectAdmin](/directadmin/how-to-block-an-email-address-using-spam-filters-in-directadmin/) for the targeted approach.
## Things Worth Knowing
- **No filter is perfect, and one that tried to be would be worse.** Spam filtering trades false negatives against false positives. A filter tuned to catch absolutely everything will also bin real mail. Aim to catch most spam and lose no legitimate mail, not the other way round.
- **Spam getting through does not mean SpamAssassin is off.** Check the message headers of something that slipped past. A scored message carries SpamAssassin's own headers showing the score it was given and which tests it matched. If the score is just below your threshold, that is a tuning question, not a fault.
- **Your own domain being spoofed is a different problem.** If you receive spam that appears to come from your own address, the fix is correct SPF, DKIM and DMARC records rather than a lower spam threshold.
- **Mail clients have their own junk filters too.** Outlook, Apple Mail and Thunderbird all file mail locally. If a message vanishes but is not in the server-side spam folder, check the client's own junk folder before assuming SpamAssassin took it.
- **Turning it off is one click.** If the filtering causes more trouble than it solves, it can be switched off just as easily. See [How to Disable Apache SpamAssassin in DirectAdmin](/directadmin/how-to-disable-apache-spamassassin-in-directadmin/).
## Troubleshooting
- **Symptom**: **SpamAssassin Setup** is not in the menu. The feature is not enabled on your hosting package. Open a ticket with Noiz support and it can be checked against your plan.
- **Symptom**: you enabled it but nothing appears to be filtered. Confirm you were on the right domain in the selector, and confirm the mail for that domain actually reaches the Noiz server by checking where its MX records point. Mail routed to another provider never touches this filter.
- **Symptom**: legitimate mail is being caught. Raise the threshold by a point or two and add an allow entry for the sender concerned. Do not compensate by disabling filtering entirely.
- **Symptom**: a message is missing and is not in the spam folder. Check the mail client's own junk folder first. If deletion was configured, the message is gone and cannot be recovered, which is exactly why deletion should not be your first setting.
- **Symptom**: the spam folder is not visible in webmail or a mail client. It may need subscribing to. In an IMAP client, look for a folder subscription or "show all folders" option and tick the spam folder there.
- **Symptom**: spam volumes jumped suddenly after months of quiet. Your address has most likely appeared in a new list. Tighten the threshold slightly and review the spam folder for a few days, and open a ticket with Noiz support if the volume is extreme.
## Related Guides
- [How to Disable Apache SpamAssassin in DirectAdmin](/directadmin/how-to-disable-apache-spamassassin-in-directadmin/)
- [How to Block Email Using Spam Filters in DirectAdmin](/directadmin/how-to-block-an-email-address-using-spam-filters-in-directadmin/)
- [How to Block a Spammy Domain Using Spam Filters in DirectAdmin](/directadmin/how-to-block-a-domain-using-spam-filters-in-directadmin/)
- [How to Remove Email Spam Filters in DirectAdmin](/directadmin/how-to-remove-email-spam-filters-in-directadmin/)
- [How to Access Your Email From DirectAdmin](/directadmin/how-to-access-your-email-from-directadmin/)
## Need a Hand?
If **SpamAssassin Setup** is missing from your panel, if legitimate mail is being caught after you have tried adjusting the threshold, or if you want the mail logs checked to see what a particular message scored and why, open a ticket with Noiz support. Include the domain, the affected address, and the date and sender of an example message, and the support team will take it from there.
# How to Enable ionCube Loader Using the CloudLinux Selector in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-enable-ioncube-loader-using-the-cloudlinux-selector-in-directadmin/
ionCube Loader is the runtime component that allows PHP to execute files protected by the ionCube Encoder. If you run commercial software that ships as encoded PHP, such as licensed billing systems, booking engines, or paid themes and plugins, the application will refuse to load until the loader is present for the exact PHP version serving your site.
On Noiz DirectAdmin hosting, ionCube Loader is available as a tick-box extension inside the CloudLinux Selector, so you can enable it yourself from the control panel without a support request and without shell access. This article covers the ionCube-specific steps and the version-matching traps that catch most people. For the general mechanics of the extension list, see [How to Enable or Disable PHP Extensions Using the CloudLinux Selector in DirectAdmin](/directadmin/how-to-enable-or-disable-php-extensions-using-cloudlinux-selector-in-directadmin/).
**Last reviewed:** 27 July 2026, against the current DirectAdmin and CloudLinux Selector releases. This guide is written for Noiz hosting and is kept current against DirectAdmin. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [ionCube Loaders](https://www.ioncube.com/loaders.php), the vendor's list of loaders and the PHP branches each one supports.
- [CloudLinux OS: PHP Selector](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#php-selector), how per-account PHP version and extension selection works.
- [CloudLinux OS: bundled PHP extensions](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#bundled-php-extensions), which extensions ship with each alternative PHP build.
## Prerequisites
- An active Noiz DirectAdmin hosting account and your control panel login.
- The PHP version your encoded application actually requires. The vendor's documentation or the encoded file's own error message will state it.
- A few minutes of tolerance for a PHP version change, because switching versions can affect other sites on the same account.
## Enable ionCube Loader
1. Log in to your DirectAdmin account.
2. In the **Extra Features** section, click **Select PHP version**. If you cannot see it, type **Select PHP** into the navigation filter box and click the result. 
3. Click the **Extensions** tab.  **Note**: if the **Extensions** page returns an error mentioning the native PHP version, your account is still set to the server's native PHP build. Native PHP is not managed by the Selector and its extension set cannot be edited from here. Switch to any non-native (alternative) PHP version on the **Current PHP version** tab first, then return to **Extensions**.
4. Tick **ioncube\_loader**. The change saves as soon as you tick it, and a confirmation message appears. 
5. Confirm the success message reads that the module **ionCube Loader** has been saved. 
## Confirm the loader is really active
A saved tick-box confirms the setting, not the running state of your website. Verify it from the web server's point of view:
1. Create a file called `info.php` in your website's document root containing ` **Site Health** > **Info** > **Media Handling**, which reports whether GD is present and which image formats it supports.
## What to Know Before You Change This
- **The setting is per account, not per domain.** The CloudLinux PHP Selector applies to the whole DirectAdmin user account. Every domain and subdomain that follows the account's PHP version picks up the extension.
- **A per-domain PHP version can override it.** DirectAdmin has its own PHP version setting for each domain under **Domain Setup**. Where a domain has been pinned to one of the server's own PHP builds there, it runs that build with its own fixed extension list and your change will not reach it. This is the most common reason GD looks enabled while the site still complains.
- **GD is not Imagick.** They are separate extensions with separate tick boxes. Some applications prefer Imagick and fall back to GD, others use only one. Enabling GD does not enable Imagick.
- **Extensions are not free.** Each enabled extension adds memory to every PHP process. Enabling a long list you do not use makes it easier to hit your account's memory limit under load. Enable what the application asks for and leave the rest alone.
- **Some builds include GD already.** If the tick box is already ticked and cannot be cleared, GD is compiled into that PHP build and there is nothing to do.
- **Switching PHP version resets the picture.** Extensions are stored per PHP version. If you later move the account from PHP 8.2 to 8.3, check the **Extensions** tab again, because the new version carries its own set of enabled modules.
- **GD does not cover every image format on its own.** WebP and AVIF support depends on how the GD build was compiled. If a modern format fails while JPEG and PNG work, check the **gd** section of a phpinfo page for the supported format list before assuming the extension is broken.
## Troubleshooting
**Symptom: the Extensions tab shows an error about the native PHP version.** Change the version drop-down from `native` to a specific PHP version, then reopen the **Extensions** tab.
**Symptom: gd is ticked but the application still reports it as missing.** Check **Domain Setup** for a per-domain PHP version that differs from the account version, and confirm with a phpinfo page loaded on that exact domain rather than on another one.
**Symptom: images upload but are never resized, and no error appears.** Many applications degrade quietly without GD. Confirm GD is loaded first, then clear any image or page cache and re-upload a test image, because images already uploaded will not be reprocessed on their own.
**Symptom: gd is not in the Extensions list at all.** The list is specific to the selected PHP version, and different versions carry different module sets. Try a currently supported version, and if GD is still absent, open a support ticket with Noiz and quote the PHP version you selected.
**Symptom: the tick box reverts when you reload the page.** The change was not saved. Watch for the on-screen confirmation as you tick the box, and try again with browser extensions such as ad blockers disabled, since the Selector saves in the background and a blocked request fails silently.
## Related Articles
- [How to Enable or Disable PHP Extensions Using the CloudLinux Selector in DirectAdmin](/directadmin/how-to-enable-or-disable-php-extensions-using-cloudlinux-selector-in-directadmin/) (the general procedure, for any extension)
- [How to Change the PHP Version via CloudLinux Selector in DirectAdmin](/directadmin/how-to-change-the-php-version-via-cloudlinux-selector-in-directadmin/)
- [How to Enable the PHP GD Extension Using the CloudLinux Selector in cPanel](/server-administration/how-to-enable-the-php-gd-extension-using-the-cloudlinux-selector-in-cpanel/)
If the **Extensions** tab does not appear on your account, or GD is loaded and the site still will not process images, open a support ticket from your Noiz client area with the domain name and the PHP version you selected, and the Noiz support team will check the account configuration for you.
# How to Enable the Mailparse PHP Extension Using CloudLinux Selector in DirectAdmin
Source: https://docs.noiz.ie/directadmin/how-to-enable-the-mailparse-php-extension-using-cloudlinux-selector-in-directadm/
Mailparse is a PHP extension for reading email messages and splitting them into their component parts: headers, bodies, MIME sections and attachments. Helpdesk and ticketing systems that accept mail-in tickets, mailing list managers, mailbox importers and some CRM add-ons all ask for it. It is not compiled into PHP by default, so nothing that needs it will work until you switch it on for your account.
This guide shows you how to enable **Mailparse** on a DirectAdmin account using the CloudLinux PHP Selector, which DirectAdmin surfaces as **Select PHP version**. It also covers the two things that catch people out with this particular extension: the native PHP version error that blocks the Extensions view, and the `mbstring` dependency that Mailparse quietly relies on.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface, with the CloudLinux PHP Selector plugin. This guide is written for Noiz hosting and is kept current against DirectAdmin and CloudLinux. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [CloudLinux OS: PHP Selector](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#php-selector): what the Selector controls and what it deliberately does not.
- [CloudLinux OS: PHP Extensions](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#php-extensions): how extensions are packaged separately for each alternative PHP version.
- [CloudLinux OS: PHP Selector client plugin](https://docs.cloudlinux.com/cloudlinuxos/lve_manager/#php-selector-client-plugin): the end-user interface you see inside the panel.
- [PHP Manual: Mailparse](https://www.php.net/manual/en/book.mailparse.php) and [Mailparse installation notes](https://www.php.net/manual/en/mailparse.installation.php), which document the mbstring requirement.
- [PECL: mailparse package](https://pecl.php.net/package/mailparse): release history and changelog.
- [DirectAdmin Documentation: PHP Extensions](https://docs.directadmin.com/webservices/php/php-extensions.html): how PHP extensions are handled at server level.
## Prerequisites
- Login details for the DirectAdmin user account that runs the site needing Mailparse.
- A **Select PHP version** item in your DirectAdmin menu. If it is absent, the CloudLinux PHP Selector is not available on your package and this procedure does not apply.
- The account set to a selectable (alternative) PHP version rather than the server's native PHP. Step 2 below covers this if you are not sure which you are on.
## Enable the Mailparse Extension
### Step 1: Open Select PHP version
1. Log in to your DirectAdmin account.
2. In the **Extra Features** section, click **Select PHP version**. If you cannot see the section, type `Select PHP` into the navigation filter box at the top of the menu and click the result that appears.

### Step 2: Open the Extensions view
1. Click the **Extensions** menu.

**Note**: if the **Extensions** page returns an error mentioning the native PHP version, the account is running the server's built-in PHP. The Selector cannot manage extensions for native PHP, because that build's extension set is fixed at server level for every account at once. Return to the **Current PHP version** view, choose a numbered version such as `8.3` instead of `native`, apply it, then reopen **Extensions**. The full procedure is in [How to Change the PHP Version via CloudLinux Selector in DirectAdmin](/directadmin/how-to-change-the-php-version-via-cloudlinux-selector-in-directadmin/).
### Step 3: Tick Mailparse
1. Find **mailparse** in the extension list.
2. Tick its checkbox.
The change saves on the spot. There is no separate Save button, no page reload and no server restart, and a confirmation message appears reading that the module **mailparse** is saved.

### Step 4: Tick mbstring while you are there
Mailparse leans on the `mbstring` extension for character set handling, and the PHP manual lists mbstring as a requirement for it. It is usually enabled already, but confirm it before you leave this screen. If **mbstring** is unticked, tick it too.
Skipping this is the single most common reason Mailparse looks enabled and yet the application still behaves oddly, typically mangling encoded subject lines, non-ASCII sender names or multipart message bodies rather than failing outright.
## Confirm Mailparse Is Actually Loaded
The checkbox records your preference. It is not proof that the PHP handler serving your website has loaded the extension, so verify it from PHP's own point of view.
1. Create a file named `phpinfo.php` in your `public_html` directory containing the single line below.
2. Visit `https://yourdomain.com/phpinfo.php`, replacing `yourdomain.com` with your own domain.
3. Search the page for `mailparse`. Its own section in the output means the extension is loaded.
4. **Delete the file as soon as you are finished.** The output exposes a great deal of detail about your environment to anyone who finds the URL.
```
**FTP Management**, select the account, then click **Unsuspend**. Access is restored straight away, with the same password as before.
## Troubleshooting
**Symptom**: the row has no Suspend option. That is almost certainly your main FTP account, the one that shares your DirectAdmin username. It is tied to the hosting account itself rather than being an extra account you created, so it is not handled the same way. To cut off access to it, change its password instead.
**Symptom**: the user says they can still connect. Check three things. An already open session can survive the change until it drops; they may be connecting with a different FTP account, such as the main one; or they may be using SFTP over SSH, which is a separate service from FTP and is not affected by suspending an FTP account.
**Symptom**: something broke right after suspending. Unsuspend the account to restore service, then work out what was using it before you try again. A short suspension is a useful way to discover undocumented integrations, but only if you can reverse it quickly.
**Symptom**: FTP Management is not in the menu. Confirm you are logged in at user level rather than reseller or admin level, and that your hosting plan includes FTP accounts. If it still does not appear, contact Noiz support.
## Related Articles
- [How to Create an FTP Account in DirectAdmin](/directadmin/how-to-create-an-ftp-account-in-directadmin/)
- [How to Change an FTP Account Password in DirectAdmin](/directadmin/how-to-change-an-ftp-account-password-in-directadmin/)
- [How to Remove an FTP Account in DirectAdmin](/directadmin/how-to-remove-an-ftp-account-in-directadmin/)
If you are unsure which FTP accounts are still in use, or you suspect an account has been compromised and want it dealt with quickly, open a ticket through the Noiz client area. The Noiz support team can review the FTP accounts on your hosting and suspend, rotate or remove them for you.
# How to Access Your Webmail in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-access-your-webmail-in-ispconfig/
This guide shows you how to reach your Noiz webmail: the browser-based inbox for a mailbox hosted on your ISPConfig account. Webmail on Noiz hosting is provided by Roundcube, so you may see it called Roundcube, web mail, online email or simply "email in the browser", and they all mean the same thing. Webmail lets you read and send mail from any computer with a web browser, without installing or configuring anything, which makes it the quickest way to check a new mailbox or to get at your mail from a machine that is not your own. This article is for Noiz clients who already have a mailbox and want to sign in to it from a browser.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** (the version Noiz runs) and the Roundcube webmail it provides. This guide is written for Noiz hosting and is kept current against ISPConfig and Roundcube. It complements, and does not replace, the official documentation linked below. Roundcube is updated regularly and its exact version, colours and the precise position of a button can shift between releases, so if a screen looks slightly different from the description here, the field names and the steps still hold.
### Official Documentation Reference
- [Roundcube Webmail (project home)](https://roundcube.net/): the official site for the webmail application that powers Noiz webmail, with an overview of its features.
- [Roundcube Documentation](https://docs.roundcube.net/): the official documentation portal, including the bundled user help that explains composing, folders, contacts and settings.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of official ISPConfig documentation, including how mailboxes and webmail fit into the hosting platform.
## Prerequisites
- A mailbox already exists for your domain. Webmail only signs you in to a mailbox that has already been created, so if you do not have one yet, first [create an email mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/).
- You know the mailbox's full email address, for example `you@yourdomain.com`, and the password that was set when the mailbox was created. On Noiz webmail the username is always the whole address, not just the part before the `@`.
- Your domain is live on Noiz hosting. If the domain was only recently pointed at Noiz, give DNS time to take effect; until it does, the domain-based webmail address may not resolve, and the fallback address described below is the reliable route in the meantime.
## Webmail Is Not the Same as a Desktop or Mobile Email App
Before you sign in, it helps to be clear about what webmail is and is not, because the two ways of reading mail are often confused.
- **Webmail (Roundcube)** runs entirely in your web browser and on the Noiz server. There is nothing to install and nothing to configure: you open a web address, log in, and your mail is there. Because the messages stay on the server, webmail always shows the current, live state of your mailbox from any device you sign in from. It is ideal for occasional access, for a machine that is not yours, and for confirming that a brand-new mailbox works.
- **A desktop or mobile email client** such as Outlook, Apple Mail, Thunderbird or the Mail app on a phone is a separate program that you set up once with the mailbox's server settings. It then collects your mail into that program. Clients are better for heavy daily use, offline reading and managing several mailboxes at once, but they need to be configured with the correct incoming and outgoing server details first.
The two are not in competition: the same mailbox can be open in webmail and in a mail client at the same time, and (with IMAP) they stay in step with each other. That choice also decides what you can see: webmail always connects over IMAP, so it shows the server-side folders including **Junk**, whereas a client set up with POP3 will not see them. This article covers webmail only. If you would rather set the mailbox up in an app, that is a separate configuration task and uses the mailbox server settings rather than a web address.
## Open Your Webmail
There are two reliable ways to reach the Roundcube login page. Try the domain address first; keep the server address in reserve for the situations described under Troubleshooting.
### Route 1: The /webmail Address on Your Own Domain
In your browser's address bar, type your domain followed by `/webmail`, using `https://`:
```
https://yourdomain.com/webmail
```
Replace `yourdomain.com` with your real domain. If your site normally answers on the `www` host, `https://www.yourdomain.com/webmail` works too. This address is an alias that the Noiz server maps to Roundcube, and it is the easiest one to remember. It works when your website is served from the same Noiz ISPConfig server that hosts your mailbox, which is the usual arrangement.
### Route 2: The Server Webmail Address
Noiz also publishes a server-level webmail address that does not depend on your own domain's website settings at all. This is the dependable fallback when the `/webmail` alias does not resolve, for example while a new domain's DNS is still settling, or when your website is hosted somewhere other than your Noiz mailbox server. The exact server webmail address for your account is listed in the welcome email that was sent when your hosting or mailbox was set up; if you no longer have it, Noiz support can give it to you. Bookmark whichever address works for you so you do not have to remember it next time.
### Optional: The Webmail Icon in the ISPConfig Panel
If you are already signed in to the control panel, there is a third route. In ISPConfig, go to **Email > Email Accounts > Email Mailbox** for the mailbox list, where each row can carry a small webmail icon that opens Roundcube in a separate tab. Two things are worth knowing before relying on it. The icon is not always present: it appears only when the server-wide **Link to webmail in Mailbox list** option is switched on and a **Webmail URL** is set, and both are server settings rather than anything on your own mailbox. It is also a shortcut to the address rather than a sign-in, so it hands you the ordinary Roundcube login page and you still enter the mailbox address and its password yourself. This route needs a panel session, so if you take it, first [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/). Signing in to webmail itself, by contrast, does not use your ISPConfig panel login at all, as the next section explains.
## Log In to Webmail
On the Roundcube login page, enter two things:
1. **Username**: your **full email address**, for example `you@yourdomain.com`. Entering only the part before the `@` will fail.
2. **Password**: the **mailbox password**, the one set when the mailbox was created.
Click the login button and Roundcube opens on your inbox.
**The single most common mix-up, worth stating plainly:** webmail uses the mailbox's own email address and password. It does *not* use your ISPConfig control-panel username and password, and it does not use your Noiz client-area (billing) login. Those are three separate accounts. If you try to sign in to webmail with your panel or billing details, it will reject them even though nothing is wrong with your mailbox. Always use the email address and its mailbox password here.
## A Quick Tour of Roundcube
Once you are in, Roundcube's layout is close to any modern email program, so most of it is self-explanatory. A short orientation:
- **Folder list** (left): your **Inbox** and the standard folders **Drafts**, **Sent**, **Junk** and **Trash**, plus any folders you create. Click a folder to see the messages in it.
- **Message list** (middle): the messages in the selected folder. Click a message to read it; the reading pane shows its content.
- **Compose**: the button to write a new message, usually at the top of the folder or message column. It opens a blank message where you fill in the recipient, subject and body, then click **Send**.
- **Search**: a search box above the message list finds mail by sender, subject or content within the current folder.
- **Contacts** (address book): stores email addresses so you can pick recipients without retyping them.
- **Settings**: the area (often a cog or gear icon) where you adjust preferences, manage folders, set up an identity or signature, and configure filters or an out-of-office reply. The exact options you see depend on which Roundcube features are enabled on your server; if a feature you expect is missing, Noiz support can confirm what is available on your plan.
- **Log out**: always log out when you finish, especially on a shared or public computer, using the logout control near your account name. Closing the tab alone does not always end the session.
To confirm the mailbox is fully working, send yourself a short test message and check it arrives, then reply to it. That proves both sending and receiving from webmail.
## Troubleshooting
Most problems with reaching webmail come down to where your domain points and whether it has a valid certificate yet. Work through these in order.
- **Symptom: `yourdomain.com/webmail` shows a "Not Found" page or your own website's error page.** The `/webmail` alias only exists when your website is served by the same Noiz server that hosts your mailbox. If your domain's website is hosted elsewhere, or its A record points to another provider, the alias will not be present on that host. Use the **server webmail address** (Route 2) instead; it reaches Roundcube regardless of where your website lives.
- **Symptom: the address does not load at all, or the browser cannot find the site.** This usually means DNS for the domain is not yet pointing at Noiz, common in the first hours after a domain is added or transferred. Until DNS takes effect, use the server webmail address, which does not depend on your domain resolving. If your domain has been live for a while and still will not load, contact Noiz support to check the DNS.
- **Symptom: a browser security or certificate warning (for example "your connection is not private", or a name-mismatch error) when you open `yourdomain.com/webmail`.** A valid HTTPS certificate for your own domain may not have been issued yet, which is normal for a newly added domain, or you may have opened `http://` instead of `https://`. Two fixes: make sure the address starts with `https://`, and use the server webmail address, which always presents a valid certificate. If you specifically need `yourdomain.com/webmail` to be free of warnings, allow time for the certificate to be issued for your domain, or raise a ticket if it does not resolve on its own.
- **Symptom: the login page loads but rejects your details.** Confirm the username is the **full email address** and that you are using the **mailbox password**, not your ISPConfig panel or Noiz client-area password. There is one exception to the full-address rule: ISPConfig allows a mailbox to be given a separate **Login** value in place of its address, so if the mailbox was created that way, the login name is that value and not the email address. If you are certain the password is right and it still fails, reset it in the **Password** field on the mailbox under **Email > Email Accounts > Email Mailbox** and try again with the new value.
- **Symptom: the details are accepted but the mailbox will not open, or webmail reports that it cannot connect to the mail server.** Webmail reads mail over IMAP, so it depends on IMAP being available for that account. ISPConfig has a per-mailbox **Disable IMAP** option on the **Mailbox** tab, and a mailbox with that ticked cannot be opened in webmail even when the address and password are entirely correct. Check that the box is clear, or ask Noiz support to check it for you.
- **Symptom: webmail works but a message you sent to yourself lands in Junk.** That is a spam-filtering result, not a webmail fault. What moves it is a mailbox-level rule in ISPConfig, **Move Spam Emails to Junk folder** on the mailbox's **Mail Filter** tab, acting on messages the spam filter has already tagged. It is not a Roundcube preference, so marking the message as not junk in webmail deals with that message but leaves the rule untouched. Mark it as not junk anyway, and if legitimate mail is regularly misfiled, contact Noiz support to review the filtering for your mailbox.
If webmail still will not open or accept your login after working through the above, open a support ticket with the Noiz support team. Include the mailbox's email address, the exact web address you are trying, and a screenshot of any error the browser or the login page shows. On Noiz managed plans the support team can confirm the correct webmail address for your account, check that the mailbox and its certificate are in order, and point you to the exact detail to correct.
# How to Add Custom PHP Settings and Apache/Nginx Directives in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-add-custom-php-settings-and-apachenginx-directives-in-ispconfig/
ISPConfig can apply advanced per-site configuration from the control panel instead of the shell: custom PHP settings, and custom Apache or nginx directives. This is particularly useful for developers who want to optimise performance, tighten security, or satisfy a specific application requirement. This guide walks you through adjusting PHP settings, such as changing the timezone, increasing the maximum upload file size, and disabling OPcache, along with adding custom Apache or nginx directives. Every change is applied to a single website, so it stays isolated from the other sites on the server.
All of these settings live in the **Options** tab of a website. Access to that tab is deliberately restricted, because the fields on it are security sensitive and can reach beyond the site they belong to. ISPConfig shows the Options tab to the server administrator, and to a reseller only where the administrator has enabled **Reseller can use the option-tab for websites**. An ordinary client login does not see the tab at all. If you hold a client account on Noiz hosting, send the exact settings you want to Noiz support and Noiz will apply them to your site.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**, the version Noiz runs. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig 3.3 documentation portal](https://www.ispconfig.org/documentation/) (the successor to the ISPConfig 3.1 Manual).
- [PHP: list of supported timezones](https://www.php.net/manual/en/timezones.php).
- [PHP: description of core php.ini directives](https://www.php.net/manual/en/ini.core.php).
## Prerequisites
- Login credentials for the ISPConfig control panel as the server administrator, or as a reseller on a server where the administrator has enabled the Options tab for resellers.
- Access to the specific website domain within ISPConfig.
- Basic familiarity with PHP directives and web server configuration (for example, php.ini syntax).
- A compatible PHP mode. PHP-FPM, FastCGI, CGI, and SuPHP all support custom php.ini overrides. Mod-PHP does not, so under Mod-PHP those directives belong in the Apache section instead.
Changes may take a minute or two to propagate, because ISPConfig regenerates the affected configuration files automatically. Where possible, test modifications on a staging site first so you do not disrupt a live site.
## Step 1: Log In to the ISPConfig Control Panel
1. Navigate to the ISPConfig login URL supplied by Noiz for your account (typically on port `8080`, for example `https://your-server:8080`).
2. Enter your username and password.
3. Once logged in, you will see the dashboard with tabs for Sites, Email, DNS, and more.
## Step 2: Open the Website Options Tab
1. Click the **Sites** tab in the top menu.
2. Under **Websites** in the left-hand menu, select **Website**.
3. In the list of websites, click the domain you want to configure.
4. Switch to the **Options** tab. If it is not there, your login does not have access to it, so see the note at the top of this guide.
The Options tab groups the fields you will use here:
- The PHP-FPM process manager fields, which control how many PHP processes the site may run.
- **PHP open\_basedir**, which limits the directories PHP may read and write for this site.
- A text area for **Custom php.ini settings**.
- A text area for **Apache Directives** (Apache only) or **nginx Directives** (nginx only).
## Step 3: Configure Custom PHP Settings
The **Custom php.ini settings** field lets you override the global PHP configuration on a per-site basis. Enter one directive per line using standard php.ini syntax (for example, `key = value`). These overrides apply under PHP-FPM, FastCGI, CGI, and SuPHP.
Where the server administrator has defined Directive Snippets under **System > Directive Snippets**, they are listed by name beside the text area. Click a name and the snippet's contents are inserted at the cursor position. The same applies to the Apache and nginx directive fields covered in Step 4.
### Changing the PHP Timezone
To set a specific timezone (for accurate date handling in applications such as WordPress or custom scripts):
1. In the Custom php.ini settings text area, add:
```
date.timezone = Africa/Johannesburg
```
Replace `Africa/Johannesburg` with the timezone you need (for example, `Europe/Dublin`). See the [PHP timezone list](https://www.php.net/manual/en/timezones.php) for valid values.
2. Save the changes. ISPConfig regenerates the site's php.ini accordingly.
This ensures functions such as `date()` use the correct timezone, preventing errors in logging or scheduling.
### Increasing the Maximum PHP Upload Size
For applications that need to accept larger file uploads (for example, media-heavy CMS platforms):
1. Add the following lines to the Custom php.ini settings:
```
upload_max_filesize = 64M
post_max_size = 64M
```
Adjust the values (for example, `128M`) to suit your needs, but stay within your hosting plan's resource limits. Note that `post_max_size` must be at least as large as `upload_max_filesize`, or the upload will still be rejected.
2. Optionally, allow more time for large uploads to complete:
```
max_execution_time = 300
max_input_time = 300
```
3. Save, then verify by uploading a test file or checking `phpinfo()` output.
These settings override the server defaults, enabling smoother file handling in forms or admin panels.
### Disabling OPcache
OPcache improves performance by caching compiled PHP bytecode, but it can get in the way during active development, or with certain plugins that write PHP at runtime. To disable it:
1. Add this line to the Custom php.ini settings:
```
opcache.enable = 0
```
2. Save the changes. This stops opcode caching for the site, and you can re-enable it later by setting the value back to `1`.
Verify by checking `phpinfo()` output, where "Opcode Caching" is then listed as "Disabled". Leave OPcache on for production sites once you have finished debugging, because disabling it noticeably increases PHP execution time.
## Step 4: Add Custom Apache or nginx Directives
For web-server-specific tweaks, such as redirects, security headers, or proxy configuration, use the **Apache Directives** field (Apache only) or the **nginx Directives** field (nginx only). Enter one directive per line, following Apache or nginx syntax. Which field appears depends on the web server your site runs, so you will see one or the other, not both. Whatever you enter is written into the site's virtual host container.
### Adding Apache Directives
Common examples include URL redirects and header modifications:
1. For a permanent redirect to a canonical hostname:
```
Redirect 301 / https://www.yourdomain.com/
```
2. To set security headers:
```
Header always set X-Frame-Options "SAMEORIGIN"
Header always set X-Content-Type-Options "nosniff"
```
3. Save. ISPConfig inserts these into the site's virtual host configuration.
### Adding nginx Directives
On nginx, equivalent directives apply:
1. For a location-based redirect:
```
location /old-path {
return 301 /new-path;
}
```
2. To enable gzip compression:
```
gzip on;
gzip_types text/plain text/css application/javascript;
```
3. Save. These are added to the site's nginx vhost block.
One nginx-specific trap is worth knowing before you paste anything in. If you declare a `location` block that the generated vhost already uses, such as `location ~ /\. {}` or `location @php {}`, ISPConfig replaces the original block with yours rather than combining them, which quietly removes the configuration the site depended on. To keep the original and add to it, put the string `##merge##` to the right of the location line:
```
location @php { ##merge##
fastcgi_read_timeout 300;
}
```
Directives are powerful, but a mistake can break site functionality or produce a 500 error, so test each change thoroughly.
## Step 5: Adjust PHP-FPM Performance Settings (Optional)
If your site uses PHP-FPM, the same Options tab carries the pool tuning fields. ISPConfig names each one after the PHP-FPM directive it writes, and shows or hides fields depending on which process manager you select:
- **PHP-FPM Process Manager**: `static`, `dynamic`, or `ondemand`. ISPConfig recommends `ondemand` for minimal resource usage, because no child processes are started until a request arrives. `dynamic` trades idle memory for responsiveness under steady traffic.
- **PHP-FPM pm.max\_children**: the ceiling on simultaneous PHP processes, and so on the number of requests the site can serve at once. Set it (for example, 40) from your traffic and your plan's memory allowance.
- **PHP-FPM pm.process\_idle\_timeout**: seconds before an idle process is killed. This one applies to `ondemand` only, and defaults to 10 seconds.
- **PHP-FPM pm.start\_servers**, **PHP-FPM pm.min\_spare\_servers** and **PHP-FPM pm.max\_spare\_servers**: these appear for `dynamic` only. ISPConfig refuses the form unless `pm.max_children >= pm.max_spare_servers >= pm.start_servers >= pm.min_spare_servers > 0`.
- **PHP-FPM pm.max\_requests**: how many requests a child handles before it is respawned, which is the usual way to work around a memory leak in a third-party library. `0` means never respawn.
Save to apply. These settings help you balance CPU and memory usage without affecting other sites on the server.
## Verification and Troubleshooting
- After saving, wait 1 to 2 minutes, then refresh your site.
- Create a temporary `phpinfo.php` file (``) in your document root to confirm the changes, then delete it afterwards for security.
- Check the site's own error log if something goes wrong. ISPConfig mounts it inside the website directory as `log/error.log`, so you can read it over SFTP or FTP. ISPConfig's Monitor module is the administrator's server-wide view of system and service logs, and does not carry per-site web logs.
- **Symptom**: a 500 error after saving directives. A syntax error in an Apache or nginx directive is the usual cause, so remove the last change you made and reapply it one line at a time.
- **Symptom**: a php.ini override has no effect. Confirm the site is running a PHP mode that honours custom php.ini (PHP-FPM, FastCGI, CGI, or SuPHP) rather than Mod-PHP. Under Mod-PHP the equivalent is `php_admin_value` or `php_flag` in the Apache Directives field, which in turn has no effect under any of the other modes.
- **Symptom**: PHP reports a file access or open\_basedir error after your change. The **PHP open\_basedir** field on the same Options tab restricts which directories PHP may touch. Add the extra path there, separated from the existing entries by a colon, or enter the string `none` to switch the restriction off. Clearing the field does not disable it.
- **Symptom**: a later change to the server-wide PHP configuration does not reach the site. Once a site has anything in Custom php.ini settings, it keeps its own generated configuration and only picks up global changes when the site is saved again in ISPConfig and its configuration is rewritten.
If a change still does not apply, contact Noiz support with the details of your modification and Noiz will assist.
## Summary
Customising PHP settings and web server directives in ISPConfig lets you tailor your Noiz hosting environment precisely, per website. By following these steps you can adjust the timezone, raise upload limits, control OPcache, and add your own Apache or nginx rules, all from the control panel and all isolated from your other sites. For deeper configuration, consult the ISPConfig documentation linked above, and always keep security and performance in mind when making changes.
# How to Add an Alias Domain in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-add-an-alias-domain-in-ispconfig/
This guide shows you how to add an alias domain to an existing website in the ISPConfig control panel on your Noiz hosting account. An alias domain (ISPConfig calls it an "aliasdomain", and elsewhere you may see it called a parked domain or domain alias) is an additional domain that points at a website you have already created, so that visitors typing either domain see the same site. You can also use it to redirect the extra domain to your main address. Note the difference from a subdomain: a subdomain uses the same domain name as the site (for example `shop.yourdomain.com` under `yourdomain.com`), whereas an alias domain is a completely different domain name (for example `yourseconddomain.com` pointing at the `yourdomain.com` website).
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This article follows the official ISPConfig manual procedure for adding an alias domain to an existing website, cross-checked against the current interface. ISPConfig evolves between releases, so if a screen differs from this guide, check the official documentation links below.
### Official Documentation Reference
- [ISPConfig Documentation: Alias Web Domains (step-by-step guide)](https://docs.ispconfig.org/creating-web-sites/alias-web-domains/)
- [ISPConfig Documentation: Alias Web Domain (form reference)](https://docs.ispconfig.org/modules/sites/alias-web-domain/)
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/)
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- The website you want to point the alias domain at already exists in the panel. If not, first follow [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/).
- The additional domain is registered and you (or Noiz) can manage its DNS records.
- Your hosting package has at least one unused alias domain allowance. If the package allows no alias domains at all, **Aliasdomain for website** does not appear in the menu. If the allowance exists but is used up, ISPConfig refuses to save the form.
## Open the alias domain list
1. Log in to ISPConfig and click the **Sites** module in the top menu.
2. In the left-hand menu, under **Websites**, click **Aliasdomain for website**. A list of any existing alias domains appears.
3. Click the **Add new Aliasdomain** button.
## Complete the Web Aliasdomain form
The **Web Aliasdomain** form opens on the **Aliasdomain** tab. Work through the fields as follows.
### Enter the domain and choose the parent website
1. In the **Domain** field, type the additional domain, for example `yourseconddomain.com` (an example placeholder, use your own domain). You can also enter a subdomain of another domain here, such as `sub.yourseconddomain.com`. Do not include `www`, that is handled by the **Auto-Subdomain** setting below.
2. In the **Parent Website** drop-down, select the existing website that the alias domain should point to, for example `yourdomain.com`.
### Choose the redirect behaviour
1. Leave **Redirect Type** set to **No redirect** if you simply want the alias domain to show the same content as the parent website, with the alias domain staying in the visitor's address bar. This is the most common choice.
2. If you instead want visitors to be forwarded to your main address, select **R=301,L (Permanent redirect + last rule)**, or **permanent** if the server runs nginx, and enter the destination in the **Redirect Path** field, for example `https://www.yourdomain.com/`. The drop-down only offers the options that suit your server's web server software, so pick whichever of the two you can see. The options are explained in more detail in the next section.
### Set Auto-Subdomain and SEO Redirect
1. In the **Auto-Subdomain** drop-down, keep the default **www.** so that both `yourseconddomain.com` and `www.yourseconddomain.com` reach the site. Choose **None** to serve only the bare domain, or **\*.** to accept any subdomain of the alias domain that is not already assigned to another site.
2. Leave **SEO Redirect** set to **No redirect** unless you want to force the www or non-www form of the alias domain, see below.
### Activate and save
1. If your account has Let's Encrypt enabled, the form also shows a **Don't add to Let's Encrypt certificate** checkbox. Leave it unticked so that the parent website's certificate is extended to cover the alias domain. Tick it only if the alias domain will not resolve to the server, because a name that does not resolve makes the whole certificate request fail.
2. Make sure the **Active** checkbox is ticked.
3. Click **Save**. ISPConfig queues the change and writes it to the web server configuration, which normally takes under a minute.
## Redirect options explained
### Redirect Type and Redirect Path
The **Redirect Type** drop-down controls what happens when a visitor requests the alias domain:
- **No redirect**: the alias domain serves the parent website's content directly. The address bar keeps the alias domain.
- **No flag**: rewrites to the **Redirect Path** without applying any rewrite flag. Rarely the right choice.
- **R (Temporary redirect)**: issues a temporary HTTP redirect to the **Redirect Path**.
- **L (Last redirect rule)**: stops further rewrite rule processing once the rule matches. Rarely needed on its own.
- **R,L (Temporary redirect + last rule)**: a temporary redirect combined with the last-rule flag. Use this for redirects you may remove later.
- **R=301,L (Permanent redirect + last rule)**: a permanent redirect combined with the last-rule flag. This is the recommended choice when the alias domain should always forward to your main address, and it tells search engines the move is permanent.
The **R**, **L**, **R,L** and **R=301,L** flags are Apache options. If the server hosting your website runs nginx, ISPConfig hides them and offers **last**, **break**, **redirect**, **permanent** and **proxy** instead. On nginx, **redirect** is the temporary equivalent (HTTP 302) and **permanent** is the permanent one (HTTP 301), so use **permanent** where this guide recommends **R=301,L**. The **proxy** option fetches the content from another URL without changing the address in the browser, and it only accepts a full URL in **Redirect Path**. It is for advanced setups and is safe to ignore for a normal alias domain.
The **Redirect Path** field is the redirect target. It accepts either a full URL such as `https://www.yourdomain.com/` or a path relative to the website's document root such as `/promo/`. A relative path must both begin and end with a slash, otherwise ISPConfig rejects it with "Invalid redirect path". A word of caution on subdirectory targets: pointing an alias domain at a subdirectory uses rewrite rules, and these usually clash with the rewrite rules that content management systems such as WordPress, Joomla or Drupal ship with. If you want a CMS to live on its own domain in its own folder, create a separate website for that domain instead of an alias domain with a subdirectory redirect.
### Auto-Subdomain
- **None**: the site answers only on `yourseconddomain.com`.
- **www.** (default): the site answers on `yourseconddomain.com` and `www.yourseconddomain.com`.
- **\*.**: the site answers on any subdomain of the alias domain that does not already point to another website.
### SEO Redirect
The **SEO Redirect** drop-down lets you force one canonical form of the alias domain so search engines do not index duplicate content. The options are:
- **No redirect**: no canonical redirect (the usual choice for an alias domain).
- `domain.tld => www.domain.tld`: redirect the bare domain to the www form.
- `www.domain.tld => domain.tld`: redirect the www form to the bare domain.
- `*.domain.tld => domain.tld`: redirect all subdomains, including www, to the bare domain.
- `*.domain.tld => www.domain.tld`: redirect all subdomains, including the bare domain, to the www form.
- `* => domain.tld` and `* => www.domain.tld`: redirect anything that is not already the chosen form to it. These two catch-alls also sweep up subdomains and alias domains, so use them with care.
Note that an SEO redirect configured on the parent website takes precedence over the one set on the alias domain. If the parent site already redirects everything to `www.yourdomain.com`, your selection here is ignored.
## Point the alias domain's DNS at your website
Adding the alias domain in ISPConfig only configures the web server. The alias domain must also resolve to the same server as the parent website, otherwise browsers cannot find it:
1. Create an **A** record for `yourseconddomain.com` (and one for `www.yourseconddomain.com` if you enabled the **www.** auto-subdomain) pointing at the same IP address as the parent website.
2. If the alias domain's DNS is hosted with Noiz, check the domain's DNS zone in the panel, or ask the Noiz support team to confirm the records for you. If the domain is registered elsewhere, add the records at that provider.
3. Allow time for DNS propagation. New or changed records can take from a few minutes up to 24 to 48 hours to become visible everywhere.
## Test the alias domain
1. Once DNS resolves, visit `http://yourseconddomain.com` and `http://www.yourseconddomain.com` in a browser.
2. With **No redirect** selected you should see the parent website's content under the alias address. With a redirect configured, the browser should land on the **Redirect Path** destination.
3. If the parent website uses a Let's Encrypt SSL certificate, ISPConfig extends the certificate to cover the alias domain automatically. This can only succeed after the alias domain's DNS points at the server, so allow a little time before testing `https://` addresses.
## Troubleshooting
**Symptom**: the alias domain shows a "server not found" error or a placeholder page. The DNS records for the alias domain are missing, wrong, or still propagating. Verify the A records point at the same IP address as the parent website and wait for propagation.
**Symptom**: ISPConfig reports "There is already a website or sub / aliasdomain with this domain name." The domain already exists somewhere in the panel, as a website, subdomain or another alias. Remove or edit the existing entry first, or open a support ticket if you cannot see where it is used.
**Symptom**: ISPConfig reports "The max. number of aliasdomains for your account is reached." Your hosting package's alias domain limit is used up. Contact the Noiz support team to discuss raising the limit.
**Symptom**: the alias domain loads over `http://` but browsers warn about the certificate on `https://`. The site's Let's Encrypt certificate has not yet been extended to the alias domain. Confirm DNS points at the server, then re-save the parent website's settings in **Sites** so the certificate request runs again.
**Symptom**: the redirect goes to the wrong address or loops. Check the **Redirect Type** and **Redirect Path** on the alias domain, and remember that an **SEO Redirect** on the parent website overrides the alias domain's own SEO Redirect setting.
If you get stuck at any point, open a support ticket with the Noiz support team and include the alias domain name, the parent website it should point to, and the redirect behaviour you want.
# How to Back Up Your Websites, Databases and Mailboxes in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-back-up-your-websites-databases-and-mailboxes-in-ispconfig/
This guide shows you how backups work in the ISPConfig control panel on your Noiz hosting account, and how to set them up so that a bad deployment, a broken plugin update or a deleted mailbox is an inconvenience rather than a disaster. The important thing to understand up front is that ISPConfig does not produce one big account archive. It produces three kinds of archive, each held and restored on its own: your **website files**, each of your **MySQL databases**, and each individual **mailbox**. Website files and the site's databases are driven together from the website's own **Backup** tab. Mailboxes are scheduled somewhere else entirely, in the Email module, and nothing you set on a website reaches them. That division is the single most useful fact in this article, because it is the one that decides which screens you actually have to visit.
This article covers the setting up and the checking. Getting data back out of an archive is covered separately in [How to Restore a Backup in ISPConfig](/ispconfig/how-to-restore-a-backup-in-ispconfig/).
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** (the release running on Noiz hosting, and the newest release tag published in the ISPConfig source repository when this article was written). This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the vendor's index of all official ISPConfig documentation.
- [ISPConfig User Manual](https://www.ispconfig.org/documentation/user-manual/): the vendor's paid PDF manual, which carries the full field-by-field reference for the Backup tab and the Backup Stats screens.
- [Website form definition (ISPConfig source, tag 3.3.1p1)](https://git.ispconfig.org/ispconfig/ispconfig3/-/blob/3.3.1p1/interface/web/sites/form/web_vhost_domain.tform.php): the authoritative list of the fields and choices on a website's Backup tab.
- [Mailbox form definition (ISPConfig source, tag 3.3.1p1)](https://git.ispconfig.org/ispconfig/ispconfig3/-/blob/3.3.1p1/interface/web/mail/form/mail_user.tform.php): the same, for a mailbox's Backup tab.
- [Backup class (ISPConfig source, tag 3.3.1p1)](https://git.ispconfig.org/ispconfig/ispconfig3/-/blob/3.3.1p1/server/lib/classes/backup.inc.php): the code that decides when each backup runs and which older copies are deleted.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- At least one of the things you want backed up already exists: a [website](/ispconfig/how-to-create-a-website-in-ispconfig/), a [database](/ispconfig/how-to-create-a-database-and-database-user-in-ispconfig/) or a [mailbox](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/).
- A hosting plan that includes the backup function. It is a per-account permission in ISPConfig, and it is set separately for web backups and for mailbox backups. If the **Backup** tab described below is simply not there, that is what is missing, not a fault.
- Somewhere off the server to keep the copies you download. A backup that only exists on the machine it came from is a convenience feature, not a safety net.
## What ISPConfig Backs Up, and Why the Split Matters
ISPConfig produces three kinds of archive:
- **Website files**, scheduled on the website itself. This is the site's own directory tree, including the `web` folder your pages live in, but leaving out the site's log folder.
- **MySQL databases**, one archive per database. Saving a schedule on the website's **Backup** tab also applies that same interval and copy count to every database attached to the site. Each database additionally carries its own **Backup interval** field.
- **Mailboxes**, scheduled on each mailbox in the Email module, one archive per address.
Mailboxes are genuinely independent. A mailbox that receives contracts can be backed up daily while the rest are left off entirely, and no website setting changes that either way. Websites and their databases are not independent in the same way. Changing the interval, the copy count or a format on a website's **Backup** tab and saving writes that interval and copy count onto every database currently attached to the site, replacing whatever those databases were set to. You can still give one database a different interval on its own form afterwards, but treat that as temporary, because the next change you save on the website's Backup tab will overwrite it again.
The trade-off is honest and worth stating. Panels that produce a single account-wide archive give you one button and one thing to remember, and restoring the whole account is straightforward. ISPConfig gives you smaller archives and the ability to put back only the database without touching the files, at the cost of setting backups up in two modules rather than on one page. Neither approach is wrong, but if you have come from a single-archive panel, the mistake to avoid is switching on the website backup and assuming everything came with it. The site's databases usually did. The mailboxes never do.
### Where each setting lives
- **Website files:** **Sites** module, open the website, **Backup** tab.
- **A database:** the website's **Backup** tab covers every database attached to the site, and for a single database on its own, the **Sites** module, open the database, the **Backup interval** field on the main form.
- **A mailbox:** **Email** module, open the mailbox, **Backup** tab.
All three write their archives to the same place on the server, and the finished website and database archives are listed together on the website's Backup tab, which is the part that catches people out. Scheduling a database backup and looking for it on the database screen will not find it.
## Back Up a Website's Files
1. Open the **Sites** module and click **Website** in the left menu.
2. Click the domain you want to protect.
3. Open the **Backup** tab.
### Backup interval
Choose **Daily**, **Weekly** or **Monthly**. **No backup** is the setting that leaves the site unprotected, and on a new site it is what you start with, so this is a deliberate choice you have to make rather than something that happens by default.
Two details the drop-down does not tell you: **Weekly** means Sundays, and **Monthly** means the first day of the month. They are not rolling seven-day or thirty-day timers. If you pick Monthly on the second of the month, nothing will happen for another four weeks. The job itself runs once a day at a time chosen by the server administrator, normally in the quiet early hours, so a backup you switch on this afternoon appears tomorrow morning rather than immediately.
One more condition applies: a website whose **Active** checkbox is unticked is skipped entirely. Taking a site offline for maintenance also stops its backups, which is exactly when you would want them.
### Number of backup copies
This is the retention control, offering 1 to 10, then 15, 20 and 30. Read it together with the interval, because the two multiply into a time window: daily with 10 copies keeps roughly the last ten days, weekly with 4 keeps roughly the last month, monthly with 12 keeps roughly the last year. When a new archive pushes the count past the limit, the oldest is deleted automatically.
The useful and non-obvious part is that the count is applied per item, not per account. Ten copies on a website means ten website archives. Ten copies on each of three databases means ten archives each, thirty in total. That is what makes the granularity practical, but it is also how disk usage gets away from people, so see the sizing note further down.
### Excluded Directories
Paths listed here are left out of the website archive. They are relative to the site's root directory and separated by commas, and the field's own example is `web/cache/*,web/backup`. Only letters, numbers and the characters used in ordinary paths are accepted, and `..` is rejected outright, so a validation error here almost always means a stray character rather than a missing folder.
This field earns its keep on content management systems. Caches, generated thumbnails, compiled template folders and locally stored copies of other backups are all rebuildable or duplicated, and excluding them can cut an archive dramatically without losing anything you would actually want back. Do not exclude anything you cannot regenerate, and remember that user uploads are usually not regenerable.
### Compression options and Encryption options
Below the main fields are two collapsed panels. Most accounts never need to open them.
**Compression options** holds **Backup format for web files** and **Backup format for database**. The default entry is labelled to show what it falls back to, and the alternatives run from ordinary zip and gzip through to bzip2, xz and 7z variants. Stronger compression produces a smaller file and takes longer and more processor time to produce, which matters on a shared server. If a format you pick is not available on the server, ISPConfig says so in a warning listing exactly which tools are missing rather than failing silently, so trust the message and choose something else. The practical advice is to leave the default alone unless you have measured a reason to change it.
**Encryption options** holds an **Enable encryption** checkbox and a **Password** field, and ISPConfig states in the panel itself that encryption is available only for the 7z, RAR and zip formats, and that zip's own encryption is not secure. Two cautions if you turn this on. First, an encrypted archive is worth exactly nothing without the password, so record it somewhere that will survive the event you are backing up against. Second, ISPConfig records the password against each archive at the moment that archive is made, so changing the password later does not stop the panel restoring the older ones. It does mean an archive you have already downloaded needs the password that was in force on the day it was taken, not the one on the tab today. Set it once, write it down, and leave it.
Click **Save** when you are done. As everywhere else in ISPConfig, the small red change indicator near the top of the panel means the setting is still being written out; it clears within about a minute.
## Back Up a Database
If you have just set a schedule on the website's **Backup** tab, the databases attached to that site at the time already picked it up and there is nothing more to do. Two cases still need the database form: a database created after you last saved the website's Backup tab, which starts at **No backup** and is not brought in line retrospectively, and a database you want on a different schedule from the rest of the site.
1. In the **Sites** module, click **Database** in the left menu.
2. Click the database you want to protect.
3. Set the **Backup interval** field on the form to **Daily**, **Weekly** or **Monthly**, and click **Save**.
The same Sunday and first-of-the-month rules apply. What decides whether a dump runs at all is any active database on the site being due that night; once one is, ISPConfig dumps every database belonging to that website in the same pass, so a database left on **No backup** or marked inactive can still end up with an archive if a sibling database triggered the run. The retention count for database archives is applied per database, so each one keeps its own set of copies.
Once the job has run, the resulting archives appear in the **Existing backups** list on the parent website's Backup tab, marked with the type **MySQL Database**. That is where you download or restore them from. If you have several databases attached to one site, they are all listed there together, and the database name is part of each file name, so tell them apart by the file name rather than by the row order.
A word on what a database dump is for. Your website archive contains the files that make the site work; the database contains everything the site has recorded since, including orders, comments, form submissions and content. For anything running WordPress, Joomla or a shop, the database is usually the part you would grieve over, so if you only schedule one thing, schedule this.
## Back Up a Mailbox
1. Open the **Email** module and click **Email Mailbox** in the left menu.
2. Click the address you want to protect.
3. Open the **Backup** tab.
4. Set **Backup interval** and **Number of backup copies**, then click **Save**.
The mailbox tab is deliberately simpler than the website one: an interval, a copy count, and the list of archives already taken. There is no exclusions field, no format choice and no encryption option, and the archive format follows whatever the server is configured to produce. Everything said above about Sundays, the first of the month and the overnight run applies here too, and the copy count is per mailbox, so setting five copies on eight mailboxes means up to forty archives. One difference from the website side matters a great deal: setting a mailbox's interval back to **No backup** does not merely stop new archives, it removes the archives that mailbox already has on the next overnight run. Restore or ask for anything you still want before you switch it off.
Now the limitation worth knowing before you rely on it: the mailbox backup list offers **Restore** and **Delete Backup**, but no download. A mailbox archive is a server-side safety net for putting mail back into the same mailbox, not a way to hand yourself a portable copy of your email. If what you actually want is a personal offline copy of your mail, the reliable route is an IMAP client, which downloads messages to your own machine as you go; see [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/). If you need the archive file itself, for example to move a mailbox to another provider, open a support ticket and ask the Noiz team to retrieve it.
## Run a Backup Now Without Waiting
Scheduled jobs are for ordinary weeks. Before a plugin update, a theme change or a content migration, you want a copy taken in the next few minutes.
The website Backup tab carries a **Manual backup** control with two buttons, **Make backup of databases** and **Make backup of web files**, which is exactly the split described above showing up again. ISPConfig warns you before it starts that manual copies count towards the same allowance as scheduled ones, so if the site is already at its limit, taking a manual backup deletes the oldest scheduled one. On a site set to keep two copies, two manual backups in a row will quietly consume your entire history. Raise the copy count for the day you are doing risky work, then put it back.
The backup is queued rather than run instantly, so you get a message saying the process has started and may take several minutes. Leave the tab and come back rather than watching it.
## How to Tell It Actually Worked
The morning after you switch a schedule on is the moment to check, not the morning after you need it.
Open the website's Backup tab and look at the **Existing backups** list. Each row shows the date, the type (**Website files** or **MySQL Database**), the file name, the file size, the backup format, whether it is encrypted, and whether it came from the scheduler or from a manual run. Three quick sanity checks: the date is recent, the size is plausible for the amount of content you have, and both a website row and a database row are present if you scheduled both. A database archive of a few kilobytes for a site with years of content deserves a second look.
For the overview across everything, ISPConfig has two summary screens. In the **Sites** module, under **Statistics**, **Backup Stats** lists your websites with the interval, the number of copies held and the space they occupy. The **Email** module has its own **Backup Stats** under **Statistics**, listing the same figures per mailbox. Both are worth a glance once a month, for two reasons: an item with an interval set but still showing a count of zero several days later is a schedule that is not working, and the size column is how you notice backups quietly eating your disk allowance. The counts are read from ISPConfig's own record of the archives it is holding, so they move as jobs finish rather than only once a day. A manual backup shows up once its job has completed, which is minutes rather than immediately, so give it a moment before concluding something is broken.
## Where the Archives Live, and Getting a Copy Off the Server
Archives are written to a backup directory on the server, outside your web space, in a separate folder per website and per mail domain. You cannot browse that location from a shared hosting account, and that is intentional: it keeps the backups out of reach of anything that compromises the website itself. File names are predictable and worth recognising, since they are built from the item and a timestamp, with manual runs prefixed so you can tell them from scheduled ones at a glance.
To get a website or database archive into your own hands, use the **Download** button on its row in the **Existing backups** list. This does not stream the file to your browser. It queues a job that copies the archive into a folder named `backup` inside your website's directory, sitting alongside your `web` folder, from where you collect it over FTP or SFTP. If you have not set up access yet, see [How to Create an FTP Account in ISPConfig](/ispconfig/how-to-create-an-ftp-account-in-ispconfig/).
Two things follow from that design, and both catch people out:
- **The file is not there instantly.** Give it a few minutes and refresh your FTP client. If you queue a second download while the first is still pending, ISPConfig tells you there is already a job waiting rather than starting another.
- **The copy in that folder is temporary.** ISPConfig clears anything older than three days out of the website's `backup` folder, so download it to your own machine promptly. This is a staging area, not storage. It is also inside your web space, so it counts towards your disk usage while it sits there.
Do this deliberately rather than only in an emergency. Once a month, download the most recent website and database archives and keep them somewhere that is not the hosting server, ideally somewhere that is not the same computer as your working copy either. Panel backups protect you from your own mistakes and from software going wrong. A copy you hold yourself is the one that protects you from everything else.
## Choosing Settings You Will Not Regret
A reasonable starting point for a typical business site, to adjust rather than adopt blindly:
- **Databases:** daily, with 7 to 14 copies. Content changes constantly and dumps are small.
- **Website files:** daily if you or a developer change the site often, weekly if it is stable, with enough copies to cover the time it would realistically take you to notice a problem. If you check the site once a fortnight, three daily copies will not save you.
- **Mailboxes:** daily on the addresses that carry business records, with a modest copy count. Mail archives are the largest of the three and grow with the mailbox.
- **Exclusions:** add cache and temporary directories to the website's Excluded Directories once you know where your software puts them.
Size the whole thing before you commit to it. Multiply each item's typical archive size by its copy count and add them up. If that total is a meaningful fraction of your plan's disk allowance, reduce copies on the largest items first, since retention costs space linearly while frequency mostly costs processing time. If the arithmetic does not fit, ask the Noiz team about a plan with more space rather than leaving a schedule you cannot afford in place until it fills the account.
## Troubleshooting
- **There is no Backup tab on the website or the mailbox**: the backup function is a per-account permission and is granted separately for web and for mail, so its absence means your plan does not currently include it. Open a support ticket to ask about enabling it.
- **The interval is set but no archive appeared**: check the day first. Weekly runs on Sundays and monthly on the first of the month, so a backup switched on mid-week may be days away. Then confirm the website or database is ticked **Active**, since inactive items are skipped. Then allow for the overnight run: a schedule saved this afternoon produces its first archive tomorrow morning.
- **The database was not backed up even though the website was**: a database created after you last saved the website's **Backup** tab starts at **No backup** and does not inherit the site's schedule retrospectively. Set the **Backup interval** on the database form, or change and re-save the website's Backup tab, which applies the site's interval and copy count to every database attached to it.
- **Older backups have disappeared**: the copy limit was reached and ISPConfig deleted the oldest to make room. Manual backups count towards the same limit. Raise **Number of backup copies** if you need a longer history and the space allows.
- **A warning says some formats are not installed**: the compression tool for that format is not present on the server, and ISPConfig names the missing ones. Choose the default format instead, or ask support whether the tool you want can be provided.
- **The Excluded Directories field will not save**: it accepts only ordinary path characters, rejects `..`, and expects paths relative to the site root separated by commas. Retype the entry following the pattern `web/cache/*,web/backup` rather than pasting an absolute path.
- **The downloaded archive is not in the backup folder**: downloads are queued, so wait a few minutes and refresh. If ISPConfig says a download is already pending, an earlier request is still being processed. Note also that files in that folder are cleared out once they are three days old.
- **There is no Download button on the mailbox backup list**: that is by design. Mailbox archives can be restored or deleted from the panel but not downloaded. Use an IMAP client for a portable copy of your mail, or ask support to retrieve the archive file.
- **An encrypted archive will not open**: the password is the backup password from the website's Backup tab, not your panel or FTP password, and encryption applies only to 7z, RAR and zip archives. If the password has been changed since that archive was taken, the one you need is the older password, not the current one.
- **Disk usage climbed sharply after switching backups on**: check both **Backup Stats** screens for the size columns. Reduce the copy count on the largest items and add cache directories to the exclusions, then re-check the following day.
## Related Guides
- [How to Restore a Backup in ISPConfig](/ispconfig/how-to-restore-a-backup-in-ispconfig/)
- [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/)
- [How to Create a Database and Database User in ISPConfig](/ispconfig/how-to-create-a-database-and-database-user-in-ispconfig/)
- [How to Create an Email Mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/)
- [How to Create an FTP Account in ISPConfig](/ispconfig/how-to-create-an-ftp-account-in-ispconfig/)
- [How to Log In to the ISPConfig Control Panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/)
If you would rather Noiz set sensible backup schedules up for you, or you are on a managed plan and want the backup sizing reviewed against your disk allowance, open a support ticket and the Noiz team will handle it. If something has already gone wrong, raise the ticket before deleting or overwriting anything, and include the domain name, which item you need recovered, and the date you last knew it to be correct.
# How to Change Your ISPConfig Password and Interface Language
Source: https://docs.noiz.ie/ispconfig/how-to-change-your-ispconfig-password-and-interface-language/
This guide shows you how to change the password you use to log in to the ISPConfig control panel, and how to switch the language the panel interface is displayed in. Both settings live on the same screen, which the official manual calls **Password and Language**; in the current ISPConfig interface it appears under **User Settings** on the **Tools** tab. The guide is for Noiz clients who log in to ISPConfig to manage their hosting account. It covers your ISPConfig login password only: your mailbox, FTP and database passwords are separate and are not affected by anything on this screen.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig documentation overview](https://www.ispconfig.org/documentation/): the index of official ISPConfig documentation
- [ISPConfig 3 User Manual](https://www.ispconfig.org/documentation/user-manual/): the official manual, which documents this screen under its older name, Password and Language
- [ISPConfig 3.2 Beta 3 release announcement](https://www.ispconfig.org/blog/ispconfig-3-2-beta-3-released/): documents the merge of the older Password and Language and Interface screens into the single User Settings screen described in this guide
- [ISPConfig 3.2.9 release announcement](https://www.ispconfig.org/blog/ispconfig-3-2-9-released/): documents the addition of the Two Factor Authentication option that appears on the same screen
- [ISPConfig source repository](https://git.ispconfig.org/ispconfig/ispconfig3): the field names and menu labels in this guide were verified against the released 3.3.1p1 code
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/) with your current username and password.
- You know your current password. If you have lost it, see the Troubleshooting section below instead.
- Somewhere safe to record your new password, such as a password manager.
## Open Your User Settings
1. Log in to the ISPConfig control panel.
2. Click the **Tools** tab in the top menu.
3. In the menu on the left, under **User Settings**, click **User Settings**. In older ISPConfig versions this link was called **Password and Language**; since ISPConfig 3.2 it has been merged with the old Interface screen into a single **Settings** form.
The **Settings** form that opens contains everything covered in this guide: the password fields, the **Language** selector, and a few related interface options.
## Change Your ISPConfig Password
1. In the **Password** field, type your new password. You can instead click **Generate Password** to have ISPConfig create a strong random password for you; if you do, copy the generated password into your password manager before you save, because you will need it at your next login.
2. Watch the **Password strength** indicator below the field. Aim for a strong rating: use at least 8 characters (longer is better) and mix upper and lowercase letters, numbers and symbols. Avoid dictionary words, sequences, usernames, names of relatives or pets, and other personal information.
3. Type the same password again in the **Repeat Password** field. ISPConfig confirms with the message `The passwords do match.` when both entries are identical.
4. Click **Save**.
The change takes effect immediately, and saving does not end your current session, so you stay logged in and use the new password from your next login onwards. Only your ISPConfig control panel login is affected. Mailbox passwords, FTP user passwords and database user passwords are managed on their own screens in the **Email** and **Sites** modules and stay exactly as they were.
## Change the Interface Language
1. On the same **Settings** form, open the **Language** drop-down list.
2. Select the language you want the ISPConfig interface displayed in. Languages are listed by their two-letter code, for example `en` for English or `de` for German.
3. Click **Save**. The form reloads in the language you picked.
ISPConfig applies the new language to your session as soon as you save, so you do not need to log out and back in. The top tabs and the side menu were drawn when you first loaded the panel, so if those are still in the old language, reload the page in your browser and they will catch up.
The language setting applies to your ISPConfig user only. Other users on the same account keep their own language choice, and your websites and email are not affected in any way.
## Other Options on the Settings Form
You do not need to touch these to change your password or language, but they sit on the same form, so it helps to know what they do:
- **Two Factor Authentication**: set to `none` by default, with `email` as the only other choice. Set it to `email` and ISPConfig emails you a one-time code at each login, which you enter on a second screen before the panel opens. The emailed code is valid for ten minutes, and that screen carries a **Request new code** option for when it expires or does not arrive. Make sure the email address on your account is working and accessible before you enable it, otherwise you can lock yourself out.
- **Design**: the visual theme of the panel. Leave it on `default` unless additional themes have been installed.
- **Startmodule**: the tab ISPConfig opens straight after you log in. By default this is the dashboard; you could set it to the **Sites** or **Email** module if you always start there.
Click **Save** after changing any of these, or **Cancel** to leave the form without saving.
## Troubleshooting
**Symptom: ISPConfig shows "The passwords do not match."** The **Password** and **Repeat Password** fields contain different text. Clear both fields and retype the new password carefully in each, or use **Generate Password** and copy the result.
**Symptom: part of the interface is still in the old language after saving.** The settings form itself switches straight away, but the top tabs and the side menu are only drawn when the panel first loads. Reload the page in your browser to redraw them. If the whole panel is still in the old language, the save did not go through: reopen **Tools**, then **User Settings**, and check that the **Language** selector is showing the language you chose.
**Symptom: you used Generate Password, saved, and did not note the new password.** Saving does not log you out, so your current session still works. Go straight back to **Tools**, then **User Settings**, and set a password you have recorded before you close the browser. If you have already been logged out, use **Password lost** on the ISPConfig login page, or contact the Noiz support team.
**Symptom: you have forgotten your current password and cannot log in at all.** Use the **Password lost** link on the ISPConfig login page. It asks for both your ISPConfig username and the email address held on your client record, and the two have to match before anything is sent. You then receive a confirmation link by email, and following that link generates a new password and emails it to you. This function can be switched off for an individual user, so if ISPConfig replies that it is not available for your account, or the email never arrives, open a support ticket with Noiz to have the password reset for you.
**Symptom: there is no Tools tab after you log in.** You are probably not logged in as your ISPConfig client user. Logging in to webmail, or logging in to ISPConfig with an email address and mailbox password, shows a different, limited interface. Log in with your ISPConfig client username as described in the [login guide](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
**Symptom: email or FTP stopped working after the change.** Nothing on this screen touches mailbox or FTP passwords, so the timing is coincidence. Check the affected service separately, and remember that your mailbox password and ISPConfig password are two different credentials that only match if you deliberately set them the same.
If you get stuck at any point, open a support ticket with the Noiz support team and include your ISPConfig username, the domain your hosting account is under, and whether the problem is with logging in, saving the form, or the language not applying. Never include your new password in a support ticket.
# How to Change a Mailbox Password in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-change-a-mailbox-password-in-ispconfig/
This guide shows you how to change the password on an existing email mailbox in the ISPConfig control panel on your Noiz hosting account, and, more importantly, what to do straight afterwards so that your mail keeps arriving. The mailbox password is the one credential that every device and app uses to collect and send mail for an address such as `you@yourdomain.com` (an example: use your own address). You may see it called the email password, the IMAP or POP password, the SMTP password or the webmail password. They are all the same single password, which is why changing it has a wider reach than most people expect. If you are creating a mailbox for the first time rather than changing one, start with [How to Create an Email Mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/) instead.
**This is not your ISPConfig panel password.** Your ISPConfig login, each mailbox, and your Noiz client area (billing) login are three separate credentials that only match if somebody deliberately set them the same. Changing one does not change the others. To change the password you use to sign in to the control panel itself, see [How to Change Your ISPConfig Password and Interface Language](/ispconfig/how-to-change-your-ispconfig-password-and-interface-language/).
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** (the version Noiz runs). This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig documentation overview](https://www.ispconfig.org/documentation/): the official documentation index.
- [ISPConfig 3 User Manual](https://www.ispconfig.org/documentation/user-manual/): a paid PDF download from the ISPConfig project, which in the publisher's words "includes a reference for all forms and form fields in ISPConfig together with examples of valid inputs". Worth knowing before you click: it is sold rather than published on the web, and the current edition covers ISPConfig 3.1, so the Email Mailbox form it describes is a few releases behind the one you will see. The steps below are written against the version Noiz runs.
- [NCSC: Three random words](https://www.ncsc.gov.uk/collection/top-tips-for-staying-secure-online/three-random-words): sound, practical guidance on choosing a password that is both strong and memorable.
## Prerequisites
- Access to the ISPConfig control panel for the account the mailbox belongs to. If you have not signed in before, see [How to Log In to the ISPConfig Control Panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- A place to record the new password before you save it, such as a password manager. ISPConfig stores mailbox passwords in a form it cannot read back, so nobody, including Noiz support, can retrieve the old or the new value for you later.
- A few minutes with the devices that use the mailbox. Read the next section before you change anything.
## Read This First: Everything Using the Mailbox Stops Collecting Mail
This is the part that catches people out, so it comes before the steps rather than after them. The moment the new password takes effect, every device and program that still holds the old one is refused by the mail server. Nothing is deleted and no mail is lost: messages simply queue on the server until something signs in successfully and collects them. But until you enter the new password everywhere, those devices are quietly failing.
"Everywhere" is usually longer than the list people have in their heads. Before you change the password, write down every place the mailbox is signed in:
- **Phones and tablets**, including a second phone in a drawer and a family member's device that was set up years ago. Phones are the single most common thing forgotten, because the mail app keeps showing the old messages it already downloaded, so the account looks fine at a glance.
- **Desktop mail clients** such as Outlook, Apple Mail or Thunderbird, on every computer where the mailbox was added.
- **Websites that send mail as this address.** If a contact form, an order confirmation or a WordPress SMTP plugin authenticates with this mailbox, it will stop sending, and it will usually fail silently. Nobody notices until a customer says an enquiry was never answered.
- **Office equipment and line-of-business software**: scan-to-email on a printer, a booking or CRM system, a backup or monitoring tool that emails its reports.
- **Anything collecting from this mailbox on a schedule**, for example another mail system set to fetch from this address and pull the mail elsewhere.
There is a second, less obvious consequence. A device left holding the old password does not give up; it retries every few minutes, around the clock. Enough failed logins from the same connection can cause the server's brute-force protection to block your internet address, which then breaks webmail and the panel for you as well, from that location, even with the correct password. If that happens, see [What to Do If Your IP Address Is Blocked by an ISPConfig Server](/ispconfig/what-to-do-if-your-ip-address-is-blocked-by-an-ispconfig-server/). The way to avoid it entirely is to update the devices promptly, or to switch a device you cannot get to right away off automatic checking until you can.
## Find the Mailbox
1. Sign in to ISPConfig and click **Email** in the top menu.
2. In the left sidebar, under **Email Accounts**, click **Email Mailbox**.
3. Click the address you want to change in the list. That opens the same form the mailbox was created on, with its existing settings loaded.
If the list is long, the filter row at the top of the table narrows it by address or domain. If the mailbox you expect is not listed at all, you are either signed in as the wrong ISPConfig user or the address is an alias or a forwarder rather than a real mailbox. Aliases and forwarders have no password of their own, because they hold no mail: they hand delivery to a real mailbox, and it is that mailbox's password that matters. See [How to Set Up Email Forwarding in ISPConfig](/ispconfig/how-to-set-up-email-forwarding-in-ispconfig/) if you are not sure which you have.
## Change the Password
On the **Mailbox** tab, the **Password** field is blank, even though the mailbox obviously has a password. That is expected and is not a fault: ISPConfig never displays a stored mailbox password, and there is no way to reveal it. It also means the field is safe to leave alone. If you save the form without typing anything in it, the existing password is kept, so you can edit the quota or the name of a mailbox without disturbing its password.
1. Type the new password in **Password**, then the identical value in **Repeat Password**. Save the new password to your password manager before you go any further.
2. Watch the **Password strength** field, which sits between the two password boxes. Noiz servers enforce a minimum password length and strength for mailboxes, so a weak entry is rejected when you save rather than silently accepted. Aim well past the minimum, and do not reuse the mailbox password from any other account. A long passphrase of several unrelated words is the sound choice, with one caveat: the meter scores the mix of character types as well as the length, so plain lowercase words can be graded weak however long the phrase is. A capital, a digit and one punctuation mark inside the passphrase clears the check without making it harder to remember.
3. If you use the **Generate Password** button, it fills both password fields for you and shows the value in plain text so you can copy it. Take that copy before you save, because once the form is saved the value cannot be read back.
4. Click **Save**.
Two practical points about what you type. Avoid a leading or trailing space, which is easy to pick up when copying and pasting and impossible to see afterwards; it is a genuine password character and will be rejected by mail clients that trim it. And keep in mind that a phone keyboard will have to reproduce whatever you choose, on the small screen, at least once per device.
Changing the password affects nothing else about the mailbox. The address, its stored mail, folders, quota, aliases, forwarders and any autoresponder all stay exactly as they were. If you are changing the password because the mailbox was compromised, though, do check those settings as a separate exercise: anything an attacker left behind keeps working regardless of the new password. Three tabs on the mailbox form are worth checking. **Send copy to** and **Send outgoing BCC to**, both on the **Mailbox** tab, quietly copy every incoming or outgoing message to another address. The **Autoresponder** tab holds any automatic reply. The **Mail Filter** tab holds rules that can move or redirect mail as it arrives.
## Confirm It Worked
Allow up to a minute or two before testing. ISPConfig hands changes to the mail server on a short cycle rather than instantly, so a login attempt in the first few seconds can still be judged against the old password.
1. Open webmail in a private or incognito browser window and sign in with the **full email address** and the **new** password. See [How to Access Your Webmail in ISPConfig](/ispconfig/how-to-access-your-webmail-in-ispconfig/) for the address to use. Webmail is the cleanest test because it authenticates against the mailbox on every login and holds no saved credentials of its own; a private window makes sure a stored password in the browser is not doing the work for you.
2. Send a message to the mailbox from an outside address and confirm it arrives, then reply to it. That proves collecting and sending are both healthy.
3. Now work through the list you wrote earlier and enter the new password on each device and app. On phones this normally appears as a prompt to sign in again on the mail account; on a desktop client it is in the account settings for that mailbox. If you need the incoming and outgoing server details while you are in there, [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/) sets out the pattern those settings follow.
Do not read "my laptop is still receiving mail" as proof that the change did not apply. A mail client that is already connected can stay connected on its existing session for a while and only fail when it next reconnects. Webmail in a fresh private window is the reliable answer.
## Troubleshooting
**Symptom: ISPConfig will not save the form and complains about the password.** Either the two fields differ, or the password is below the minimum length or strength the server requires. Clear both fields and retype the value carefully, or use **Generate Password** and copy the result.
**Symptom: the new password is rejected everywhere, including webmail.** Confirm the username is the **full email address** and not just the part before the `@`. If that is right, wait two minutes and try once more, in case you tested before the change was applied. If it still fails, reopen the mailbox in ISPConfig and set the password again, this time using **Generate Password** so there is no chance of a typo or a stray space.
**Symptom: webmail works but a phone or mail client keeps asking for the password.** The app is still sending the old one. Some mail apps hold a separate password for outgoing (SMTP) mail as well as incoming, and both need updating. Some cache the old value stubbornly: if repeated attempts fail with a password you know is correct, remove the account from the device and add it again.
**Symptom: mail stopped arriving, or the website stopped sending, and nothing was changed on that device.** Something was almost certainly configured with the mailbox password and then forgotten. Work back through the list above, giving particular attention to website contact forms, SMTP plugins and office equipment.
**Symptom: everything is refused from one location, including the correct new password.** That is the pattern of a brute-force block triggered by a device retrying the old password. See [What to Do If Your IP Address Is Blocked by an ISPConfig Server](/ispconfig/what-to-do-if-your-ip-address-is-blocked-by-an-ispconfig-server/), and find the device that is still using the old password before the block simply returns.
**Symptom: you have forgotten the current password and cannot get into the mailbox.** There is nothing to recover, because the stored password cannot be read back. Setting a new one from ISPConfig, as above, is the fix; no old password is needed to do it.
If a mailbox still refuses the new password after you have worked through the above, open a support ticket with the Noiz support team. Include the mailbox address, the domain, roughly when the password was changed, and which device or app is failing. Noiz managed plan clients can also ask the support team to make the change on their behalf. Never send a password in a support ticket.
## Related Articles
- [How to Create an Email Mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/)
- [How to Change Your ISPConfig Password and Interface Language](/ispconfig/how-to-change-your-ispconfig-password-and-interface-language/)
- [How to Access Your Webmail in ISPConfig](/ispconfig/how-to-access-your-webmail-in-ispconfig/)
- [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/)
- [What to Do If Your IP Address Is Blocked by an ISPConfig Server](/ispconfig/what-to-do-if-your-ip-address-is-blocked-by-an-ispconfig-server/)
- [How to Set Up Email Forwarding in ISPConfig](/ispconfig/how-to-set-up-email-forwarding-in-ispconfig/)
# How to Configure Spamfilter Policies for a Mailbox in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-configure-spamfilter-policies-for-a-mailbox-in-ispconfig/
This guide shows you how to choose a spamfilter policy for an individual mailbox in the ISPConfig control panel, and explains what the built-in policy levels and their tag and kill scores actually do. A mailbox is sometimes called an email account, and a spamfilter policy is sometimes called a spamfilter level: it is the set of rules that decides how aggressively incoming mail for that address is checked for spam and viruses. By the end of this guide you will know how to pick the right policy for each mailbox, how mailbox settings interact with the domain-wide setting, and how to read the scores that decide whether a message is tagged as spam or blocked outright.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**, the release Noiz runs. The field names, policy names and default scores below were checked against that release. This guide complements, and does not replace, the official ISPConfig documentation linked below. ISPConfig evolves between releases, so if a screen differs from this guide, check those links.
### Official Documentation Reference
- [ISPConfig official documentation index](https://www.ispconfig.org/documentation/), home of the ISPConfig 3 manual that this article is based on
- [Howtoforge forum: Clarification of Spam Filter Policies in ISPConfig 3](https://forum.howtoforge.com/threads/clarification-of-spam-filter-policies-in-ispconfig3.38480/), background on the default policy levels and score thresholds
- [ISPConfig 3.3.1p1 source: spamfilter policy interface text](https://git.ispconfig.org/ispconfig/ispconfig3/-/raw/3.3.1p1/interface/web/mail/lib/lang/en_spamfilter_policy.lng), the exact field labels used by the current policy editor
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- At least one mailbox already exists on your account. If not, first [create an email mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/).
- Your hosting plan includes the **Email** module. If you cannot see it after logging in, your plan may not include email hosting through ISPConfig.
## How Spamfilter Policies Work
Every message that arrives for a filtered mailbox is scanned and given a spam score. The higher the score, the more likely the message is spam. A spamfilter policy is a named set of thresholds and behaviours that tells the mail system what to do at each score: add warning headers, tag the subject line, or refuse the message entirely.
ISPConfig lets you apply a policy at two levels:
- **Per email domain**: the **Spamfilter** field on the domain under **Email** > **Email Accounts** > **Domain** sets the default for every mailbox on that domain.
- **Per mailbox**: the **Spamfilter** field on the individual mailbox overrides the domain default for that one address.
The mailbox dropdown includes the option **- Inherit domain setting -**, which is the default for new mailboxes. While it is selected, the mailbox simply follows whatever policy the domain uses. As soon as you pick a named policy on the mailbox, that choice wins for this mailbox, regardless of what the domain is set to. That holds even when the domain's **Spamfilter** field is `- not enabled -`: a policy chosen on the mailbox still applies.
## Select a Spamfilter Policy for a Mailbox
### Open the Mailbox Settings
1. Log in to the ISPConfig control panel.
2. Click **Email** in the top menu.
3. In the left-hand menu, under **Email Accounts**, click **Email Mailbox**. A list of your mailboxes appears.
4. Click the email address of the mailbox you want to change, for example `info@yourdomain.com` (replace `yourdomain.com` with your own domain).
### Choose a Policy and Save
1. On the **Mailbox** tab, find the **Spamfilter** dropdown.
2. Select the policy you want for this mailbox. `- Inherit domain setting -` is always first; the named policies follow in alphabetical order, so the standard list reads: For almost every mailbox, `Normal` is the right choice. The next section explains what each level means.
- `- Inherit domain setting -`
- `Non-paying`
- `Normal`
- `Permissive`
- `Trigger happy`
- `Uncensored`
- `Wants all spam`
- `Wants viruses`
3. Click **Save**.
ISPConfig applies configuration changes in the background, so allow a minute or two before testing. The new policy affects mail that arrives after the change; it does not rescan messages already in the mailbox.
## What the Policy Levels Mean
The seven built-in policies are working examples inherited from the underlying mail filter, and their names describe the kind of recipient they were written for. Two of them switch filtering off, by different means; the rest differ mainly in where the score thresholds sit. Listed here roughly from least filtering to most:
- `Uncensored`: mail is still scanned, but the results of the spam, virus, banned file and bad header checks are all ignored and everything is delivered. Selecting this level effectively switches the spamfilter off for the mailbox. Use it only for troubleshooting or for special-purpose addresses that must receive absolutely everything.
- `Non-paying`: switches filtering off the other way round, by skipping the spam, virus and banned file checks entirely rather than scanning and then ignoring the verdict. It is an example policy for accounts not entitled to a filtering service, and it is rarely the right choice on a hosting account. Prefer `Normal` unless the Noiz support team advises otherwise.
- `Wants all spam`: spam checks run and spam is still tagged, but no spam is ever blocked; all of it is delivered. Virus mail is still blocked. Useful for an abuse or postmaster address that needs to see the spam other people are sent.
- `Wants viruses`: the mirror image. Virus results are ignored, so messages carrying malware are delivered, while spam is filtered and blocked as usual. Not recommended for normal mailboxes.
- `Permissive`: filtering is active but the score thresholds are set high, so only very obvious spam is affected. Choose this if legitimate mail is being wrongly flagged under `Normal`.
- `Normal`: the balanced default. Suspicious mail gets informational headers, likely spam is tagged in the subject line and filed to Junk, and outright blocking is reserved for extreme scores. This is the recommended level for everyday mailboxes.
- `Trigger happy`: the thresholds are set low and the blocking threshold sits level with the tagging one, so the filter fires early, catches more spam and refuses it rather than tagging it. That carries a real risk of losing legitimate mail. Choose it only for addresses drowning in spam.
## Understanding Tag and Kill Scores
Each policy is defined by a small set of score thresholds. You can view them under **Email** > **Spamfilter** > **Policy**: click a policy name to open it. Whether you can see or edit this section depends on the limits of your hosting plan, and that is fine, because you only need the mailbox dropdown for day-to-day use.
The classic thresholds, found on the **Tag-Level** section of the policy form, are:
- **SPAM tag level**: at or above this score, the system adds informational spam headers to the message (visible in the message source, for example `X-Spam-Score`). The message is still delivered normally. ISPConfig ships `Normal` with this set to `1`.
- **SPAM tag2 level**: at or above this score, the message is formally classed as spam. It receives spam-detected headers, and if **SPAM modifies subject** is enabled, the **SPAM subject tag2** text is added to the subject line. Those spam-detected headers are also what the Junk folder rule matches on, so this threshold is what decides whether a message is filed as spam. `Normal` ships with tag2 at `4.5` and a subject tag2 of `***SPAM***`.
- **SPAM kill level**: at or above this score, the system takes evasive action and the message is blocked rather than delivered. This value must be equal to or higher than the tag2 level. `Normal` ships with the kill level at `50`, far above its tag2 level, so under the shipped `Normal` policy spam is tagged and delivered, not refused. Where a policy sets the kill level equal to its tag2 level, as `Trigger happy` does, everything that reaches tag2 is blocked instead, and a subject tag serves no purpose there because nothing tagged is delivered.
The policy form also carries a second, simpler set of fields covering the same ground, used where the server runs the newer filtering engine: **SPAM tag level** (the score at which mail is tagged), **SPAM tag method** (whether tagging rewrites the subject line or only adds a header) and **SPAM reject level** (the score at which mail is refused, equivalent to the kill level), alongside **Use greylisting** and a **Greylisting level**, which temporarily defers borderline messages so that legitimate mail servers retry and most spam senders give up. Only one of the two sets is in force on any given server, and the scores in each are set independently, so do not assume a change to one takes effect. If you are unsure which set applies to your mailbox, ask the Noiz support team.
A note of caution: policies are shared. Every mailbox and domain set to `Normal` uses the same `Normal` record, so editing its scores changes filtering for all of them at once. If your plan allows it, create a new policy with **Add Policy record** and assign that to the specific mailbox instead of editing a built-in level.
## Send Tagged Spam to the Junk Folder
Selecting a policy decides how spam is scored; a separate mailbox setting decides where tagged spam ends up. To have spam filed automatically:
1. Open the mailbox as described above and go to its **Mail Filter** tab.
2. Set **Move Spam Emails to Junk folder** to `Move first, before custom filters.`, which is the default for new mailboxes.
3. Click **Save**.
The other two choices are `Move last, after custom filters.`, which gives your own filter rules the first chance to claim the message, and `Do not move Spam Emails to Junk folder.`, which leaves tagged spam in the inbox. The rule matches the spam-detected headers added at the tag2 level, so it fires only once a message crosses that threshold, and only while the spamfilter is active for the mailbox, meaning a policy other than `Uncensored` applies, either inherited from the domain or set on the mailbox itself. The Junk folder is only visible when you collect mail over IMAP; POP3 downloads the inbox only, so POP3 users will not see the Junk folder in their mail program.
## Troubleshooting
- **Too much spam is still reaching the inbox**: confirm the mailbox is not set to `Uncensored`, `Non-paying` or `Wants all spam`, the three levels that let spam through, and that a policy is actually active (if the mailbox is set to `- Inherit domain setting -`, check the domain's **Spamfilter** field is not `- not enabled -`). Then try `Trigger happy` and set **Move Spam Emails to Junk folder** to one of the two move options.
- **Legitimate mail is being tagged or lost**: switch the mailbox to `Permissive`, or add the sender under **Email** > **Spamfilter** > **Whitelist** if that section is available on your plan. Under the shipped `Normal` policy spam is tagged and delivered rather than refused, so check the Junk folder and look for `***SPAM***` in the subject line before assuming a message never arrived. `Trigger happy` does refuse mail outright, so if a mailbox is set to that level, expect genuine losses rather than tagged copies.
- **The policy change appears to have no effect**: allow a minute or two for ISPConfig to apply the change, then send a fresh test message from an external address. Also check for a mailbox-level policy overriding the domain setting, or the reverse.
- **The Spamfilter dropdown or the Spamfilter section is missing**: the email limits on your hosting plan control what you can see. Open a support ticket with the Noiz support team to confirm what your plan includes.
- **Tagged spam is not moving to the Junk folder**: make sure **Move Spam Emails to Junk folder** on the **Mail Filter** tab is not set to `Do not move Spam Emails to Junk folder.`, and that you are accessing the mailbox over IMAP rather than POP3.
If you get stuck at any point, open a support ticket with the Noiz support team and include the mailbox address, the spamfilter policy you selected, and, for filtering problems, the full headers of an example message that was handled incorrectly.
# How to Create Email Filter Rules in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-email-filter-rules-in-ispconfig/
This guide shows you how to create email filter rules for a mailbox in the ISPConfig control panel on your Noiz hosting account. Filter rules (sometimes called message rules, sorting rules or Sieve filters) run on the server the moment a message arrives, before any mail programme sees it, and can move the message to a folder, delete it, keep it in the Inbox, or reject it back to the sender based on its subject, sender, recipient, mailing list ID, any other header, or its size. Because the rules live on the server, they work the same whether you read your mail in webmail, on your phone or on your computer.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This article follows the official ISPConfig manual procedure for creating email filter rules, cross-checked against the current interface. ISPConfig evolves between releases, so if a screen differs from this guide, check the official documentation links below.
### Official Documentation Reference
- [ISPConfig official documentation index](https://www.ispconfig.org/documentation/)
- [ISPConfig 3 documentation: Basic Email Configuration](https://docs.ispconfig.org/modules/mail/basic-email-configuration/)
- [ISPConfig 3 documentation: My First Email](https://docs.ispconfig.org/my-first-email/)
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- The mailbox you want to filter already exists. If not, first [create an email mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/).
- You read the mailbox over IMAP, either in webmail or in a mail programme set up with IMAP. Folders other than the Inbox are only visible over IMAP; POP3 downloads the Inbox alone, so mail filtered into folders would seem to vanish.
## How Filter Rules Work
- Rules belong to one mailbox. Each mailbox on your domain has its own independent set of filter rules.
- Rules only apply to mail that arrives after the rule is saved. Messages already sitting in the mailbox are not sorted retroactively.
- Rules are checked one after the other. A rule that moves, deletes or rejects a message ends processing for that message; later rules do not run on it. Newly added rules are placed at the top of the processing order. The list on the **Mail Filter** tab is sorted by rule name, so it does not show the order in which rules run.
- A message that matches no rule is delivered to the Inbox as normal.
## Open the Mail Filter Tab
1. Log in to the ISPConfig control panel.
2. Click the **Email** tab in the top navigation bar.
3. In the left-hand menu, under **Email Accounts**, click **Email Mailbox**. The list of mailboxes on your account appears.
4. Click the mailbox you want to add filters to, for example `info@yourdomain.com`. The mailbox settings open with the tabs **Mailbox**, **Autoresponder**, **Mail Filter**, **Custom Rules** and **Backup**. **Custom Rules** is only visible to the server administrator, so it does not appear on a hosting account, and **Backup** is not shown on every account either.
5. Click the **Mail Filter** tab.
Besides the list of filter rules, this tab holds three built-in housekeeping settings for the mailbox:
- **Move Spam Emails to Junk folder.**: controls what happens to messages the server-side spam filter has tagged as spam. **Move first, before custom filters.** puts tagged spam into the Junk folder before your own rules run (the usual choice), **Move last, after custom filters.** lets your own rules see the message first, and **Do not move Spam Emails to Junk folder.** leaves tagged spam in the Inbox. This only has an effect while the spam filter is active for the mailbox or its domain, and the Junk folder is only visible over IMAP.
- **Purge Trash automatically after X days**: automatically empties the Trash folder of items older than the number of days you enter. `0` disables the purge.
- **Purge Junk automatically after X days**: the same automatic clean-up for the Junk folder. `0` disables it.
## Create a Filter Rule
### Step 1: Add a new filter
1. On the **Mail Filter** tab, click the **Add new Filter** button. The **Email filter** form opens on its **Filter** tab.
2. In the **Name** field, type a short label that reminds you what the rule does, for example `Newsletters` or `Invoices to folder`. The name is only for you; it does not affect matching.
### Step 2: Set the Source (what to match)
The **Source** section has three parts stacked under one another: which part of the message to examine, how to compare it, and the text to look for.
1. In the first drop-down, choose the part of the message to examine:
- **Subject**: the subject line.
- **From**: the sender.
- **To**: the recipient address the message was sent to. Useful when several addresses deliver into one mailbox.
- **List ID**: the mailing list identifier that most newsletter and discussion list software adds, for example `customers.lists.example.com`.
- **Header**: any other message header of your choice.
- **Email size over (KB)**: the overall size of the message.
2. In the second drop-down, choose the condition: **Contains**, **Is**, **Begins with**, **Ends with**, **Matches Regex (POSIX)**, **Localpart** or **Domain**.
- **Contains** is the safest everyday choice, and matching is not case sensitive. For **From** and **To** in particular, prefer **Contains** over **Is**: the header usually reads `Jane Doe `, so an exact **Is** match on just the address fails. With **Contains** you can match either the address or the display name.
- **Localpart** and **Domain** match exactly the part of an email address before or after the @ sign, and are meant for the address fields **From** and **To**. For example, **From** plus **Domain** plus `example.com` matches every sender at that domain.
- **Matches Regex (POSIX)** is for advanced patterns. It uses POSIX extended syntax; inline flags such as `(?i)` are not supported, so for case-insensitive matching use **Contains** instead, or character classes such as `[aA][bB][cC]`.
3. In the text field, type the search term, for example `invoice` for a subject rule or `newsletter@example.com` for a sender rule. Two sources need a special format here:
- With **Header**, type the header name, a colon, then the text to look for, for example `X-Mailer: ExampleApp`.
- With **Email size over (KB)**, type the size, adding `k` after the number for kilobytes, for example `500k`. A plain number is treated as megabytes, so `10` matches messages larger than 10 MB. The condition drop-down has no effect for size rules; the rule always matches messages larger than the size given.
### Step 3: Choose the Action (what to do with matches)
1. In the **Action** drop-down, choose what happens to messages that match:
- **Move to**: files the message into the folder you name in the text field below the drop-down, then stops further rules. Type the folder name exactly, for example `Newsletters`; use `/` for a subfolder, for example `Work/Invoices`. Folder names may only contain letters, numbers and the characters `-` `.` `_` `&` `/` and spaces. Create the folder in webmail or your IMAP mail programme first if it does not already exist.
- **Delete**: discards the message permanently. The sender is not notified and the message does not appear in Trash, so use this with care; moving suspect mail to a folder you review is usually safer.
- **Keep**: delivers the message to the Inbox and protects it, so a later rule cannot delete it. Unlike the other three actions, **Keep** does not end processing, so later rules still run against the message. Use it as an exception near the top of your rules, for example to keep mail from an important sender that a broader rule further down would otherwise remove.
- **Reject**: refuses the message and returns it to the sender. In this case the text field below the drop-down holds the short rejection note sent back, for example `Not accepted at this address`, not a folder name.
2. Leave the **Active** box ticked so the rule takes effect. Unticking it later switches the rule off without deleting it.
3. Click **Save**. You are returned to the **Mail Filter** tab and the new rule appears in the list.
### Step 4: Test the rule
1. Wait a minute or two: ISPConfig applies changes to the mail server on a short cycle, so a brand-new rule may not take effect instantly.
2. Send the mailbox a test message that matches the rule, for example one with the search term in the subject line.
3. Check the result in webmail or an IMAP mail programme: the message should be in the target folder (or absent, for a delete rule) rather than in the Inbox.
## Edit, Disable or Remove a Rule
- To change a rule, open the mailbox, go to the **Mail Filter** tab and click the rule's name in the list. Adjust the fields and click **Save**.
- To pause a rule without losing it, open the rule, untick **Active** and save.
- To remove a rule permanently, click its **Delete** button in the list and confirm.
## Troubleshooting
- **Filtered messages seem to have disappeared**: your mail programme is probably using POP3, which only sees the Inbox. Log in to webmail, or set the account up with IMAP, and the folders your rules file into will appear. You may also need to subscribe to the folder in your mail programme's folder list.
- **Moved messages land in the Inbox instead of the folder**: the target folder does not exist or its name is spelt differently. Create the folder in webmail with exactly the name used in the rule, including capitalisation, then test again.
- **The rule never matches**: switch the condition to **Contains** and simplify the search term. Remember that **From** headers usually include a display name around the address, that filters only act on newly arriving mail, and that changes take a minute or two to reach the mail server.
- **Spam is not being moved to Junk**: check that **Move Spam Emails to Junk folder.** is not set to **Do not move Spam Emails to Junk folder.**, and that the **Spamfilter** setting on the **Mailbox** tab is on a level other than **Uncensored**, which switches the spam filter off. The level can be set on the mailbox itself or on its mail domain. Only messages the filter has tagged as spam are moved.
- **Error "The max. number of mailfilters is reached."**: your hosting plan's filter limit is full. Delete a rule you no longer need, or open a support ticket with the Noiz support team to discuss raising the limit.
- **Error "The target may only contain these characters: a-z, 0-9, -, ., \_, &, /, and {space}"**: the folder name contains a character ISPConfig does not accept. Rename the target using only letters, numbers and the listed characters.
- **A correspondent says their mail bounced back**: a **Reject** rule matched their message. Review your rules and loosen or deactivate the one responsible.
If you get stuck at any point, open a support ticket with the Noiz support team and include the mailbox address, the rule's **Source**, condition, search term and **Action** exactly as saved, and an example message (sender, subject and approximate time) that the rule handled incorrectly.
# How to Create a Catchall Email Address in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-a-catchall-email-address-in-ispconfig/
This guide shows you how to create a catchall email address in the ISPConfig control panel on your Noiz hosting account. A catchall (also written catch-all, and sometimes called a wildcard address) collects every message sent to an address at your domain that does not exist as a mailbox, alias or forward, and delivers it into one mailbox you choose. It is a useful safety net for misspelt addresses, but it comes with a real spam trade-off, which this article explains before you switch it on.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig 3 documentation: Catch All Email](https://docs.ispconfig.org/my-first-email/catch-all-email/)
- [ISPConfig official documentation index](https://www.ispconfig.org/documentation/)
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- A mailbox already exists to receive the caught mail. If not, first [create an email mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/), for example `info@yourdomain.com`.
- Your email domain is already set up on the account and appears in the drop-down lists under the **Email** tab.
## How a Catchall Works
Normally, when someone sends a message to an address that does not exist on your domain, the mail server rejects it and the sender receives a bounce message along the lines of "no such user here". A catchall changes that behaviour: any message addressed to a non-existent address at the domain is delivered to the destination mailbox you nominate instead of bouncing.
- Existing mailboxes, aliases and forwards always take priority. The catchall only receives mail for addresses that are not defined anywhere else on the domain.
- Each domain can have **only one** catchall address. If you try to add a second, ISPConfig refuses with an error.
- Typical uses: catching mail sent to misspelt addresses such as `acounts@yourdomain.com`, or receiving mail for ad-hoc addresses you hand out without creating each one in advance.
## Create the Catchall Address
### Step 1: Open the Email Catchall list
1. Log in to the ISPConfig control panel.
2. Click the **Email** tab in the top navigation bar.
3. In the left-hand menu, under **Email Accounts**, click **Email Catchall**. The list of existing catchall entries for your account appears; on most accounts this list is empty.
### Step 2: Complete the Email Catchall form
1. Click the **Add new Catchall** button. The **Email Catchall** form opens.
2. In the **Source** drop-down, select the domain the catchall should apply to, for example `yourdomain.com`. Note the @ sign shown in front of the list: the rule matches every address at that domain that does not otherwise exist.
3. In the **Destination Email** field, type the full address of the mailbox that should receive the caught mail, for example `info@yourdomain.com`. Use an existing mailbox on your Noiz account, ideally on the same domain, so the mail stays on the server and is easy to manage.
4. Review the optional settings:
- **Send as**: cleared by default. When ticked, the destination mailbox is allowed to use addresses in the source domain as its sender address when it authenticates to the mail server over SMTP. Most catchalls do not need this, so leave it clear unless you have a specific reason to change it.
- **Enable greylisting**: an anti-spam measure that briefly delays the very first message from an unknown sender. Legitimate mail servers retry automatically, so genuine mail still arrives, just a little later the first time. On a catchall this option is well worth considering, because catchalls attract far more spam than ordinary addresses.
- **Active**: ticked by default. The catchall only works while this box is ticked. Unticking it later is a quick way to switch the catchall off without deleting it.
5. Click **Save**. The new entry appears in the Email Catchall list.
### Step 3: Test the catchall
1. Wait a minute or two: ISPConfig applies configuration changes to the mail server on a short cycle, so a brand-new catchall may not take effect instantly.
2. From an outside address, for example a personal webmail account, send a test message to an address on your domain that you know does not exist, such as `testing12345@yourdomain.com`.
3. Check the destination mailbox. The test message should arrive there instead of bouncing back to the sender.
## The Spam Caveat: Think Before You Rely on a Catchall
Spammers routinely send to guessed and dictionary-generated addresses such as `admin@`, `sales@`, `john@` and thousands of random variations. Without a catchall, all of that mail is rejected at the door. With a catchall, every one of those guesses becomes a deliverable address, so the destination mailbox can fill with junk quickly. Keep the following in mind:
- **Expect more spam.** The server-side spam filter still scores incoming mail, but a catchall widens the funnel considerably, and some junk will get through.
- **Watch the mailbox quota.** A catchall mailbox that nobody empties can hit its storage limit, and once it is full, legitimate mail to that mailbox starts bouncing too. Review and clear it regularly.
- **Prefer specific addresses where you can.** If you only need a handful of extra addresses, create them individually as aliases or forwards instead of catching everything. That keeps the "no such user" rejection working for everything else.
- **Use greylisting.** Ticking **Enable greylisting** on the catchall cuts a large share of low-effort spam at the cost of a short delay on first contact from new senders.
- **Switch it off if it becomes a burden.** Untick **Active** on the catchall entry and mail to non-existent addresses will bounce again, while your real mailboxes, aliases and forwards carry on unaffected.
## Troubleshooting
- **Error "There is already a Catchall record for this domain."**: each domain can have only one catchall. Open the existing entry in the **Email Catchall** list and edit its **Destination Email** instead of adding a second one.
- **Error "Destination is no valid email address."**: the **Destination Email** field needs a complete address including the @ sign and domain, for example `info@yourdomain.com`, not just a name like `info`.
- **Error "The max. number of email catchall accounts for your account is reached."**: your hosting plan's catchall limit is full. Delete an unused entry, or open a support ticket with the Noiz support team to discuss raising the limit.
- **There is no Email Catchall entry in the left-hand menu**: the catchall allowance on the hosting plan is set to zero. ISPConfig hides the menu entry completely in that case rather than showing it and refusing on save, so it is easy to mistake for a missing feature. Open a support ticket with the Noiz support team to have the allowance raised.
- **The test message bounced instead of being caught**: check that the **Active** box is ticked, allow a couple of minutes after saving before testing again, and confirm you selected the right domain in the **Source** drop-down.
- **The test message arrived somewhere else**: the address you tested probably already exists as a mailbox, alias or forward. Those always take priority over the catchall, so pick a clearly random address for testing.
- **First messages from new senders arrive late**: this is greylisting doing its job; the delay only affects the first message from an unknown sender. If it causes problems, untick **Enable greylisting** on the catchall entry.
- **The destination mailbox is drowning in spam**: see the caveat section above. Enable greylisting, empty the mailbox regularly, or deactivate the catchall and create specific aliases for the addresses you actually need.
If you get stuck at any point, open a support ticket with the Noiz support team and include the domain name, the destination email address you entered and, if a test message went missing or bounced, the exact address you sent it to and the complete bounce message text.
# How to Create a Cron Job in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-a-cron-job-in-ispconfig/
This guide shows you how to create a cron job in the ISPConfig control panel, so that a command or a web address on your hosting account runs automatically on a schedule you choose. It is written for Noiz clients managing their own hosting account through ISPConfig. A cron job is sometimes called a scheduled task, a crontab entry or simply a "cron"; typical uses include running a maintenance script every night, triggering a WordPress or shop-system background task, or fetching a page every few minutes. The guide also explains the schedule syntax, the difference between command crons and URL crons, and where the output of your cron job is logged.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below. ISPConfig evolves between releases, so if a screen differs from this guide, check those links.
### Official Documentation Reference
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual whose chapter 4.6.4.2 covers cron jobs.
- [ISPConfig 3.3.1p1 cron job form (official source repository)](https://git.ispconfig.org/ispconfig/ispconfig3/-/blob/3.3.1p1/interface/web/sites/templates/cron_edit.htm): the exact form definition this article was checked against, including the field hints and placeholder variables.
- [Cron Jobs and how to use them: an introduction (HowtoForge)](https://www.howtoforge.com/a-short-introduction-to-cron-jobs): the general cron scheduling tutorial that the official ISPConfig manual itself refers readers to.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- At least one active website exists on your account, because every cron job belongs to a website. If you have none yet, first [create a website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/).
- You know what you want to run: either the full path to a script on your hosting account, or a web address such as `https://yourdomain.com/cron.php` (an example placeholder; use your own domain).
- Your hosting plan includes cron jobs. The number of cron jobs, the allowed cron types and the minimum interval between runs are set per account, so if the **Cron Jobs** menu item is missing, your plan may not include them.
## Open the Cron Job Form
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, under **Command Line**, click **Cron Jobs**. A list of any existing cron jobs on your account appears.
4. Click the **Add new Cron job** button.
The **Cron Job** form opens. It contains the website selector, five schedule fields, the command field, and the **Log output** and **Active** options, all on a single tab.
## Choose the Parent Website
In the **Parent website** drop-down, select the website this cron job belongs to. This choice matters for two reasons:
- The job runs as that website's own system user, so it has exactly the same file permissions as the website itself. It can read and write the site's files but nothing belonging to other sites.
- Any log files the job produces are written into that website's `private` folder (explained below).
## Set the Schedule
The next five fields define when the job runs. Each field accepts `*`, a number, a list, a range or a step value, and ISPConfig shows a short example hint next to each one.
- **Minutes**: the minute of the hour to run the job. Allowed values `0` to `59`; `*` means every minute.
- **Hours**: the hour of the day. Allowed values `0` to `23`; `*` means every hour.
- **Days of month**: the calendar day. Allowed values `1` to `31`; `*` means every day of the month.
- **Months**: the month. Allowed values `1` to `12`; `*` means every month.
- **Days of week**: the weekday. Allowed values `0` to `7`, where both `0` and `7` mean Sunday; `*` means every day of the week.
### Schedule Syntax
Within each field you can combine values in the standard cron ways:
- `*` matches every possible value of the field.
- A list such as `1,2,5,9` matches each listed value.
- A range such as `0-4` matches every value from 0 to 4, and you can combine ranges with lists, for example `0-4,8-12`. The second number must be higher than the first, so `5-1` and `5-5` are both rejected.
- A step such as `*/5` means every fifth value, so `*/5` in **Minutes** runs the job every five minutes. Steps also work on ranges: `1-9/2` is the same as `1,3,5,7,9`. The step must be `2` or higher, so `*/1` is rejected; write `*` instead.
- Only digits and the characters `*`, `,`, `-` and `/` are accepted. General cron documentation allows three-letter names such as `jan` or `sun`, but ISPConfig refuses them with an "Invalid format" message, so always use numbers.
- Of the special `@` keywords found in general cron documentation, ISPConfig accepts only `@reboot`, and only in the **Months** field. Entered there it runs the job once each time the server starts. The other four fields still need a valid entry such as `*`, but they are ignored.
One rule often catches people out: if you restrict both **Days of month** and **Days of week** (that is, neither is `*`), the job runs when *either* field matches, not both. For example, minutes `30`, hours `4`, days of month `1,15`, days of week `5` runs at 04:30 on the 1st and 15th of every month *and* on every Friday.
### Common Schedule Examples
- Every 5 minutes: **Minutes** `*/5`, all other fields `*`.
- Every hour, on the hour: **Minutes** `0`, all other fields `*`.
- Every night at 02:30: **Minutes** `30`, **Hours** `2`, remaining fields `*`.
- Every Sunday at 06:00: **Minutes** `0`, **Hours** `6`, **Days of week** `0`, remaining fields `*`.
- First day of each month at midnight: **Minutes** `0`, **Hours** `0`, **Days of month** `1`, remaining fields `*`.
Note that your account may enforce a minimum interval between runs. If your plan's minimum is five minutes, for example, ISPConfig will refuse a schedule that fires every minute.
## Enter the Command or URL
The field labelled **Command to run (commands are executed via sh, urls via wget)** takes either a shell command or a web address. Which of the two you use changes how the job behaves, so pick deliberately. The field holds at most 255 characters, so put anything longer into a script and call the script instead.
### Command Crons
If you enter a shell command, it is executed by `sh` under your website's system user. Always use full absolute paths, because cron jobs do not start in your website folder and have only a minimal environment. A typical example that runs a PHP script inside your web space looks like this:
```
{SITE_PHP} {DOCROOT_CLIENT}/scripts/maintenance.php
```
The curly-bracket tokens are placeholders that ISPConfig fills in for you when the job runs. The **Variables** row just below the field lists the ones available; hovering over one shows the actual value for the selected website, and clicking it inserts the placeholder into the command:
- `{SITE_PHP}`: the PHP command-line binary matching the PHP version selected for the website, so your cron runs the same PHP version as the site itself.
- `{DOCROOT_CLIENT}`: the full path to the website's `web` folder, the same folder your site files live in.
- `{DOMAIN}`: the website's domain name.
Using the placeholders is strongly recommended over typing server paths by hand: they always resolve to the correct location for your account, and they keep working if the site is ever moved.
On some accounts, command crons run inside a restricted (Jailkit) environment for security, shown by a padlock icon beside the **Parent website** drop-down whose tooltip reads **Jailkit secured cronjob**. In that case only files inside your own site directory are reachable, and system-wide tools may not be available; scripts within your web space work as normal.
### URL Crons
If you enter a web address starting with `http://` or `https://`, ISPConfig does not run a shell command at all. Instead it fetches the address with `wget` at each scheduled time, which makes the web server execute the page exactly as if a visitor had opened it. For example:
```
https://yourdomain.com/cron.php
```
Points to know about URL crons:
- Only `http` and `https` addresses are accepted; anything else is rejected as an invalid command.
- Some accounts are limited to URL crons only. On those accounts the address must start with `https://`, and anything else is refused with **URL cron only. Please enter a URL starting with https:// as cron command.**
- The `{DOMAIN}` placeholder works here as well, so `https://{DOMAIN}/cron.php` keeps pointing at the right site. `{SITE_PHP}` and `{DOCROOT_CLIENT}` apply to command crons only.
- The address is fetched once per scheduled run, with a single attempt and a generous timeout of two hours, so long-running scripts are not cut off prematurely.
- The page must be reachable from the internet without logging in. If the script should not be run by strangers, protect it with a secret token in the address rather than a login page, for example `https://yourdomain.com/cron.php?key=example-secret`.
URL crons are the right choice for application background tasks (WordPress, shop systems, newsletter tools) that ship a "cron URL". Command crons are the right choice when you need to run a script directly with PHP or shell access to your files.
## Logging, Activation and Saving
1. Tick **Log output** if you want ISPConfig to record what the job produces. Logging is the easiest way to confirm a new job actually works, so enabling it on a new cron job is good practice.
2. Leave **Active** ticked so the job starts running. Unticking it keeps the job saved but switched off.
3. Click **Save**.
ISPConfig applies the change to the server automatically; allow a minute or so before the first run can happen. The job then runs on your schedule with no further action needed.
### Where the Logs Go
With **Log output** enabled, log files are written into the `private` folder of the parent website, alongside your `web` folder. You can view them with your FTP account for that site:
- `private/cron.log`: the normal output of your command.
- `private/cron_error.log`: error output, the first place to look when a job misbehaves.
- `private/cron_wget.log`: for URL crons, the content of the page that was fetched.
These files sit outside the `web` folder on purpose, so visitors to your website can never download them. Log files grow with every run, so check and clear them occasionally if your job runs frequently.
## Safety Notes
- Test the command first. Run the script by hand, or open the URL in a browser, before scheduling it. A cron job repeats whatever it does, including mistakes.
- Be conservative with frequency. A heavy script every minute can slow your whole site down. Schedule maintenance work during quiet hours, such as the early morning.
- Be careful with destructive commands. A cleanup script that deletes files runs unattended; double-check its paths so it can only ever touch what it should.
- Watch for overlap. If a run can take longer than the gap before the next run, the two can overlap. Lengthen the interval or make the script exit early if a previous run is still busy.
- Keep secrets out of logs. Anything your script prints ends up in `cron.log`; avoid printing passwords or API keys.
- Deactivate rather than delete. If you only need to pause a job, untick **Active** and save; the schedule and command stay intact for later.
## Troubleshooting
**Symptom: the Cron Jobs menu item is missing under Sites**: your hosting plan does not currently include cron jobs, or the limit is set to zero. Open a support ticket to have it enabled.
**Symptom: "The cron job frequency exceeds the allowed limit." when saving**: your schedule fires more often than your account's minimum interval allows. Lengthen the interval, for example from every minute to every five minutes.
**Symptom: "The maximum number of allowed cron jobs was reached."**: delete a cron job you no longer need, or ask the Noiz support team about raising the limit on your plan.
**Symptom: "Invalid command format. Please note that in case of an url call only http/https is allowed."**: the command starts like a URL but is not a plain `http://` or `https://` address, or your account is URL-cron only and the entry is not a valid `https://` address. Correct the address, or enter a proper shell command instead.
**Symptom: the job saves but never seems to run**: check that **Active** is ticked, wait a couple of minutes after saving for the server to pick up the change, then enable **Log output** and check `private/cron.log` and `private/cron_error.log` after the next scheduled time. For command crons, confirm every path in the command is absolute and correct.
**Symptom: the job runs but the log files are empty**: an empty `cron.log` usually just means the script produced no output, which is normal for many well-behaved scripts. Add a line to your script that prints a timestamp if you want positive confirmation of each run.
**Symptom: a URL cron runs but the task is not done**: open the URL in a private browser window. If it needs a login, redirects, or shows an error page, the scheduled fetch sees the same thing. Check `private/cron_wget.log` to see exactly what the fetch received, and adjust the script so it works without a logged-in session.
If you get stuck at any point, open a support ticket with the Noiz support team and include the domain of the parent website, the exact command or URL, the five schedule values, and the most recent lines of `private/cron.log` or `private/cron_error.log` if logging was enabled.
# How to Create a DNS Zone in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-a-dns-zone-in-ispconfig/
This guide shows you how to create a DNS zone in the ISPConfig control panel using the built-in DNS Wizard. A DNS zone is the container that holds all of the DNS records for a domain, so it is sometimes simply called the domain's DNS or its zone file. The wizard creates the zone and a sensible starter set of records in one step, so you do not need to understand every record type before you begin. This article is for Noiz clients whose hosting plan includes the **DNS** module in ISPConfig and whose domain uses, or is about to use, the Noiz nameservers.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**, the release Noiz runs. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig Documentation: DNS Basics](https://docs.ispconfig.org/dns-basics/) covers how DNS resolution works and how it applies to an ISPConfig server.
- [ISPConfig Documentation: Creating Web Sites](https://docs.ispconfig.org/creating-web-sites/) walks through the DNS Wizard as part of setting up a first site.
- [HowtoForge: Setting up your own name service with ISPConfig](https://www.howtoforge.com/tutorial/setting-up-your-own-name-service-with-ispconfig/) gives background on zones, records and creating zones manually.
- [ISPConfig documentation overview](https://www.ispconfig.org/documentation/) is the index of official ISPConfig documentation, including the user manual.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/) and your panel shows the **DNS** module in the top menu. If it does not, your plan may not include DNS management; contact Noiz support to confirm.
- A registered domain, for example `yourdomain.com`, whose nameservers point at the Noiz nameservers, or which you are about to point there through your domain registrar.
- The IP address your domain should resolve to. If you have already created the site, this is the address shown in the **IPv4-Address** field of the website; see [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/). It is also listed in your Noiz welcome email.
## When You Need to Create a DNS Zone
A DNS zone in ISPConfig only answers queries when your domain is delegated to the nameservers of your hosting account. You would typically create a zone when:
- You have added a new domain to your hosting and want the Noiz nameservers to answer DNS queries for it.
- You are moving a domain's DNS hosting to Noiz from your registrar or another provider, and need the zone in place before you change the nameservers.
- You want to manage records such as `MX`, `TXT` or `CNAME` in the ISPConfig panel; the zone must exist before individual records can be added to it.
If your domain's DNS is hosted elsewhere, for example at your registrar or a third-party DNS service, a zone created in ISPConfig has no effect until the domain's nameservers are changed to point at the hosting nameservers. Nameserver changes are made at your registrar, not inside ISPConfig.
## Create the Zone with the DNS Wizard
The official manual recommends the DNS Wizard over creating a zone manually, because the wizard builds the zone from a template and automatically creates the common records a domain needs, such as the `www`, mail and nameserver entries. You can adjust or extend the records afterwards.
### Step 1: Open the DNS Wizard
1. Log in to the ISPConfig control panel.
2. Click the **DNS** module in the top menu.
3. In the left-hand menu, under **DNS-Wizard**, click **Add DNS-Zone**. The page that opens is headed **DNS Zone Wizard**.
The zone list carries the same wizard on a button, so if you are already looking at your zones you can click **Add new DNS Zone with Wizard** there instead.
### Step 2: Complete the Wizard Form
Fill in the form as follows. Depending on how the zone template is set up for your account, some fields may already be filled in for you or may not appear at all. That is normal: hidden fields use preset values chosen by the template, typically the correct Noiz nameservers and contact address.
1. **Template**: leave this on `Default` unless Noiz has told you to pick a different template. The template decides which records the wizard creates.
2. **Client**: this field appears only for administrator and reseller accounts, and sets who owns the zone. On a client account the zone is assigned to you automatically.
3. **Server**: this only appears when more than one DNS server is available to the account. Where a single DNS server is assigned, as on a standard Noiz plan, the zone is placed on it without asking.
4. **Domain**: enter the domain the zone is for, for example `yourdomain.com`. A trailing dot is not required here; `yourdomain.com` is sufficient.
5. **IP Address**: enter the IPv4 address the domain should point to, for example `203.0.113.10` (an example address; use the one for your own account). The wizard will point `yourdomain.com`, `www.yourdomain.com` and `mail.yourdomain.com` at this address; you can change individual records later.
6. **NS 1**: the hostname of the primary nameserver, for example `ns1.yourhostdomain.com`. If this field is visible and empty, use the nameserver hostnames from your Noiz welcome email. No trailing dot is needed. The hostname you give here has to resolve to the server the zone is created on, which is why it is normally preset for you.
7. **NS 2**: the hostname of the secondary nameserver, for example `ns2.yourhostdomain.com`.
8. **Email**: the email address of the zone administrator, for example `admin@yourdomain.com`. Enter it as a normal email address; the wizard converts it to the format DNS requires.
9. **DKIM**: read only, and nothing to decide. The tick box is shown greyed out and already ticked. It does not generate a DKIM key. If an email domain for the same domain already exists on your account with DKIM switched on, the wizard copies that key's public half into a `TXT` record named after the DKIM selector, for example `default._domainkey.yourdomain.com`. If there is no such email domain, no DKIM record is added and the zone is created as normal.
10. **Sign zone (DNSSEC)**: leave this unticked unless you specifically intend to sign the zone. DNSSEC only works once signing data from the zone is also published at your domain registrar, so it is a separate task with its own steps.
11. Click **Create new DNS zone**. The panel returns you to the zone list.
## What the Wizard Creates for You
With the `Default` template, the wizard creates the zone together with this starter set of records for `yourdomain.com`:
- An `A` record for `yourdomain.com` pointing to the IP address you entered.
- An `A` record for `www.yourdomain.com` pointing to the same address.
- An `A` record for `mail.yourdomain.com` pointing to the same address.
- Two `NS` records naming the primary and secondary nameservers you entered as authoritative for the zone.
- An `MX` record for `yourdomain.com` pointing to `mail.yourdomain.com` at priority `10`, so mail for the domain is delivered to that host.
- A `TXT` record for `yourdomain.com` holding a starter SPF policy of `v=spf1 mx a ~all`, which permits the hosts named in the `MX` and `A` records to send mail for the domain.
The zone's timing values are taken from the template too, not from anything you type into the wizard. The stock ISPConfig Default template uses a record lifetime (TTL) of 3600 seconds, a refresh of 7200 and an expiry of 604800. These defaults suit most accounts and you do not normally need to change them. A template customised for your account may use different values and may create a different set of records, so treat the list above as the stock behaviour rather than a guarantee.
## Check and Adjust the New Zone
1. Still in the **DNS** module, click **Zones** under the **DNS** heading in the left-hand menu. Your new zone appears in the **DNS-Zones** list with **Active** showing **Yes**. A zone that is not active is highlighted in red in the list instead.
2. Click the zone to open it. It opens on the **Records** tab, showing the records the wizard created. Here you can edit or delete existing records, and add further ones using the buttons for each record type, such as **A**, **CNAME**, **MX** and **TXT**.
3. The **Zone settings** tab holds the zone-wide SOA values built from the template: the primary nameserver, the zone administrator address, the serial number, and the refresh, retry, expire, minimum and TTL timers.
Note that on the **Records** tab, fully qualified names must end with a trailing dot, for example `yourdomain.com.`, while plain host names such as `www` must not. The wizard handled this for you, but keep it in mind when adding records of your own.
Changes to a zone are written out to the nameserver by a background process rather than the moment you click save. While a change is still queued, an information panel appears above the list reading **The following changes are not yet populated to all servers**, followed by the pending item, for example **Create DNS zone**. The panel warns that storing updates can take up to a minute, and it clears once the change is live on the server.
## Troubleshooting
- **The NS 1, NS 2 or Email fields are missing from the wizard**: the zone template for your account presets these values, so the wizard hides the fields. This is expected and the correct values are used automatically.
- **The zone exists but the domain does not resolve**: check at your registrar that the domain's nameservers point at the Noiz nameservers. After a nameserver change, allow up to 24 to 48 hours for the change to propagate worldwide.
- **The wizard will not create the zone and reports an error**: a zone name can exist only once on the server, so the wizard refuses rather than creating a duplicate. Open **DNS** > **DNS** > **Zones** and edit the existing zone instead. If you cannot see it, it may belong to another account; contact Noiz support.
- **You entered the wrong IP address**: open the zone under **DNS** > **DNS** > **Zones** and edit each `A` record on the **Records** tab to correct the address. Remember that `yourdomain.com`, `www` and `mail` each have their own record.
- **The max. number of DNS zones for your account is reached**: each hosting plan allows a set number of DNS zones, and the wizard shows this message instead of the form once you hit it. Delete an unused zone or ask Noiz support about increasing the allowance.
If you get stuck at any point, open a support ticket with the Noiz support team and include the domain name, the IP address you entered in the wizard, and a screenshot of any error message the panel shows.
# How to Create a Database and Database User in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-a-database-and-database-user-in-ispconfig/
This guide shows you how to create a MySQL database and a database user in the ISPConfig control panel, link the two together, and then use the details in your website code or open the database in phpMyAdmin. It is written for Noiz clients managing their own hosting account through ISPConfig. Note that a database user is not the same as your ISPConfig login: it is a separate username and password that your website software uses to read and write data. ISPConfig keeps databases and database users in two separate forms so that one database user can be reused across several databases, which means you create the user first and then attach it when you create the database.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [How to Add a Website, MySQL Database and Users in ISPConfig (HowtoForge)](https://www.howtoforge.com/ispconfig-website/): a current step-by-step guide covering the Database Users and Databases forms, maintained by the ISPConfig developers' documentation site.
- [ISPConfig 3 Documentation](https://docs.ispconfig.org/): the official online documentation for the current ISPConfig interface.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- A website already exists on your account, because every database is assigned to a site. If you have not created one yet, follow [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/) first.
- A hosting plan that includes databases. If your plan carries no database allowance at all, the **Databases** section does not appear in the Sites menu.
## Step 1: Create the Database User
The database user must exist before you create the database, otherwise it will not appear in the drop-down list on the database form.
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, under **Databases**, click **Database Users**. A list of any existing database users on your account appears.
4. Click the **Add new user** button.
Fill in the form as follows, then click **Save**:
- **Client**: this field sits at the top of the form but appears only on administrator and reseller logins. If you see it, leave it at the preset value for your account.
- **Database user**: enter a short name for the user, using only letters and numbers, for example `wpuser`. Avoid underscores. ISPConfig automatically adds an account prefix in front of whatever you type; the greyed-out text next to the field shows the prefix, for example `c1`. So if you type `wpuser`, the real username becomes `c1wpuser`, and that full name is what you will later use in your website configuration. The finished username cannot exceed 32 characters once the prefix is counted, so keep the part you type short.
- **Database password**: type a strong password, or click the **Generate Password** button beside the field to have ISPConfig create one for you. The **Password strength** indicator shows how strong your choice is. Record the password somewhere safe now; ISPConfig does not display it again later.
- **Repeat Password**: enter the same password again. A confirmation line appears below the field once the two entries match.
The user now appears in the Database Users list. At this point it exists only inside ISPConfig; it becomes a working MySQL login once you attach it to a database in the next step.
## Step 2: Create the Database and Link the User
1. Still in the **Sites** module, in the left menu under **Databases**, click **Databases**.
2. Click the **Add new Database** button. The database form opens on the **Database** tab.
Complete the fields described below, then click **Save**. On a shared hosting account you may not see every field mentioned here: options such as the **Server** selection are usually preset by Noiz, and anything you do not see has already been configured for you.
### Site
In the **Site** field, select the website this database belongs to, for example `yourdomain.com`. The drop-down opens on **- Select Site -** and the form refuses to save until a real site is chosen. This is what ties the database to a website for ownership and quota accounting.
### Type
Leave the **Type** field set to **MySQL**. This is the standard database type used by software such as WordPress and Joomla.
### Backup interval
The **Backup interval** drop-down decides whether ISPConfig takes its own scheduled dump of this database, and how often. The choices are **No backup**, **Daily**, **Weekly** and **Monthly**, and a new database starts on **No backup**. The setting belongs to the database record itself, so choose an interval here if you want the panel to hold a restorable copy of the data.
### Database name
Enter a short, descriptive name using only letters and numbers, for example `wordpress`. As with the database user, ISPConfig adds your account prefix automatically, so typing `wordpress` with a prefix of `c1` produces the real database name `c1wordpress`. The field accepts letters, numbers and the underscore, and the finished name must be between 2 and 64 characters once the prefix is counted. Choose it carefully: on a client login the database name cannot be edited after the database has been created. The full prefixed name is what your website configuration must use.
### Database quota
**Database quota** is the largest size in megabytes this database is allowed to reach, and `-1` means unlimited. MySQL has no true hard quota, so the figure is enforced by monitoring rather than by refusing writes: passing it raises an over-quota notification instead of an immediate failure. The total across all your databases is capped by the allowance on your plan, and asking for more than the plan has left makes the form report the remaining figure and clamp your entry to it. Leave the value as it arrives unless you deliberately want to cap one database.
### Database user
In the **Database user** drop-down, select the user you created in Step 1, for example `c1wpuser`. This grants the user full access to the database. The optional **Read-only database user** drop-down lets you attach a second user that can only read data, which most sites do not need; leave it on **None** unless you have a specific reason.
### Database charset
The **Database charset (MySQL)** drop-down offers **DB-Default**, **Latin 1**, **UTF-8** and **UTF8MB4**. **DB-Default** hands the decision to the database server's own default and suits almost every install. Pick **UTF8MB4** only when the software you are installing asks for it by name, which it will if it needs to store emoji and other four-byte characters. Decide before you save, because ISPConfig does not allow the charset to be changed once the database exists; switching later means creating a second database and importing the data into it.
### Remote Access
Leave the **Remote Access** checkbox unticked. Your website runs on the same server as the database and connects locally, so remote access is not needed and leaving it off is safer. If you ever need to connect from an external tool, tick the box and enter the connecting machine's IP address in the **Remote Access IPs** field. The field label spells out the rule: separate several addresses with commas, and a blank field allows connections from any host, which is the one outcome to avoid.
### Active
Leave the **Active** checkbox ticked so the database is enabled as soon as it is created.
## Save and Use the Database in Your Website
1. Click **Save**. You return to the database list, where the new database now appears.
2. Watch for the small red change indicator near the top of the panel. It shows that ISPConfig is still creating the database and user on the server in the background. This normally takes under a minute; the database is ready once the indicator disappears.
Your website software connects with four pieces of information. Using the examples above, they would be:
- Database host: `localhost`
- Database name: `c1wordpress` (the full prefixed name)
- Database username: `c1wpuser` (the full prefixed name)
- Database password: the password you set in Step 1
For example, in a WordPress `wp-config.php` file the same details look like this (replace the example values with your own):
```
define( 'DB_NAME', 'c1wordpress' );
define( 'DB_USER', 'c1wpuser' );
define( 'DB_PASSWORD', 'your-database-password' );
define( 'DB_HOST', 'localhost' );
```
## Open the Database in phpMyAdmin
phpMyAdmin is a browser-based tool for working with a database directly: browsing tables, running queries, and importing or exporting `.sql` backup files.
1. In the **Sites** module, under **Databases**, click **Databases** to open the database list.
2. In the row for your database, click the **phpMyAdmin** icon. A new browser tab opens with the phpMyAdmin login page.
3. Log in with the full database username, for example `c1wpuser`, and the database password. Your ISPConfig panel login will not work here; phpMyAdmin only accepts database users.
Once logged in you will see only the databases your user is linked to. Select your database in the left column to browse its tables.
## Troubleshooting
- **The Database user drop-down offers nothing but "Select database user"**: the database user has not been created yet, and the form will not save without one. Cancel the database form, create the user under **Database Users** as described in Step 1, then reopen the database form.
- **phpMyAdmin rejects the username and password**: make sure you are using the full prefixed username, for example `c1wpuser` rather than `wpuser`, together with the database password rather than your panel password. Also confirm the user is linked to at least one database and that the red change indicator has cleared; a user that is not attached to any database cannot log in.
- **The website shows a database connection error**: check all four connection values character by character. The host should be `localhost`, and both the database name and username must include the account prefix. If the details are correct, edit the database in ISPConfig and confirm the **Active** checkbox is ticked.
- **ISPConfig reports that the maximum number of databases is reached**: the **Add new Database** and **Add new user** buttons stay on screen when your allowance is used up, so the limit shows itself as an error the moment you click one. Delete a database or user you no longer need, or open a support ticket to have the allowance raised. If the **Databases** section is missing from the Sites menu altogether, your plan carries no database allowance at all.
- **An external database tool cannot connect**: remote connections are blocked unless **Remote Access** is enabled on the database and the connecting machine's IP address is listed in **Remote Access IPs**. For occasional tasks, phpMyAdmin is usually the simpler option.
If you get stuck at any point, open a support ticket with the Noiz support team and include the database name, the database username, the website it belongs to, and the exact error message or symptom. Never include the database password in a ticket.
# How to Create a Shell User in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-a-shell-user-in-ispconfig/
This guide shows you how to create a shell user in the ISPConfig control panel so you can access a website's files over SSH. It is written for Noiz clients managing their own hosting account through ISPConfig. A shell user is sometimes called an SSH user or SSH account: it lets you log in to a command line on the server with an SSH client such as OpenSSH or PuTTY, and transfer files securely with an SFTP or SCP client such as WinSCP or FileZilla. You will also learn what the chroot option does and how to use an SSH key instead of a password.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [How to Add a Website in ISPConfig (HowtoForge)](https://www.howtoforge.com/ispconfig-website/): the current field-by-field guide to the Sites module, including the shell user form, maintained by the ISPConfig developers' documentation site.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual.
- [How To Create and Install SSH Keys on the Shell (HowtoForge)](https://www.howtoforge.com/linux-basics-how-to-install-ssh-keys-on-the-shell): generating an SSH key pair on Linux or macOS.
- [Key-Based SSH Logins With PuTTY (HowtoForge)](https://www.howtoforge.com/ssh_key_based_logins_putty): the tutorial the official manual recommends for generating and using SSH keys on Windows.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- An existing website on your account. A shell user always belongs to one website; if you have not created one yet, see [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/).
- A hosting plan that includes shell access. If the **Command Line** section or its **Shell-User** item is missing from the left menu, your plan's shell user allowance is zero and ISPConfig hides the section entirely.
- An SSH client on your computer. Linux, macOS and current versions of Windows include the `ssh` command in the terminal; on Windows you can also use PuTTY.
## Open the Shell User Form
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, under **Command Line**, click **Shell-User**. A list of any existing shell users on your account appears.
4. Click the **Add new Shell-User** button.
The shell user form opens on the **Shell User** tab. The same form has a second tab, **Options**, carrying the **Web Username**, **Web Group**, **Shell** and **Base Dir** settings, but ISPConfig shows that tab to administrators only. On a client login everything you need is on the **Shell User** tab, and those underlying values are derived from the website you choose.
## Complete the Shell User Tab
Fill in the fields described below, then click **Save**. There is no server to pick on this form: ISPConfig creates the shell user on whichever server hosts the website you select in **Site**.
### Site
In the **Site** drop-down, choose the website this shell user belongs to. The user's home directory is placed inside that website's directory tree, so the account can work with that site's files.
### Username
In the **Username** field, enter the login name you want, for example `deploy`. ISPConfig shows a prefix next to the field and adds it to whatever you type, so the actual login name is the prefix plus your entry. For example, if the prefix shown is `client1` and you type `deploy`, you will log in as `client1deploy`. Use the copy button beside the field to put the full name on your clipboard; you need it every time you connect. Only letters, numbers, full stops, hyphens and underscores are accepted, the name must be unique on the server, and the finished name including the prefix must not exceed 32 characters. A short list of system account names is reserved and will be refused.
### Password
Type a password in the **Password** field and confirm it in **Repeat Password**, or click **Generate Password** to have ISPConfig create a strong one for you. The **Password strength** indicator rates your choice; use at least 8 characters, longer where you can, with a mix of upper and lower case letters, numbers and symbols, and avoid dictionary words, repeated or sequential characters, and anything drawn from names or personal details. This password protects command line access to your website's files, so treat it like an administrator credential. If you plan to log in only with an SSH key, still set a strong password here; you simply will not need to type it.
### Chroot Shell
The **Chroot Shell** drop-down controls how much of the server's file system the shell user can see:
- **Jailkit**: the user is locked (chrooted, also called jailed) into the website's own directory tree, with a home directory of their own inside it. They cannot browse anything above that boundary, and can only run a limited, safe set of commands installed inside the jail. This is the recommended setting and is usually the standard on shared hosting.
- **None**: the user can browse the whole server file system, limited only by ordinary file permissions. The official manual flags this as a security risk, and on shared hosting it is normally not offered.
The choices shown depend on what your account allows; you may see only **Jailkit**. Select **Jailkit** unless Noiz has advised otherwise for a specific reason. The first time a jailed user is created for a website, the server builds the jail environment in the background, which can take a little longer than later changes.
### Quota
The **Quota** field sets the maximum disk space, in megabytes, available to this shell user. A value of `-1` means unlimited, which on a shared hosting account effectively means "up to my plan limit". Because the shell user works inside the website's directory, most people leave this at `-1` and let the website's own quota apply.
### SSH-RSA Public Key (for key-based logins)
The **SSH-RSA Public Key (for key-based logins)** field is optional. If you paste a public SSH key here, you can log in without typing a password: your SSH client proves your identity with the matching private key, which stays on your computer. Key-based logins are both more convenient and more secure than passwords, so they are worth setting up if you connect regularly. How to generate a key is covered in the next section.
Paste each public key on its own line, exactly as produced by your key generator: a single long line starting with the key type, for example `ssh-rsa AAAA...`. Despite the field's RSA label, the keys are installed as standard authorised keys on the server, so current OpenSSH key types are accepted; an RSA key is the safe choice if you are unsure. Never paste a private key into this field. Leave the field empty if you only want password logins.
### Active
Leave the **Active** checkbox ticked so the account works as soon as it is created. Unticking it later disables SSH access for this user without deleting the account.
### Save
1. Click **Save**. You return to the shell user list, where the new user now appears.
2. Watch for the small red change indicator near the top of the panel. It shows that ISPConfig is still creating the system account, and the jail if you chose **Jailkit**, in the background. Wait until it disappears before trying to log in; this normally takes under a minute.
## Set Up Key-Based Logins (Optional)
To use the **SSH-RSA Public Key** field, you first need a key pair on your computer. On Linux, macOS or Windows (PowerShell or Command Prompt on current versions), open a terminal and run:
```
ssh-keygen -t rsa -b 4096
```
Accept the default file location, and optionally set a passphrase to protect the key file itself. This creates two files: a private key (`id_rsa`), which must never leave your computer, and a public key (`id_rsa.pub`). Display the public key with:
```
cat ~/.ssh/id_rsa.pub
```
Copy the whole output line, paste it into the **SSH-RSA Public Key (for key-based logins)** field of the shell user, and click **Save**. On Windows with PuTTY, generate the key pair with PuTTYgen instead and copy the public key text it displays; see the PuTTY tutorial in the documentation links above. Once the change indicator clears, your SSH client will log in without asking for the account password.
## Connect via SSH
Once the change indicator has cleared, connect from your computer's terminal. Replace the example username and domain with your own details:
```
ssh client1deploy@yourdomain.com
```
Here `client1deploy` is an example of the full prefixed username and `yourdomain.com` is an example domain that points at your Noiz hosting server. The standard SSH port `22` is used unless Noiz has told you otherwise. The first time you connect, your SSH client asks you to confirm the server's fingerprint; type `yes` to continue, then enter the shell user's password if you are not using a key.
After logging in, a jailed user lands in their own home directory inside the website's jail and can move around the site's files. The jail's root is the website's base directory, so the site content sits at `/web` from the jailed user's point of view. Only a limited set of commands is available inside the jail; this is by design. The same username and password (or key) also work for secure file transfers with an SFTP client such as WinSCP or FileZilla using the SFTP protocol on port `22`.
## Troubleshooting
- **Permission denied when logging in**: check that you are using the full username including the prefix, for example `client1deploy` rather than `deploy`. Also confirm the **Active** box is ticked and that the red change indicator had cleared before you tried. Repeated failed attempts can temporarily block your internet address as a security measure, so pause a few minutes before retrying with the correct details.
- **Key-based login still asks for a password**: the public key was probably pasted incorrectly. Edit the shell user and check the field contains the complete key as one single line, starting with the key type such as `ssh-rsa`, with no line breaks inside it, and that it is the public key, not the private one. Save and wait for the change indicator to clear.
- **Connection times out or is refused**: check you are connecting to a domain that points at your Noiz hosting server, on port `22`. Some office and public networks block outgoing SSH; try another connection if you suspect this.
- **A command I need is missing inside the jail**: jailed shells only include a limited command set. Open a support ticket stating which command you need and the Noiz support team will advise whether it can be made available.
- **I cannot see files outside my home directory**: this is the chroot jail working as intended. A jailed shell user can only ever see their own website's directory tree.
- **The Shell-User menu item is missing**: ISPConfig hides the whole **Command Line** section when the shell user allowance on your plan is zero, so shell access is not included. If the menu is there but opening the form reports that the maximum number of shell users is reached, you have used the allowance you do have. Open a support ticket either way to check it.
If you get stuck at any point, open a support ticket with the Noiz support team and include the shell username you created, the website it belongs to, and the exact error message your SSH client shows when you try to connect.
# How to Create a Subdomain in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-a-subdomain-in-ispconfig/
This guide shows you how to create a subdomain, such as `blog.yourdomain.com`, for an existing website in the ISPConfig control panel. It is written for Noiz clients managing their own hosting account through ISPConfig. ISPConfig offers two kinds of subdomain: a standard subdomain, which shares the parent website's content or redirects visitors elsewhere, and a vhost subdomain (shown in the panel as **Subdomain (Vhost)**, and sometimes called a vhostsubdomain), which behaves like a small website of its own with its own folder and settings. This article explains the difference and walks you through creating both.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig, including the field names and limits that changed after the widely circulated 3.1 manual was written. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [Subdomains (ISPConfig 3 Documentation)](https://docs.ispconfig.org/creating-web-sites/subdomains/): the current official documentation on the different ways to create a subdomain.
- [Subdomains in the Sites module (ISPConfig 3 Documentation)](https://docs.ispconfig.org/modules/sites/subdomains/): the same topic within the official Sites module documentation.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- An existing website in ISPConfig to attach the subdomain to. If you have not created one yet, follow [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/) first.
- A hosting plan with an unused subdomain allowance. The **Subdomain** menu item is hidden entirely when your plan allows no subdomains, and once you have used your allowance up, saving a new one fails with *The max. number of web subdomains for your account is reached.*
- A DNS record for the subdomain, for example an A or CNAME record for `blog.yourdomain.com`, pointing at your Noiz hosting server. You can create the subdomain in ISPConfig first and sort out DNS afterwards, but the subdomain only works in a browser once DNS is in place.
## Choose the Right Type of Subdomain
Before you open any forms, decide what the subdomain should do. ISPConfig 3.3 gives you up to three options:
- **Standard subdomain** (the **Subdomain** menu item): the subdomain is attached to the parent website and, by default, shows exactly the same content as the main domain. You can optionally redirect it to a folder of the site or to another URL. Its whole form is a handful of fields, so it has no web space, PHP settings or SSL configuration of its own. Choose this when the subdomain is simply another name for the existing site, or a signpost pointing somewhere else.
- **Vhost subdomain** (the **Subdomain (Vhost)** menu item): the subdomain gets its own document root inside the parent website's folder, plus its own PHP, SSL and other settings, without any redirect rules. Choose this when you want to run separate content or a separate application, for example a WordPress blog at `blog.yourdomain.com`, alongside the main site. This menu item only appears if the feature is enabled on your server; if you do not see it, use the next option instead.
- **A full website on a subdomain**: when creating a website, you can enter a subdomain such as `shop.yourdomain.com` straight into the **Domain** field. ISPConfig then creates a completely independent website with its own web space, counted against your website allowance rather than your subdomain allowance. See [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/).
One caution from the official manual: do not use a standard subdomain redirected to a subdirectory if you plan to install a content management system such as WordPress, Joomla or Drupal in that subdirectory. The redirect is built from rewrite rules, and these usually collide with the CMS's own rewrite rules. For a CMS, use a vhost subdomain or a full website instead. A standard subdomain redirect to a subdirectory is fine for static HTML files.
A related feature you may notice in the same menu is the aliasdomain. The difference is simple: a subdomain uses the same domain name as the parent website, for example `blog.yourdomain.com` under `yourdomain.com`, while an aliasdomain points a completely different domain name at the same site.
## Create a Standard Subdomain
### Open the Subdomain Form
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, under **Websites**, click **Subdomain**. A list of any existing subdomains on your account appears.
4. Click the **Add new Subdomain** button.
### Complete the Form
Fill in the fields described below, then click **Save**.
- **Host**: enter only the subdomain part, without the main domain. For `blog.yourdomain.com`, enter `blog`. A wildcard is rejected here with *Wildcard subdomains are not allowed*; wildcard cover is set on the parent website's **Auto-Subdomain** field instead, not on an individual subdomain.
- **Domain**: select the parent website from the drop-down, for example `yourdomain.com`. The list shows the websites already configured on your account, each entry giving the domain name followed by the server it runs on.
- **Redirect Type**: leave this set to **No redirect** if the subdomain should show the same content as the parent website. To redirect instead, choose one of the options; on an Apache server the current interface labels them **No flag**, **R (Temporary redirect)**, **L (Last redirect rule)**, **R,L (Temporary redirect + last rule)** and **R=301,L (Permanent redirect + last rule)**. Following the official manual's guidance: for a redirect to another URL choose **R,L**, or **R=301,L** if the move is permanent, and for a redirect to a subdirectory of the site choose **L**. On a server running nginx the Apache flags are hidden and the list offers **last**, **break**, **redirect**, **permanent** and **proxy** instead; the manual's advice there is to use **permanent** for a URL redirect. **proxy** is the odd one out: it fetches the target's content and serves it under the subdomain's own address rather than sending the visitor away, it accepts only a full URL in **Redirect Path**, and selecting it adds an extra **Options** tab to the form holding a **Proxy Directives** field.
- **Redirect Path**: the redirect target. For a URL redirect enter the full address ending in a slash, for example `https://www.anotherdomain.com/`. For a subdirectory redirect enter the path relative to the website's document root, beginning and ending with a slash, for example `/blog/`. Leave the field empty when **Redirect Type** is **No redirect**. Anything else is refused with *Invalid redirect path. Valid redirects are for example: /test/ or https://www.domain.tld/test/*.
- **Don't add to Let's Encrypt certificate**: if the parent website uses a Let's Encrypt SSL certificate, ISPConfig automatically includes the new subdomain in that certificate. Tick this box only if the subdomain's DNS does not point at the hosting server, otherwise the failed inclusion can hold up certificate renewal. If you do not see this checkbox, it simply is not applicable to your site.
- **Active**: leave this ticked so the subdomain is enabled as soon as it is created.
### Save and Wait for the Configuration Update
1. Click **Save**. You return to the subdomain list, where the new entry appears.
2. Watch for the small red change indicator near the top of the panel. It carries a count of the changes still queued and clicking it lists them. ISPConfig's server process collects that queue once a minute, so the web server configuration is normally written within a minute of saving.
## Create a Subdomain (Vhost)
The **Subdomain (Vhost)** menu item only appears in the **Sites** module when the server administrator has enabled vhost subdomains. If you do not see it on your account and you need a subdomain with its own content, create the subdomain as a full website instead, or open a support ticket.
1. Click the **Sites** module in the top navigation.
2. In the left menu, under **Websites**, click **Subdomain (Vhost)**.
3. Click the **Add new subdomain** button.
The form that opens looks very similar to the website form, because a vhost subdomain really is a small website of its own. Three fields are specific to it:
- **Hostname**: enter only the subdomain part, without the main domain. For `blog.yourdomain.com`, enter `blog`.
- **Domain**: select the parent website from the drop-down, for example `yourdomain.com`.
- **Web folder**: enter the folder, relative to the parent website's web space, that will hold this subdomain's files. For example, `blog` creates a separate `blog` folder alongside the parent site's files, while `web/blog` uses a subdirectory inside the parent site's public `web` directory. To share the parent website's own document root, enter `web`. The field must not be empty, and in ISPConfig 3.3.1p1 the value must not start with a slash at all: enter `web`, not `/web` or `/web/`. Older ISPConfig documentation, and the panel's own prompt when you leave the field blank, still suggest the `/web/` form; if a value is refused with *Invalid folder entered. Please do not enter a slash.*, drop the leading slash and save again.
The remaining fields, such as **Traffic Quota**, **PHP**, **SSL**, **Let's Encrypt SSL**, **Auto-Subdomain** and **Active**, work exactly as they do for a website; see [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/) for what each one means. Two things the website form has are deliberately absent here, because the parent website owns them: there is no **Harddisk Quota** field, since the subdomain's files sit inside the parent's web space and count against the parent's disk allowance, and there is no **Backup** tab, since the subdomain is covered by the parent website's backup settings. The **Server**, **Client**, **IPv4-Address** and **IPv6-Address** fields are absent for the same reason. Because a vhost subdomain does have its own SSL configuration, you can tick **SSL** and **Let's Encrypt SSL** to give it its own free HTTPS certificate once its DNS record points at the server. Scripts such as PHP run under the parent website's user, so there are no file permission problems between the parent site and the subdomain.
Click **Save**, then wait for the red change indicator to clear as before. Upload the subdomain's files to the folder you specified in **Web folder**, using the parent website's FTP access.
## Point DNS at the Subdomain and Verify
1. Make sure the subdomain has a DNS record. A CNAME record pointing the subdomain at the main domain, for example `blog.yourdomain.com` to `yourdomain.com`, is the simplest option; an A record holding the server's IP address works equally well. The ISPConfig manual is firm on this point: every name attached to a website, including its auto-subdomain and any alias or subdomain, has to be reachable from outside before the site behaves as configured. If Noiz hosts your DNS and you are unsure, open a support ticket and the record can be checked for you.
2. Allow time for the DNS change to spread; this can take up to 24 hours worldwide, though it is usually much faster.
3. Open `http://blog.yourdomain.com` in a browser. A standard subdomain with **No redirect** shows the parent website's content; a redirecting subdomain sends you to the target you configured; a vhost subdomain shows whatever you uploaded to its **Web folder**.
## Troubleshooting
- **The subdomain shows exactly the same pages as the main site**: for a standard subdomain with **Redirect Type** set to **No redirect**, this is the designed behaviour, not a fault. If you wanted separate content, create the subdomain as a **Subdomain (Vhost)** or as a full website instead.
- **Saving fails with "There is already a website or sub / aliasdomain with this domain name"**: the same subdomain already exists somewhere on the system, possibly as a website, an aliasdomain or an auto-subdomain. Check your website list and subdomain list first; if you cannot find it, contact support.
- **The subdomain does not load in a browser**: wait for the red change indicator in the panel to clear, then check DNS. The subdomain needs its own A or CNAME record; a record for `yourdomain.com` alone does not cover `blog.yourdomain.com` unless a wildcard record exists.
- **The browser shows a certificate warning on the subdomain**: the subdomain is not yet covered by a valid SSL certificate. For a standard subdomain, make sure its DNS points at the server and that **Don't add to Let's Encrypt certificate** is not ticked, then edit and re-save the parent website so the certificate is reissued. For a vhost subdomain, tick **SSL** and **Let's Encrypt SSL** on the subdomain itself once DNS resolves.
- **A CMS installed in a redirected subdirectory shows broken links or endless redirects**: the subdomain's rewrite rules are colliding with the CMS's own rules. Remove the directory redirect and recreate the subdomain as a **Subdomain (Vhost)** or a full website, as the official manual recommends.
- **The Subdomain (Vhost) menu item is missing**: vhost subdomains are not enabled on your server, or your plan does not include them. Create the subdomain as a full website instead, or open a support ticket.
If you get stuck at any point, open a support ticket with the Noiz support team and include the full subdomain name, the parent website it belongs to, which type of subdomain you are creating, and the exact error message or symptom you are seeing.
# How to Create a Website in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-a-website-in-ispconfig/
This guide shows you how to create a new website in the ISPConfig control panel, from opening the website form to checking that the site responds in a browser. It is written for Noiz clients managing their own hosting account through ISPConfig. In ISPConfig a website is sometimes called a web domain or a vhost, and the form you fill in is labelled **Web Domain**. Along the way, each of the main fields is explained so you know what it means for a shared hosting account.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [Creating Web Sites (ISPConfig 3 Documentation)](https://docs.ispconfig.org/creating-web-sites/): the current official documentation section on adding websites.
- [The basics of setting up your first site (ISPConfig 3 Documentation)](https://docs.ispconfig.org/modules/sites/the-basics-of-setting-up-your-first-site/): the official walkthrough of the Sites module for a first website.
- [How to Add a Website in ISPConfig (HowtoForge)](https://www.howtoforge.com/ispconfig-website/): a detailed field-by-field guide to the same form, maintained by the ISPConfig developers' documentation site.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- A registered domain name, for example `yourdomain.com`. The domain's DNS records must point to your Noiz hosting server before visitors can reach the site, but you can create the website in ISPConfig first and sort out DNS afterwards.
- A hosting plan with at least one unused website allowance. The **Add new website** button is always shown, so the limit only becomes visible when you click it: if your allowance is used up, ISPConfig answers with `The max. number of web domains for your account is reached.` instead of opening the form.
## Open the Website Form
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, under **Websites**, click **Website**. A list of any existing websites on your account appears.
4. Click the **Add new website** button.
The **Web Domain** form opens on the **Domain** tab. The full set of tabs is **Domain**, **Redirect**, **SSL**, **Statistics**, **Backup** and **Options**, but for a standard website you only need the **Domain** tab: the rest hold special configurations you can leave at their defaults. Not all of them appear on every account. The **SSL** and **Backup** tabs are shown only if your plan includes those features, and the **Options** tab is reserved for administrator and reseller logins, so a normal hosting login will not see it at all.
## Complete the Domain Tab
The fields below are described in the order they appear on the form. Fill them in, then click **Save**. On a shared hosting account you may not see every field mentioned here: ISPConfig only shows options your plan includes, and fields such as the server or IP address selection are usually preset by Noiz. Anything you do not see has already been configured correctly for you.
One thing to know before you start: a website you create yourself stays yours to edit afterwards. If a website was created on your account by Noiz support instead, ISPConfig locks the **Domain** tab of that site to read-only for your login, and changes to it have to go through a support ticket.
### Domain
In the **Domain** field, enter the main domain of the website without any subdomain prefix, for example `yourdomain.com` rather than `www.yourdomain.com`. The `www` version is handled separately by the **Auto-Subdomain** field below. If you want the site to live on a subdomain instead, you can enter one here, for example `shop.yourdomain.com`, and ISPConfig creates it as a full website with its own web space.
### Harddisk Quota and Traffic Quota
- **Harddisk Quota** is the maximum amount of web space, in megabytes, this website may use for its files. A value of `-1` means unlimited.
- **Traffic Quota** is the maximum amount of traffic, in megabytes per month, the website may serve. Again, `-1` means unlimited.
On a shared hosting account these values are capped by your overall plan allowance, so `-1` effectively means "up to my plan limit". If you ask for more than the account has left, ISPConfig refuses the save and tells you how much is still available under **Max. available Harddisk Quota** or **Max. available Traffic Quota**. If your plan allows several websites, you can use these fields to stop one site consuming space or traffic needed by another. Otherwise, leave the defaults in place.
### Other checkboxes you may see
Depending on your plan, the next block of the **Domain** tab may show **CGI**, **SSI**, **SuEXEC** and **Own Error-Documents**. **CGI** lets the web server execute CGI scripts from the site's `cgi-bin` directory, and **SSI** activates Server Side Includes for `.shtml` files: leave both unticked unless your site genuinely uses them. **SuEXEC** runs CGI scripts, including PHP running as Fast-CGI or CGI, as the website's own user and group, and should stay ticked for security. On most servers suEXEC is enforced for every site, in which case the checkbox is not shown at all. **Own Error-Documents** lets you supply your own error pages, for example a custom 404 page, instead of the server's standard ones, and is safe to leave ticked.
### Auto-Subdomain
The **Auto-Subdomain** field decides which subdomain, if any, is created automatically alongside the main domain:
- **None**: the site answers only on the exact domain, for example `yourdomain.com`. Visitors typing `www.yourdomain.com` would get an error.
- **www.**: the site answers on both `yourdomain.com` and `www.yourdomain.com`. This is the default and the sensible choice for most websites.
- **\*.** (wildcard): the site answers on any subdomain that is not already assigned to another website, for example `anything.yourdomain.com`. Only pick this if your site software genuinely needs wildcard subdomains, such as a multisite installation. The option is only offered if your plan allows wildcard subdomains.
Select **www.** unless you have a reason not to. Remember that each name still needs a matching DNS record pointing at the server before it works in a browser. If `www.yourdomain.com` already exists on the system in its own right, as a website, subdomain or alias domain, ISPConfig will not let you claim it here as well and the save fails with `There is already a subdomain with these settings.`
### SSL and Let's Encrypt SSL
- **SSL** enables HTTPS for the website.
- **Let's Encrypt SSL** requests and renews a free, trusted SSL certificate automatically. Ticking it ticks **SSL** for you, and unticking **SSL** clears it again, so the two always move together.
Tick **Let's Encrypt SSL** to give the site a working HTTPS address with no manual certificate work. While it is enabled the certificate is managed end to end by Let's Encrypt. The separate **SSL** tab, which exists for pasting in a certificate you bought elsewhere, stays visible but does nothing: it displays a notice that everything on it applies to non-Let's Encrypt certificates only, and that you must untick **Let's Encrypt SSL** first if you want to switch to your own certificate.
One important caveat: the check only succeeds if the domain, and every name attached to the site including the auto-subdomain and any alias or subdomains, already resolves to the hosting server from the public internet. A redirect on the site can also break the check. If DNS is not pointing at the server yet, create the website without these boxes ticked, wait for DNS to be in place, then edit the site and tick them. On a brand-new site ISPConfig always saves the website first and enables the certificate on a second pass a moment later, so give it a little longer than an ordinary save.
### PHP and PHP Version
The **PHP** drop-down controls whether, and how, the web server runs PHP scripts for this site. The exact list of modes shown depends on how the server is configured and on what your plan allows:
- **Disabled**: the site serves only static files such as HTML, CSS and images. Choose this if the site will never run PHP code.
- **PHP-FPM**: the mode to pick for almost every site. Scripts run under the website's own user account, several PHP versions can be offered side by side, processes are spawned and recycled adaptively, and it is generally faster than the CGI-based modes.
- **Fast-CGI**: also runs scripts as the website's user and also supports multiple PHP versions. It is a sound choice, and on a busy Apache site it performs comparably to PHP-FPM.
- **CGI**: runs scripts as the website's user but starts a fresh process per request, so it uses more memory and is the slowest of the three.
Unless you have a specific reason to do otherwise, select **PHP-FPM**. Note that in PHP-FPM, Fast-CGI and CGI modes, `php.ini` values cannot be changed from a PHP script, a vhost file or an `.htaccess` file. If your site needs a custom PHP setting such as a larger upload limit, open a support ticket rather than trying to set it from the site itself.
When you select **PHP-FPM** or **Fast-CGI**, the **PHP Version** drop-down appears; the other modes use the server's default PHP version. Choose the newest version that your website software supports; newer PHP versions are faster and receive security fixes for longer. You can change this setting at any time on a site you created yourself, so if a site misbehaves after a version change, you can switch back while you update the site's code.
### Active
Leave the **Active** checkbox ticked so the website is enabled as soon as it is created. Unticking it later takes the site offline without deleting any files, which can be useful during maintenance.
## Save and Verify the Website
1. Click **Save**. You return to the **Websites** list, where the new site now appears.
2. Look for the status box above the list reading **The following changes are not yet populated to all servers:** followed by **Create new website: 1**. It means ISPConfig has recorded your site but has not finished writing the web server configuration yet. ISPConfig's own advice is that storing updates can take up to one minute. A small counter also appears in the panel header while anything is pending; clicking it lists the same outstanding changes. The site is ready once both clear.
3. Once DNS for the domain points at the server, open `http://yourdomain.com` in a browser. A brand-new site shows the default ISPConfig welcome page, which confirms the web server is answering for your domain.
To replace the welcome page with your own site, upload your files to the website's `web` directory using an FTP user or file manager access for this site. The welcome page is a file called `standard_index.html`, placed there by ISPConfig along with a starter `favicon.ico` and `robots.txt`. It sits last in the web server's index order, so as soon as a real `index.html` or `index.php` exists, your own page is served instead. Deleting `standard_index.html` is tidy housekeeping rather than a required step.
## Troubleshooting
- **Clicking Add new website shows "The max. number of web domains for your account is reached."**: your plan's website allowance is used up. Open a support ticket to check or increase your allowance.
- **Saving fails with "There is already a website or sub / aliasdomain with this domain name."**: the domain is already configured as a website, alias domain or subdomain somewhere on the system. Check your own site list first; if you do not see it there, contact support.
- **The site is not reachable straight after saving**: wait a minute for the pending changes box on the **Websites** list to clear, then try again. If the domain still does not load, its DNS records probably do not point at the hosting server yet. DNS changes can take up to 24 hours to take effect worldwide.
- **The Let's Encrypt SSL checkbox switches itself off after saving**: the certificate check failed, almost always because the domain or its `www` name does not yet resolve to the server. Note that **SSL** is cleared along with it if it was not already enabled before, so expect to find both boxes unticked. Fix the DNS records, then edit the website and tick **Let's Encrypt SSL** again.
- **The browser shows the ISPConfig welcome page instead of my site**: the website exists but no `index.html` or `index.php` of your own is present in the `web` directory yet, so the server falls through to the `standard_index.html` placeholder. Upload your site to the `web` directory. If you have uploaded it into a subdirectory by mistake, move the files up a level.
- **The Domain tab fields are greyed out and cannot be edited**: that website was created for you by Noiz rather than by you, so ISPConfig treats its settings as read-only for your login. Open a support ticket with the change you need.
If you get stuck at any point, open a support ticket with the Noiz support team and include the domain name you are trying to create, the exact error message or symptom, and a note of which field or step the problem occurred on.
# How to Create a phpinfo File to Check Your PHP Configuration in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-a-phpinfo-file-to-check-your-php-configuration-in-ispconfig/
This guide shows you how to create a **phpinfo** file for a website on your Noiz hosting account so you can see exactly how PHP is configured for that site. A phpinfo file is a tiny PHP script (usually a single line) that, when opened in a browser, prints a full report of the running PHP setup: the active PHP version, which `php.ini` file is actually loaded, every extension that is turned on, and the effective limits such as `memory_limit` and `upload_max_filesize`. It is the quickest way to answer questions like โwhich PHP version is this site really running?โ, โwhich php.ini do I need to edit?โ and โdid that extension actually load?โ. It is written for Noiz clients whose websites run under ISPConfig, though the same file works on any PHP host. The report also exposes a great deal about the server, so the most important instruction in this guide is the one at the end: **delete the file the moment you are finished with it**.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** (latest stable) and PHPโs built-in `phpinfo()` function. This guide is written for Noiz hosting and is kept current against ISPConfig and PHP. It complements, and does not replace, the official documentation linked below. The `phpinfo()` output itself is a standard PHP feature and looks the same on any host; ISPConfig details can vary slightly between releases, so if a screen differs, check the official links.
### Official Documentation Reference
- [phpinfo() (PHP Manual)](https://www.php.net/manual/en/function.phpinfo.php): the official reference for the function that produces the report, including what each section contains.
- [The configuration file php.ini (PHP Manual)](https://www.php.net/manual/en/configuration.file.php): how PHP finds and layers its configuration files, which explains the **Loaded Configuration File** and **Additional .ini files** lines in the report.
- [ISPConfig Documentation](https://docs.ispconfig.org/): the official documentation covering website PHP mode and per-site PHP version selection.
## Prerequisites
- A website on your Noiz account whose PHP configuration you want to inspect.
- A way to upload a file into the siteโs document root: an FTP or SFTP client such as FileZilla or WinSCP with the login details for that website, or a web file manager if your plan provides one.
- To read the siteโs PHP mode and version in the panel, the ability to [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/). This is optional; the phpinfo file works without it.
## Read This First: The Security Warning
A phpinfo report is a gift to anyone probing your server. It reveals the exact PHP version (making it easy to look up known vulnerabilities for that release), the full list of loaded extensions and their versions, absolute file-system paths, the web server and its version, environment variables, and more. Leaving one on a live site is a well-known reconnaissance target and is routinely scanned for by bots.
Treat the file as strictly temporary. The safe pattern is:
- Give it an **unpredictable name**, not `phpinfo.php` or `info.php`, which are the first names an attacker guesses.
- Open it, read what you need, and **delete it straight away**.
- Never leave it in place โfor laterโ. If you need it again, it takes ten seconds to recreate.
The deletion step is covered in its own section below, and it is not optional.
## Create the phpinfo File
The file contains a single PHP function call. Everything else is optional.
### Write the Script
On your own computer, create a plain text file and put exactly this inside it:
```
### Open It in a Browser
Using `yourdomain.com` as an example for your real domain, go to the fileโs address, matching the exact file name you chose:
```
https://yourdomain.com/phpcheck-7f3a9.php
```
You should see the familiar purple-and-grey PHP information table. If you see the raw `
## What to Look For in the Report
The report is long, but for the common questions you only need a handful of lines. Use your browserโs find function (`Ctrl`+`F`, or `Cmd`+`F` on a Mac) to jump to each one.
### The Active PHP Version
The big heading at the very top reads **PHP Version 8.x.x** (or whichever version applies). This is the version the website is genuinely executing, which is the only version that matters when a plugin or application says it needs a minimum PHP release. It can differ from what a command-line check reports, which is why the browser view is the authoritative one for a website.
### The php.ini That Is Actually Loaded
Search for **Loaded Configuration File**. Its value is the full path to the main `php.ini` the site is using, for example `/etc/php/8.2/fpm/php.ini`. This is the single most useful line in the whole report: it tells you precisely which file governs the settings, so you are never editing the wrong one.
Just below it, **Scan this dir for additional .ini files** and **Additional .ini files parsed** list the extra fragment files (often one per extension) that PHP loads on top of the main file. If a setting is not where you expect it in the main `php.ini`, it is frequently being set in one of these fragments instead.
On an ISPConfig site the path is also a clue to how any per-site override was applied. A site in PHP-FPM mode loads the server-wide `php.ini` for its PHP version, because its custom settings are written into that siteโs own FPM pool configuration rather than into a separate `php.ini`. A site in Fast-CGI, CGI or SuPHP mode that has custom settings gets a generated per-site `php.ini` instead, so the path points into the siteโs own configuration directory rather than the system one under `/etc`.
### Which PHP Mode Is in Use
Search for **Server API**. A value such as `FPM/FastCGI`, `CGI/FastCGI`, or `Apache 2.0 Handler` tells you which PHP mode the site runs under. This maps directly to the PHP mode set for the website in ISPConfig (PHP-FPM, Fast-CGI, and so on), which is useful when a change you made in the panel does not seem to be taking effect: the Server API confirms the mode PHP is really serving requests with.
### Whether an Extension Is Loaded
Each enabled extension has its own titled section in the report, for example **gd**, **curl**, **mysqli**, **intl**, **imagick**, or **opcache**. To confirm one is present, use find to search for its name: if there is a section header for it, it is loaded; if there is no match anywhere on the page, it is not enabled for this siteโs PHP version. This is the fastest way to settle an applicationโs โrequired extensionโ error.
### The Effective Limits, and the Local vs Master Trick
In the **Core** section near the top you will find the limits people most often need to check:
- `memory_limit`: how much memory a single script may use.
- `upload_max_filesize` and `post_max_size`: the largest file, and the largest whole request, that can be uploaded.
- `max_execution_time`: how long a script may run before it is stopped.
- `max_input_vars`: how many form or array fields a request may contain (a common culprit behind large menus or imports silently failing).
Each setting shows two columns: **Local Value** and **Master Value**. The **Master Value** is the server-wide default from the main `php.ini`; the **Local Value** is what is actually in force for this site after any per-site overrides. On an ISPConfig site, anything entered in the **Custom php.ini settings** field on the websiteโs **Options** tab shows up here as a Local Value that differs from the Master Value, which is a quick way to confirm an override took effect. That tab is shown only to administrator logins, and to reseller logins where the server permits it, so on a Noiz-managed site the change is made for you: ask the Noiz support team for the limit you need, then reload the phpinfo page and check the Local Value. Always trust the **Local Value** as the real limit for the site.
## How This Fits ISPConfigโs Per-Site PHP
ISPConfig lets each website choose its own PHP handling, which is exactly why a phpinfo check is worth doing per site rather than assuming a server-wide answer. Open the site under **Sites > Websites > Website**: two fields on its **Domain** tab shape what the report will say:
- **PHP**, which either disables PHP for the site or sets the mode it runs under (PHP-FPM, Fast-CGI, and similar). The report reflects the mode in its **Server API** line.
- **PHP Version**, which selects among the PHP releases installed on the server. This dropdown appears only when **PHP** is set to Fast-CGI or PHP-FPM; the other modes always run the serverโs default PHP, so there is nothing to choose. Two sites on the very same Noiz account can therefore run different PHP versions, and each has its own `php.ini` and its own set of loaded extensions.
Because of this, the version and extensions shown by a phpinfo file placed on one site apply to that site only. If you change the **PHP Version** for a site in ISPConfig and reload the phpinfo page, the version at the top should change to match, confirming the switch worked. The **Loaded Configuration File** path usually changes with it, because each PHP release keeps its own configuration directory, though a site whose settings are served from a generated per-site `php.ini` keeps the same path.
## Delete the File Immediately Afterwards
As soon as you have read what you need, remove the file. Do not skip this.
1. Reconnect (or return) to your FTP or SFTP session for the site.
2. Open the same `web` document-root folder.
3. Delete the `phpcheck-7f3a9.php` file you uploaded.
4. Reload the fileโs address in your browser. You should now get a **404 Not Found**, which confirms it is gone.
If you ever find an old `info.php`, `phpinfo.php`, or similar left behind on a site, delete it as well: an out-of-date report is just as revealing to an attacker as a fresh one.
## A Safer Alternative for Shell Accounts
If your service includes shell access over SSH (Noiz VPS, dedicated servers, and shell-user accounts), you can inspect PHP without exposing anything on the web at all. From the command line:
```
php -v
```
prints the version, and
```
php -i
```
prints the same information as a phpinfo page, in plain text. To jump straight to one setting, filter it, for example:
```
php -i | grep memory_limit
```
Where several PHP releases are installed, call the specific one by its versioned binary, such as `php8.2 -i`, to be sure which you are querying. One caveat: the command line uses the **CLI** build of PHP, which can load a different `php.ini` and different limits from the **FPM/FastCGI** build that serves your website. For the values a visitorโs request actually sees, the browser-based phpinfo file remains the definitive check; the command line is the convenient, exposure-free option for the CLI environment.
## Troubleshooting
- **The browser shows the raw `
### Step 2: Add the new alias
1. Click the **Add new Email alias** button. The **Email Alias** form opens.
2. In the **Email** row, type the part of the address before the @ sign into the **Alias** field. For example, type `info` if you want the alias `info@yourdomain.com`. ISPConfig accepts letters, digits, dots, hyphens and underscores here. The first and last character must be a letter or a digit, and a dot may not appear twice in a row. A plus sign is rejected, so an alias such as `info+sales` is not possible. If the address breaks any of these rules, saving fails with **Email address is invalid.**
3. Select your email domain, for example `yourdomain.com`, from the **Domain** drop-down menu next to the Alias field.
4. In the **Destination** drop-down, select the existing mailbox that should receive mail sent to the alias, for example `jane@yourdomain.com`. The destination address is also the username the mailbox owner uses to log in for sending and receiving.
### Step 3: Review the optional settings
- **Send as**: ticked by default. When enabled, the owner of the destination mailbox is allowed to send outgoing mail using the alias as the sender address, while still logging in with the destination mailbox's own username and password. Leave this ticked if replies should appear to come from the alias.
- **Enable greylisting**: an anti-spam measure that briefly delays the very first message from an unknown sender. Legitimate mail servers retry automatically, so genuine mail still arrives, just a little later the first time. Leave it unticked unless the alias attracts a lot of spam.
- **Active**: ticked by default. The alias only works while this box is ticked, so leave it as it is. Unticking it later is a quick way to switch the alias off without deleting it.
### Step 4: Save and test
1. Click **Save**. The new alias appears in the Email Alias list.
2. Wait a minute or two: ISPConfig applies configuration changes to the mail server on a short cycle, so a brand-new alias may not accept mail instantly.
3. Send a test message from an outside address, for example a personal webmail account, to the new alias. It should arrive in the destination mailbox.
4. If you enabled **Send as** and want to reply from the alias, add the alias address as an additional sender identity in your email program or webmail, using the destination mailbox's username and password for the outgoing server.
## Troubleshooting
- **The Destination drop-down is empty**: no mailbox exists on your account yet. [Create a mailbox](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/) first, then return to the alias form.
- **Your domain is missing from the Domain drop-down**: a domain that is set up as a domain alias is deliberately left out of this list, because mail for it is already rewritten to the domain it points at. Create the alias on that target domain instead.
- **Error "There is already a mailbox with this email address"**: an active mailbox already uses that exact address, so the same address cannot also be an alias. Choose a different local part, or simply use the mailbox itself.
- **Error "This email alias does already exist"**: an alias or forward with that same address and that same destination is already set up. Edit the existing entry rather than creating a second one.
- **Error "The max. number of email aliases for your account is reached"**: your hosting plan's alias limit is full. Delete an unused alias, or open a support ticket with the Noiz support team to discuss raising the limit.
- **Mail to the alias bounces or never arrives**: check that the alias's **Active** box is ticked and that the destination mailbox itself is active and not over its storage quota. Also allow a couple of minutes after saving before testing.
- **You cannot send from the alias address**: confirm the **Send as** box is ticked on the alias, and that your email program authenticates with the destination mailbox's credentials while using the alias as the From address.
If you get stuck at any point, open a support ticket with the Noiz support team and include the full alias address, the destination mailbox address and, if a message bounced, the complete bounce message text.
# How to Create an Email Mailbox With an Autoresponder and Forwarding in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-an-email-mailbox-with-an-autoresponder-and-forwarding-in-ispconfig/
This guide shows you how to create an email mailbox in ISPConfig that replies to every sender with an automatic message and forwards a copy of each incoming message to another address. It is the pattern to use when you are retiring an address (for example, a staff member has left) but you still want incoming mail routed to someone else and senders told the address is no longer monitored.
In ISPConfig the relevant fields use their own names: **Send copy to** is a forward (a carbon copy of each message), and **Autoresponder** is the automatic reply (sometimes called a vacation or out-of-office message). A third field, **Disable (local) delivering**, stops mail being saved in the mailbox itself, and it is the one people reach for to stop a retired mailbox filling up. Leave it alone here: ticking it also switches the autoresponder off. The reason is set out under **Why local delivery must stay on** below. For a plain mailbox without these extras, start with the basic guide, [How to Create an Email Mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/).
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** (the release running on Noiz servers). This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig documentation portal](https://www.ispconfig.org/documentation/)
- [ISPConfig manual](https://www.ispconfig.org/documentation/user-manual/) (field-by-field reference for the Email module)
- [ISPConfig frequently asked questions](https://www.ispconfig.org/documentation/frequently-asked-questions/)
## Prerequisites
- Login details for your ISPConfig control panel (client or admin level).
- The email domain already added to your account, so that it appears in the domain dropdown.
- The destination address you want to forward to. This can be on the same domain or an external address, such as a Gmail account.
## Step-by-Step Instructions
1. Log in to your ISPConfig control panel
- Open your web browser and go to your ISPConfig panel address (for example, `https://yourserver:8080`).
- Enter your username and password, then click **Login**.
2. Open the Email module
- From the top menu, click **Email**.
- In the left-hand menu, select **Email Mailbox**.
- Click **Add new Mailbox**.
3. Enter the mailbox name and password
- In the **Name** field, type a display name (optional).
- In the **Email** field, type the local part of the address (for example, `info`) and choose the domain from the dropdown, giving you `info@yourdomain.com`.
- Set a strong password in the **Password** and **Repeat Password** fields, or click **Generate Password**. A password is always required, even on an address nobody will log in to.
- Set **Quota (0 for unlimited)** in MB. This mailbox does keep a copy of everything it forwards, so give it a realistic size rather than treating it as empty.
4. Set the forwarding (Send copy to) address
- In the **Send copy to** field, enter the address that should receive the mail (for example, `newperson@yourdomain.com`). More than one address is allowed here, separated by commas.
- Leave **Copy during delivery** as you find it. It only decides whether the copy is taken before or during delivery to the mailbox, and either setting forwards the mail.
- Leave **Send outgoing BCC to** blank unless your organisation has a specific archiving or compliance requirement. It takes one address only, and it copies mail sent *from* this account, not mail arriving at it.
5. Configure the autoresponder
- Click the **Autoresponder** tab.
- Tick **Enable the autoresponder**.
- In **Email Subject**, enter a subject line (for example, `This mailbox is no longer monitored`).
- In **Text**, enter the reply body (for example, `Thank you for your email. This address is no longer monitored. Please write to info@yourdomain.com instead.`).
- Set **Start on** and **End by** only if the reply should run for a limited period. Leave both blank for a permanent reply. **Start on** will not accept a date in the past, and **End by** must be later than **Start on**. Once the **End by** date has passed, no further replies go out.
6. Check the delivery options
- Return to the **Mailbox** tab and scroll to the options near the bottom.
- Leave **Disable (local) delivering** unticked. This is the important one. Ticking it hands the message straight to the forward address and never delivers it to the mailbox, and the autoresponder only runs as part of that local delivery, so ticking it silently switches the automatic reply off.
- Leave **Enable receiving** ticked, or there is nothing to forward or answer in the first place.
- Leave **Disable sending** unticked. It looks harmless on an address nobody sends from, but with the default **Copy during delivery** setting it also breaks the forward, because ISPConfig only passes the **Send copy to** address to the mail server while sending is allowed on the account.
- Leave **Enable greylisting**, **Disable IMAP** and **Disable POP3** unticked unless you have a specific reason to change them. Greylisting in particular is best left off on a forwarding address, so that forwards are not delayed.
7. Save and test
- Click **Save**.
- Wait a minute or two. ISPConfig applies mailbox changes to the mail server through a background job queue, so they are not always instant.
- From an outside account, send a test message to the address.
- Confirm that the sender receives the automatic reply, and that the message arrives at the **Send copy to** address. A copy is also kept in the mailbox itself, which you can check by webmail if you want a third confirmation.
## How This Combination Works
On its own, a mailbox stores mail and lets someone read it. The two settings above add to that behaviour:
- **Send copy to** forwards a copy of every incoming message to the address you specify. The original is still delivered to the mailbox, so the mail is in two places and nothing is lost if the forward target has a bad day.
- The **Autoresponder** replies to the sender, so people writing to the old address are told where to go next. That reply is produced while the message is being delivered into the mailbox, not by the forward.
The result is a graceful retirement of an address. No one loses the mail, and senders are told where to write instead.
### Why local delivery must stay on
**Disable (local) delivering** looks like the obvious third ingredient, since it stops the retired mailbox filling up. It does more than that. Ticking it moves the whole job up to the mail server: the message is redirected to the **Send copy to** address before the mailbox is involved at all, so mailbox rules are never reached. ISPConfig says this in the field's own tooltip, which notes that it disables delivery to the inbox and the processing of mail filters and rules. The autoresponder is one of those rules, so it never runs.
That leaves two honest choices rather than one:
- **Reply and forward.** Leave **Disable (local) delivering** unticked, as in the steps above. Mail is answered, forwarded, and also kept. This is what most address retirements want.
- **Forward only, nothing kept.** Tick **Disable (local) delivering** and accept that there will be no automatic reply. If that is all you need, **Email** then **Email Forward** does the same job without creating a mailbox, a password or a quota at all.
## Points to Watch
- **The mailbox does fill up.** Because local delivery stays on, every message it forwards is also stored. Set a **Quota** you are happy with and empty the mailbox occasionally, or the address will eventually start refusing mail.
- **Replies are rate limited.** Any one sender gets at most one automatic reply per day, however many messages they send, so nobody is flooded and reply loops do not build up. Anything already flagged as spam is never answered, and automated and mailing list messages are left alone too.
- **Aliases are covered.** If other addresses or alias domains point at this mailbox, the autoresponder treats those as the same person and replies for them as well.
- **The reply comes from the retired address.** Recipients see the automatic reply as coming from the address you are retiring, which is expected. Always point them to a monitored address in the reply text.
- **Changes are queued.** If a test does not behave as expected straight away, wait a moment and try again before changing settings.
## Troubleshooting
- **The autoresponse never arrives.** Check **Disable (local) delivering** on the **Mailbox** tab first, because ticking it switches the autoresponder off and is by far the most common cause. Then check that **Enable the autoresponder** is ticked and that **End by** has not already passed. Remember that a given sender is only answered once a day, and that spam, automated senders and mailing lists are deliberately not answered.
- **Forwarded mail is not received.** Confirm the **Send copy to** address is entered correctly and is active, and that **Disable sending** is unticked, since that setting stops the forward as well. Ask the recipient to check their spam or junk folder, because forwarded mail can score higher there.
- **The sender gets a bounce.** If the forward target is rejecting the mail or cannot be reached, the sender is told about that copy even though the mailbox copy was delivered normally. Correct or replace the forward address. A bounce can also mean the mailbox has hit its **Quota**.
- **Nothing changed after saving.** Give ISPConfig a minute to apply the queued job, then test again.
## Need a Hand?
If you are on a managed Noiz hosting plan and would like this configured for you, or you are unsure which forwarding pattern suits your situation, open a support ticket from your Noiz client area and the team will set it up with you.
## Reference Screenshot
The ISPConfig 3.3 Mailbox configuration screen:

# How to Create an Email Mailbox in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/
This guide walks you through creating a basic email mailbox in the ISPConfig control panel on your Noiz shared hosting account. A mailbox is a real, storable inbox (for example `info@yourdomain.co.za`) that you can read in webmail or connect to an email client such as Thunderbird or Outlook. It is the quickest way to get a working email address up and running.
If you also want the mailbox to reply automatically while you are away, or to send a copy of incoming mail to a second address, follow the fuller walkthrough in [How to create an Email Mailbox with an Autoresponder and a Send copy to address in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-with-an-autoresponder-and-forwarding-in-ispconfig/) instead.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** (the version running on Noiz shared hosting). This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig Documentation](https://www.ispconfig.org/documentation/): the vendor manual covering the Email module and mailbox options in depth.
## Prerequisites
- A Noiz shared hosting account with ISPConfig access.
- Your ISPConfig login credentials (sent in your welcome email).
- An **email domain** already present on your account. In ISPConfig a mailbox can only be created once its domain exists under **Email > Email Accounts > Domain**. On Noiz shared hosting this is normally set up for you when your hosting is provisioned, so your domain should already appear in the dropdown. If it does not, contact Noiz support to have the email domain added before you continue.
## Step 1: Log in to ISPConfig
1. Sign in to the ISPConfig control panel. If you are not sure how, see [How to log in to the ISPConfig control panel via a web browser](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
2. Once logged in as a client, ISPConfig shows only your own services. If your account has reseller or admin rights and you manage several clients, make sure you have the correct client selected before adding the mailbox (see [Understanding ISPConfig User Levels](/ispconfig/understanding-ispconfig-user-levels-admin-reseller-and-client/)).
**Troubleshooting tip:** If you cannot sign in, double-check the username and password from your welcome email, and confirm you are using the correct panel address. If sign-in fails repeatedly the server may have temporarily blocked your IP address for security reasons; see [What to Do If Your IP Address Is Blocked by an ISPConfig Server](/ispconfig/what-to-do-if-your-ip-address-is-blocked-by-an-ispconfig-server/).
## Step 2: Create the email mailbox
1. In the top menu, click **Email**.
2. In the left sidebar, under **Email Accounts**, click **Email Mailbox**.
3. Click **Add new Mailbox**.
4. Complete the mailbox details: For a basic mailbox the remaining fields can stay as they are. **Spamfilter** starts on **- Inherit domain setting -**, so the mailbox follows the policy already set on the domain, and **Enable receiving** is ticked by default.
- **Name:** Optional. The real name of the person who will use the address (for example `John Doe`). It appears in the mailbox list as the **Realname** and can be left blank.
- **Email:** This one row is two fields. Type the part before the @ (for example `info`) in the box on the left, then select your domain (for example `yourdomain.co.za`) from the dropdown beside it, giving `info@yourdomain.co.za`. Only domains already added as email domains appear in that dropdown. The finished address is also the username for webmail, IMAP, POP3 and SMTP.
- **Password** and **Repeat Password:** Set a strong, unique password in both boxes, or click **Generate Password**, which fills both for you. A **Password strength** indicator sits between the two fields. This password is the login for webmail and any email client, so store it somewhere safe.
- **Quota (0 for unlimited):** The mailbox size in MB (for example `500`). `0` means unlimited, but ISPConfig only accepts `0` where the account has no mail storage limit at all. On a plan with a mail space allowance the save is refused, ISPConfig reports the maximum space still free in MB, and it fills that figure into the field for you. Setting a sensible quota also stops one mailbox swallowing the whole allowance.
5. Click **Save** to create the mailbox.
**Good to know:** The mailbox record is saved immediately, but the server applies pending changes on a once-a-minute cycle, so the mail storage for the new account is created a moment later. If a first login fails right away, wait a minute and try again.
## Step 3: Verify the mailbox and start using it
1. Return to the **Email Mailbox** list. Your new address should appear in the table.
2. Sign in to the mailbox to confirm it works. The fastest check is webmail; see [How to Access Your Webmail in ISPConfig](/ispconfig/how-to-access-your-webmail-in-ispconfig/). Where the server has welcome messages enabled, the inbox already contains one, which is a useful sign that delivery is working.
3. To use the mailbox in a desktop or mobile app, add it as an IMAP account. Your login is the **full email address** and the password you set above. For the exact incoming and outgoing server names and ports, follow [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/).
## Troubleshooting
- **Your domain is missing from the Domain dropdown:** the email domain has not been added under **Email > Email Accounts > Domain**. On Noiz shared hosting this is provisioned for you, so contact Noiz support to have it added.
- **The new mailbox does not appear in the list:** the list is read straight from the panel database, so a saved mailbox shows up at once. If it is not there, the save was rejected and the form stays open with a red message at the top: an account that has used up its allowance of mailboxes reports that the maximum number of mailboxes has been reached, and one that has used up its mail storage reports the maximum space still available in MB. Contact Noiz support if you need a larger allowance.
- **Email Mailbox is missing from the sidebar:** ISPConfig hides that menu entry when the account is allocated no mailboxes at all. Contact Noiz support to have mailboxes added to the plan.
- **Webmail or your email client rejects the login:** confirm you are entering the **full email address** as the username (not just the part before the @), and that the password matches exactly. If the mailbox form shows a separate **Login** field with a value in it, that value is the username instead. Re-set the password from the mailbox settings if you are unsure.
If you are on a Noiz managed plan and would rather Noiz set the mailbox up for you, or you are stuck at any step, open a support ticket and the Noiz team will help.
## Related articles
- [How to create an Email Mailbox with an Autoresponder and a Send copy to address in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-with-an-autoresponder-and-forwarding-in-ispconfig/)
- [How to Set Up Email Forwarding in ISPConfig](/ispconfig/how-to-set-up-email-forwarding-in-ispconfig/)
- [How to Create an Email Alias in ISPConfig](/ispconfig/how-to-create-an-email-alias-in-ispconfig/)
- [How to Access Your Webmail in ISPConfig](/ispconfig/how-to-access-your-webmail-in-ispconfig/)
- [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/)
- [How to log in to the ISPConfig control panel via a web browser](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/)
# How to Create an FTP Account in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-create-an-ftp-account-in-ispconfig/
This guide shows you how to create an FTP account in the ISPConfig control panel and then connect to it with an FTP program so you can upload files to your website. It is written for Noiz clients managing their own hosting account through ISPConfig. In ISPConfig an FTP account is called an **FTP User**, and you may also see it referred to as an FTP login elsewhere; they all mean the same thing: a username and password that let a file transfer program such as FileZilla read and write the files of one of your websites.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This article follows the official ISPConfig manual procedure for creating an FTP account, cross-checked against the current interface. ISPConfig evolves between releases, so if a screen differs from this guide, check the official documentation links below.
### Official Documentation Reference
- [How to Add a Website in ISPConfig (HowtoForge)](https://www.howtoforge.com/ispconfig-website/): includes a current, field-by-field walkthrough of creating an FTP user under **Web Access**, maintained by the ISPConfig developers' documentation site.
- [ISPConfig 3 Documentation](https://docs.ispconfig.org/): the official online documentation index for ISPConfig 3.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- At least one website already exists on your account, because every FTP account belongs to a specific website. If you have not created one yet, see [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/).
- An FTP program installed on your computer, for example FileZilla, WinSCP or Cyberduck. Any client that supports FTP with TLS encryption will work.
- A hosting plan with at least one unused FTP user allowance. If the **FTP-User** menu item is missing, your plan does not include FTP users.
## Open the FTP User Form
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, under **Web Access**, click **FTP-User**. A list of any existing FTP accounts on your hosting appears.
4. Click the **Add new FTP-User** button.
The **FTP User** form opens on the **FTP User** tab. A second tab, **Options**, holds optional settings covered later in this guide. Parts of the official ISPConfig manual still write this path as **Sites** > **FTP** > **FTP-User**, but the menu group in the panel is **Web Access**, which is also how the manual's own reference chapter lists it.
## Complete the FTP User Tab
Fill in the fields described below, then click **Save**.
### Website
In the **Website** drop-down, select the website this FTP account should have access to, for example `yourdomain.com`. Each entry in the list is shown as the domain name followed by the name of the server it is hosted on. The account will be able to see and change the files of this one website only. If you host several websites and want FTP access to each, create a separate FTP account for each site.
### Username and the automatic prefix
In the **Username** field, type the name you want for the account, for example `deploy`. Notice the short piece of text shown immediately in front of the box: that is a fixed prefix which ISPConfig adds automatically to whatever you type. The prefix is based on your client name on the system, so if the prefix reads `client1` and you type `deploy`, the actual username you will log in with is `client1deploy`.
The prefix keeps usernames unique across everyone hosted on the server and cannot be removed from your side, so do not try to type it again yourself. After saving, the **FTP-User** list shows the complete final username, and that full string, prefix included, is what you must enter in your FTP program.
### Password and Repeat Password
Type a password in the **Password** field and confirm it in **Repeat Password**, or click the **Generate Password** button to have ISPConfig create a strong one for you. The **Password strength** indicator rates your choice as you type. Because an FTP account can read and overwrite every file of the website, treat this password with the same care as the panel login itself: use eight or more characters mixing upper and lower case letters, numbers and symbols, and avoid dictionary words or names. A minimum password length and strength are enforced for FTP users, so a short or weak password is rejected when you save. Record the password somewhere safe; ISPConfig does not display it again later.
### Harddisk-Quota
The **Harddisk-Quota** field sets the maximum amount of disk space, in megabytes, this FTP account may upload. A value of `-1` means unlimited, and is normally fine to leave in place: an FTP user can never upload more than the disk quota of the website itself, so this field only matters if you want to give a specific FTP user a tighter limit than the site as a whole, for example when handing a login to an outside developer.
### Active
Leave the **Active** checkbox ticked so the account works as soon as it is created. Unticking it later disables the login without deleting the account or any files, which is a quick way to suspend a contractor's access when a job is finished.
## Optional Settings on the Options Tab
For a standard FTP account you can skip this tab entirely and simply click **Save**. Two settings are available if you need them:
- **Directory**: the home directory of the FTP account. The account can do uploads and downloads in this directory and every subdirectory below it. The field is blank while you are creating the account, and there is no point filling it in at that stage, because ISPConfig sets it to the website's own directory as soon as you save. To confine the account to one part of the site, save the account first, then reopen it from the list and add the subfolder to the end of the path, for example ending in `/web/media` to lock the user into the `media` folder inside the site's document root. The path must stay inside the website's directory; ISPConfig rejects anything outside it.
- **Expire at**: an optional date and time at which the account is disabled automatically. Useful for temporary access, for example a developer engaged for a fixed project. Leave it empty for an account that never expires.
Server administrators see further fields on this tab, such as **User identifier (UID)**, **Group identifier (GID)**, **Filequota** and the upload and download ratio and bandwidth limits. These are not shown on a client login, and the defaults set by Noiz are correct, so you do not need to do anything about them.
## Save and Find the Final Username
1. Click **Save**. You return to the **FTP-User** list, where the new account now appears.
2. Read the **Username** column carefully: it shows the complete username including the automatic prefix, for example `client1deploy`. This full string is your FTP login name.
3. Watch for the small red change indicator near the top of the panel. It shows that ISPConfig is still writing the new account to the FTP server in the background, and clicking it lists what is outstanding. The server collects queued changes once a minute, so the indicator normally clears within a minute or two; try to connect once it has gone.
## Connect With an FTP Client
Every FTP program asks for the same handful of details, even if the labels vary slightly. Use these settings:
| Setting | Value |
| --- | --- |
| **Host** (also labelled Server or Hostname) | Your website's domain without any prefix, for example `yourdomain.com`, not `http://yourdomain.com` |
| **Port** | `21`, or leave blank to use the default |
| **Protocol / Encryption** | FTP with explicit TLS, often labelled **FTPS**, **FTPES** or **Require explicit FTP over TLS**. Choose this rather than plain unencrypted FTP so your password and files are protected in transit |
| **Username** (also labelled User or Login) | The full username from the FTP-User list, prefix included, for example `client1deploy` |
| **Password** | The password you set on the **FTP User** tab |
| **Transfer mode** | Passive, which is the default in almost every modern client |
Connect, and if your client shows a certificate confirmation window the first time, review it and choose to trust the certificate for future sessions. Once logged in you will see the directory structure of your website.
### Where to put your files
- Upload website content into the `web` directory, or subdirectories of it. The `web` directory is the document root, meaning it is what visitors see when they open `yourdomain.com` in a browser.
- The `private` directory is for files that should not be reachable from the web, such as configuration backups.
- Perl and CGI scripts belong in the `cgi-bin` directory rather than in `web`.
- Other directories you may see, such as `log`, `tmp`, `ssl` and `backup`, are maintained by the server. Leave them alone.
A brand-new website contains a placeholder welcome page called `standard_index.html` in the `web` directory, along with a default `favicon.ico` and `robots.txt`. The web server only falls back to that placeholder when no `index.html` or `index.php` is present, so your own home page takes over the moment you upload it. Delete `standard_index.html` once your site is live if you would rather it were not sitting there.
## Troubleshooting
- **Login is refused with an authentication error**: the most common cause is entering only the short name you typed in the form, for example `deploy`, instead of the full prefixed username, for example `client1deploy`. Copy the username exactly as it appears in the **FTP-User** list. Also allow a minute after saving for the red change indicator to clear before the first login attempt.
- **Saving fails with "The username must be unique."**: an FTP account with that name already exists somewhere on the server. Choose a different name.
- **"The max. number of FTP users for your account is reached."**: your plan's FTP user limit is used up. ISPConfig shows this message the moment you click **Add new FTP-User**, in place of the form, so you never get as far as saving. Delete an account you no longer need, or open a support ticket to discuss a higher allowance.
- **The connection times out or the directory listing hangs**: check that your client is set to passive transfer mode and that a local firewall or office network is not blocking FTP. If the network blocks port `21`, connecting from another network will confirm the account itself is fine.
- **The client warns about the server certificate**: FTP with explicit TLS presents the server's certificate, and some clients ask you to confirm it on first connection. Inspect the certificate details and accept it. If the warning claims the certificate is expired or the name looks completely unrelated to your hosting, stop and contact support.
- **Files upload successfully but do not appear on the website**: they were probably uploaded outside the `web` directory. Move them into `web`, and check that your home page file is named `index.html` or `index.php`, because a differently named file leaves the server showing the `standard_index.html` placeholder instead.
- **Uploads suddenly fail partway through**: the account or the website has hit its disk quota. Remove unneeded files, lower the amount you are uploading, or raise the **Harddisk-Quota** value if you set one for this FTP user.
- **Editing the Directory field fails with "Directory not inside of web root directory."**: the path you entered points outside the website's own directory. Keep the path ISPConfig set for the website exactly as it is and only append your subfolder to the end of it.
If you get stuck at any point, open a support ticket with the Noiz support team and include the full FTP username, the website it belongs to, the FTP program you are using, and the exact error message from its message log.
# How to Delete an FTP Account in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-delete-an-ftp-account-in-ispconfig/
This guide covers removing an FTP login from a website on your Noiz hosting through the ISPConfig control panel, and the two consequences that catch people out afterwards. In ISPConfig the account is called an **FTP User**; you may see the same thing called an FTP account or an FTP login elsewhere. Deleting one takes about ten seconds. Working out what depended on it takes longer, so most of this guide is about that.
**Last reviewed:** 27 July 2026, against the current ISPConfig release. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig 3 User Manual](https://www.ispconfig.org/documentation/user-manual/): the official manual, including the **Sites** > **Web Access** > **FTP-Accounts** reference for every field on the FTP user form.
- [ISPConfig Documentation index](https://www.ispconfig.org/documentation/): the full list of official ISPConfig documentation.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- The FTP account belongs to a website on your own hosting account. You cannot see or delete FTP users belonging to another client.
- You know, or are about to work out, what has been using the credentials. The section below is there to help with that.
## What Deleting Actually Does
An FTP user in ISPConfig is a set of credentials stored in a database, not a person and not a folder. Deleting it removes the ability to log in with that username and password. Nothing else changes. Two specific points are worth being clear about before you click anything.
### The files are not deleted
Everything the account could reach stays exactly where it is. Your website keeps serving, the contents of `web` and `private` are untouched, and anything the account uploaded remains on disk. Deleting an FTP user is a credentials operation, never a cleanup operation.
This matters most when the reason for deleting is that you no longer trust whoever had the login. Removing the account closes one door, and the files that person left behind are still live: an abandoned admin script, a forgotten upload folder or a modified theme file will keep working after the account is gone. If you want those files removed, remove them *first*, while you still have a working way in, and only then delete the login. Reversing the order means creating a fresh account just to finish the tidy-up.
It is also worth remembering that FTP is one door among several. A [shell user](/ispconfig/how-to-create-a-shell-user-in-ispconfig/) (listed in ISPConfig as **SSH/SFTP-User** under **Command Line**), a database user, or a WordPress or other application login are separate credentials and are unaffected. If you are cutting off access properly rather than tidying up, check each of those too.
### Anything using the credentials starts failing
This is the one that generates support tickets a fortnight later. FTP logins tend to end up saved inside tools that nobody thinks about day to day:
- Backup plugins and backup services that push a copy of the site to remote storage over FTP.
- Deployment tooling: a CI pipeline, a build script, or the saved deployment profile in an editor or IDE.
- [Cron jobs](/ispconfig/how-to-create-a-cron-job-in-ispconfig/) or scheduled scripts that call `lftp`, `curl` or `wget` with the username baked into the command.
- Saved site profiles in FileZilla, WinSCP or Cyberduck belonging to a designer or developer who is still working on the site.
The awkward part is that these failures are usually quiet. A backup job often reports that it ran, because the local archive was created successfully, and only the remote upload step failed. You find out when you need the backup. Before deleting, check the tools you know connect to the site, and note the account's **Website** value on the **FTP User** tab along with the **Directory** path on the **Options** tab: a login confined to a single subfolder is almost always a tool or a limited contractor rather than a general-purpose login.
One useful distinction: a tool connecting on port `22` is using SSH or SFTP, which is a shell user, not an FTP user, and deleting an FTP account will not affect it. Only connections on port `21` are affected.
## Disable First If You Are Not Certain
ISPConfig lets you switch an account off without destroying it, and when you cannot account for everything that might be using a login, this is the better first move.
1. Open **Sites** > **Web Access** > **FTP-Accounts** and click the account name to open it.
2. On the **FTP User** tab, untick **Active**, then click **Save**.
Logins are refused immediately, the settings and the directory restriction are preserved, and re-ticking the box restores the account with the same password. Leave it disabled for a week or two, and anything that quietly depended on it will surface. There is also an **Expire at** field on the **Options** tab if you would rather set a date and let ISPConfig disable the account for you. On a client login that tab is short: **Directory** and **Expire at** only, because the file quota, ratio, bandwidth and UID or GID fields are administrator-only.
The one thing disabling does not do is free up capacity. A disabled account still counts towards the **Max. number of FTP users** limit on your hosting plan, so if you are deleting in order to create a new account and have hit the limit, you need an actual deletion.
## Delete the FTP Account
1. In the ISPConfig control panel, click **Sites**, then **FTP-Accounts** under **Web Access** in the left menu. The list it opens is headed **FTP-User**, which is the same thing.
2. Find the account in the list. The **Username** column shows the full username including the automatic client prefix, so an account created as `deploy` appears as something like `client1deploy`. Match on the full string, and check the **Website** column if similar names exist across several sites.
3. Click the delete icon at the right-hand end of that row.
4. Confirm when ISPConfig asks *Do you really want to delete this record?* There is no undo.
## Confirm It Worked
The account disappearing from the list means ISPConfig has accepted the change, not that the FTP server has applied it yet. Watch the small red change indicator near the top of the panel: while it is showing, the deletion is still being written out to the FTP server in the background. The list itself names the outstanding job, as **Delete FTP user**, and ISPConfig's own wording is that storing updates can take up to one minute.
Once it has cleared, prove the deletion rather than assuming it. Open your FTP client and try to connect with the old username and password. A correct result is a rejected login, usually reported as an authentication or `530` error. If you would rather check from the site's side afterwards, the [website usage and log tools](/ispconfig/how-to-monitor-website-usage-and-logs-in-ispconfig/) will show whether anything is still attempting to connect.
An FTP session that was already open when you deleted the account may continue until it disconnects. If you are cutting off access urgently, confirm no session is still live rather than relying on the deletion alone.
## Troubleshooting
- **The account is not in the list at all**: the list only shows FTP users on websites assigned to your client login, so an account on another client's site never appears. If you are certain it should be there, open a support ticket with the full username and the website it belongs to.
- **Deleting returns a permissions message**: ISPConfig answers *You dont have the permission to delete this record!* when your login can see the record but is not allowed to remove it. Retrying will not help, so raise a support ticket.
- **The account is still listed after confirming**: refresh the list. If it persists and the red change indicator has cleared, the deletion did not reach the FTP server, and that needs a support ticket.
- **The old credentials still work a few minutes later**: either the change indicator has not cleared yet, or your FTP client is reusing an existing connection. Disconnect fully, close the client, and try again.
- **You deleted the wrong account**: no files were harmed. [Create a new FTP account](/ispconfig/how-to-create-an-ftp-account-in-ispconfig/) using the same short username and the same website, and the full prefixed username will come out identical. The password will be a new one, so anything storing the old password still needs updating.
- **A backup or deployment started failing shortly afterwards**: it was using the deleted credentials. Rather than recreating the same login out of habit, decide whether that tool should still have write access, then either create a fresh account scoped to the directory it actually needs or remove the integration.
- **A limit message blocks you from recreating the account**: clicking **Add new FTP-User** answers *The max. number of FTP users for your account is reached.* and the form never opens. Disabled accounts still occupy a slot, so deleting one you genuinely no longer need is the fix, not disabling another.
If you are not sure which FTP account a tool is using, or you need help checking what a departing developer left behind before you remove their access, open a support ticket with the Noiz support team. Include the website domain and the full FTP username as it appears in the **FTP-User** list under **Web Access**.
# How to Enable DKIM and DNSSEC for a Domain in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-enable-dkim-and-dnssec-for-a-domain-in-ispconfig/
This guide shows you how to switch on two signing features for a domain in the ISPConfig control panel: DKIM, which digitally signs the email your domain sends, and DNSSEC, which digitally signs the domain's DNS zone. DKIM is short for DomainKeys Identified Mail, and DNSSEC for Domain Name System Security Extensions; turning on DNSSEC is often described as "signing the zone". It is written for Noiz clients managing their own hosting account through ISPConfig. The two features are independent, so you can enable either one on its own, but they work well together and this guide covers both. DKIM matters for deliverability, because the large mailbox providers now expect a valid DKIM signature on the mail you send, and unsigned messages are far more likely to land in the spam folder or be rejected. DNSSEC protects the DNS answers themselves, so resolvers around the world can detect a forged or tampered reply for your domain.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual that describes the DKIM and DNSSEC fields.
- [My First Email (ISPConfig 3 Documentation)](https://docs.ispconfig.org/my-first-email/): the official walkthrough of the Email module, where the mail domain and its DKIM settings live.
- [DNS Basics (ISPConfig 3 Documentation)](https://docs.ispconfig.org/dns-basics/): the official primer on how the DNS module and DNS zones work in ISPConfig.
- [How to change the DNSSEC algorithm in ISPConfig 3 (FAQforge)](https://www.faqforge.com/linux/controlpanels/ispconfig3/how-to-change-dnssec-algorithm-in-ispconfig-3/): maintained by an ISPConfig core developer; explains the per-zone DNSSEC algorithm choice and how the DS data for the registry is generated.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- For the DKIM part, an email domain already exists on your account. If you have already [created an email mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/), the email domain is already in place.
- For the DNSSEC part, and for the DKIM DNS record to be published automatically, the domain's DNS zone must be hosted in the **DNS** module of ISPConfig on your Noiz account. If your DNS is hosted elsewhere, you can still enable DKIM and copy the record across by hand, but zone signing has to be done wherever the DNS is actually hosted.
- For DNSSEC you also need a way to publish DS data at the domain's registry: either access to the DNSSEC settings at your domain registrar, or, if the domain is registered through Noiz, a support ticket asking for the DS data to be published.
## Part 1: Enable DKIM for Your Mail Domain
DKIM works with a key pair. The private key stays on the mail server and adds a hidden signature to every message sent from your domain. The matching public key is published in DNS, where any receiving mail server can fetch it and confirm the signature is genuine. Alongside an SPF record, which lists the servers allowed to send for your domain, and a DMARC policy, which tells receivers what to do when a check fails, a passing DKIM signature is one of the strongest signals you can send that your mail is legitimate.
### Step 1: Open the DKIM settings
1. Log in to ISPConfig and click the **Email** module in the top navigation.
2. In the left-hand menu, under **Email Accounts**, click **Domain**. A list of your email domains appears.
3. Click the domain you want to sign mail for, for example the example domain `yourdomain.com`.
4. On the domain form, click the **DomainKeys Identified Mail (DKIM)** button below the main fields. The DKIM settings are collapsed behind it and stay hidden until you click it.
### Step 2: Generate the key and enable signing
1. Tick the **enable DKIM** checkbox.
2. Leave the **DKIM-Selector** field set to `default`, which is the value ISPConfig pre-fills. The selector names the key instance and becomes part of the DNS record name; you only need a different selector if you run more than one key for the same domain, for example when rotating keys. A selector must be lower-case letters and digits only, up to 63 characters, optionally followed by a dot and a second string of the same form.
3. Click the **Generate DKIM Private-key** button. After a moment, ISPConfig fills the **DKIM Private-key** field with a new key and the read-only **DNS-Record** field with the matching public record, and ticks **enable DKIM** for you if you have not already. The **DNS-Record** field holds a complete zone-file line rather than just the key: the record name, a TTL, `IN TXT`, and then the quoted value beginning `v=DKIM1`. If you already hold a DKIM key pair from a previous setup, you can paste the private key into the **DKIM Private-key** field instead of generating a new one.
4. Copy the contents of the **DNS-Record** field somewhere safe. You will need it in the next step if your DNS is hosted outside ISPConfig.
5. Click **Save**.
From this point on, the mail server signs every outgoing message from every mailbox on the domain automatically. Nothing changes for the people using the mailboxes; the signature travels invisibly in the message headers.
### Step 3: Publish the DKIM record in DNS
The signature only passes verification once the public key is available in DNS as a TXT record. Where you add that record depends on where the domain's DNS is hosted.
**If the DNS zone is hosted in ISPConfig on your Noiz account**, the record is added for you, provided the mail domain itself is set to **Active**. When ISPConfig recognises the zone as one it manages, a small link icon appears beside the **DNS-Record** label with the tooltip *Managed zone, dns updated automatically*. To confirm the record:
1. Click the **DNS** module in the top navigation, then click **Zones** under **DNS** in the left-hand menu.
2. Click the zone for your domain and open the **Records** tab.
3. Look in the **Name** column for a **TXT** record called `default._domainkey.yourdomain.com.`, with the trailing dot, whose data begins with `v=DKIM1`.
If the record has not appeared, you can add it with the built-in wizard. On the **Records** tab, click the **DKIM** button. Every field except **TTL** is read-only: the **Public-Key** and **DKIM-Selector** values are filled in automatically from the email domain settings. Click **Save** and the record is stored as a TXT record in the zone. The wizard refuses with *DKIM disabled for this mail-domain* if DKIM is not enabled on the email domain yet, and with *DNS-Record already exists* if the record is in fact already there.
**If the domain's DNS is hosted elsewhere**, log in to that DNS provider and create a TXT record with the host name `default._domainkey` (some providers want the full name, `default._domainkey.yourdomain.com`) and, as its value, the text from the **DNS-Record** field beginning with `v=DKIM1`.
### Step 4: Test the signature
1. Allow time for the DNS change to spread. A record in a Noiz-hosted zone is usually visible within minutes; records at outside providers can take up to 24 hours.
2. Send a message from a mailbox on the domain, using webmail or a mail program that sends through the Noiz mail server with SMTP authentication, to an address you control at one of the large mail providers.
3. Open the received message's full headers and find the `Authentication-Results` line. You want to see `dkim=pass` together with your domain name.
You can also use any online DKIM checker: give it your domain and the selector `default`, and it will confirm whether the public key record is visible.
## Part 2: Sign the DNS Zone with DNSSEC
DNSSEC adds digital signatures to the DNS zone itself, so a resolver can prove that the DNS answers it receives for your domain, including the mail and DKIM records you have just set up, have not been forged or altered on the way. Signing happens in two stages: first ISPConfig signs the zone on the name server, then you publish a small piece of data called a DS record at the domain's registry to complete the chain of trust. A signed zone without the DS record published is harmless, so you can enable signing safely and publish the DS data when you are ready. DNSSEC can be switched on per zone, and only for primary zones that ISPConfig hosts.
### Step 1: Turn on zone signing
1. Click the **DNS** module in the top navigation, then click **Zones** under **DNS** in the left-hand menu.
2. Click the zone for your domain. Zone names are listed with a trailing dot, for example `yourdomain.com.`, which is normal DNS notation.
3. On the **DNS Zone** tab, tick the **Sign zone (DNSSEC)** checkbox.
4. Check the **DNSSEC Algorithm** setting directly below it. This is a set of tick boxes rather than a single choice, and **13 (ECDSAP256SHA256)** is ticked by default, which is the algorithm you want. The other option, **7 (NSEC3RSASHA1)**, is based on the ageing SHA-1 hash and is best avoided; tick it only for the rare registry that cannot accept algorithm 13. Ticking both signs the zone under both algorithms and generates a separate key pair for each.
5. Click **Save**.
The server now generates the signing keys and signs the zone in the background. Watch for the small red change counter near the top of the panel, which you can click to see the outstanding changes listed; the work is normally finished within a few minutes of it clearing.
### Step 2: Copy the DS data for the registry
1. Go back to **Zones** and open the zone again.
2. On the **DNS Zone** tab, the read-only **DNSSEC DS-Data for registry** field now contains the data for the signed zone. It is laid out in two blocks: a `DS-Records:` block, which is the part the registry needs, and below a divider a `DNSKEY-Records:` block holding the public keys themselves. If the field is still empty, wait a few minutes and reopen the zone, because the data is produced by a background process on the server.
3. Copy the whole field. Registrars usually ask for the values from the DS lines: the key tag, the algorithm number (`13`), the digest type (`2`, meaning SHA-256) and the digest itself. The key-signing key is the entry marked `257`.
4. Publish the DS data at the domain's registry. If you manage the domain at an outside registrar, paste the values into its DNSSEC or DS record screen. If the domain is registered through Noiz, open a support ticket, paste in the full contents of the **DNSSEC DS-Data for registry** field, and ask for it to be published. The `.co.za` registry supports DNSSEC, as do most common domain extensions, but a few registries still do not; your registrar can confirm.
### Step 3: Verify the chain of trust
1. Wait for the registry to publish the DS record. This can take from a few minutes to a day, depending on the registrar.
2. Test the domain with an online DNSSEC analyser such as DNSViz (dnsviz.net) or a similar checker. A healthy setup is reported as secure, with an unbroken chain from the root zone down to your domain.
3. If you are comfortable with the command line, you can also query a validating resolver directly, replacing `yourdomain.com` with your own domain:
```
dig +dnssec yourdomain.com A
```
In the answer, the `ad` (authenticated data) flag in the header shows that the resolver validated the response against your DNSSEC signatures.
### Changing or disabling DNSSEC later
Once the DS record is published at the registry, the signatures in your zone must always match it. Never untick **Sign zone (DNSSEC)**, delete the zone, change the signing algorithm, or move the domain's DNS hosting elsewhere while the DS record is still published: validating resolvers across the internet would treat every answer for the domain as forged, and the domain would stop resolving for a large share of visitors. ISPConfig itself guards the checkbox, raising a confirmation dialog that explains what becomes of the existing keys before it will let you untick it; read that dialog rather than clicking past it. The safe order is always the reverse of setup. Remove the DS record at the registrar first, wait at least a day for resolvers to notice, and only then change the zone. The same applies before transferring the domain to another registrar or DNS host. If you are unsure, open a support ticket before changing anything.
## Troubleshooting
- **The DKIM fields cannot be edited**: the **DomainKeys Identified Mail (DKIM)** button is always on the mail domain form, so if nothing appears, click it again to expand the section. If the fields appear but are locked, your login may not have permission to change DKIM settings on this domain. Open a support ticket to have it checked.
- **DKIM is enabled but online checkers cannot find the record**: the DNS record has not been published yet or has not spread. Confirm the `default._domainkey` TXT record exists in the zone (Step 3 of Part 1), check you used the selector `default` in the checker, and allow up to 24 hours for records hosted at outside providers.
- **Received mail shows dkim=fail or no signature at all**: make sure the message was sent through the Noiz mail server with SMTP authentication. Mail sent through a third-party service, or by a website contact form using its own sending route, is not signed by this key. Also confirm **enable DKIM** is still ticked and the change was saved.
- **The DNSSEC DS-Data for registry field stays empty**: the signing process has not finished. Wait a few minutes and reopen the zone. If it is still empty after half an hour, untick **Sign zone (DNSSEC)**, click **Save**, wait for the change counter to clear, then tick it again and save, which is the sequence the official ISPConfig manual recommends for this. If the field remains empty, open a support ticket: the usual cause is the server running short of entropy while generating the keys, which has to be fixed server-side.
- **There is no Sign zone (DNSSEC) checkbox on the DNS Zone tab**: ISPConfig hides the entire DNSSEC block, checkbox, algorithm and DS-Data field alike, when the name server holding the zone has mirror servers configured. That is a property of the platform rather than of your account, so open a support ticket to ask whether the zone can be signed.
- **The registrar rejects the DS data**: some registries only accept certain algorithms or digest types, and a few domain extensions do not support DNSSEC at all. Ask the registrar which algorithms it accepts; if it cannot take algorithm 13, the zone can be re-signed with the older algorithm instead.
- **The domain stopped resolving for some visitors after a DNSSEC change**: the DS record at the registry no longer matches the keys the zone is served with. Unticking and re-ticking **Sign zone (DNSSEC)** will not repair it, because that re-signs with the keys already on the server and produces exactly the same DS data; what does change the keys is switching the algorithm, renaming the zone or deleting it. Open a support ticket straight away and include the current contents of the **DNSSEC DS-Data for registry** field.
If you get stuck at any point, open a support ticket with the Noiz support team and include the domain name, whether the problem is with DKIM or DNSSEC, and a copy of the **DNS-Record** or **DNSSEC DS-Data for registry** value from the panel.
# How to Fetch Email from an External Account into ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-fetch-email-from-an-external-account-into-ispconfig/
This guide shows you how to pull email from an external POP3 or IMAP account into a mailbox on your Noiz hosting account, using the **Fetchmail** feature in the ISPConfig control panel. This is useful when you are moving away from an old provider, or when you want messages from a secondary address (for example an old free webmail account) delivered into one central mailbox. ISPConfig calls this feature Fetchmail, and the form you fill in is called **Get Email**; behind the scenes ISPConfig uses a utility called getmail to do the retrieval, so you may see either name in error messages or documentation. A mailbox is sometimes called an email account, and the external account is sometimes called the source or remote account.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig official documentation](https://www.ispconfig.org/documentation/)
- [ISPConfig source: Get Email form definition (field list and protocol options)](https://git.ispconfig.org/ispconfig/ispconfig3/-/raw/3.3.1p1/interface/web/mail/form/mail_get.tform.php)
- [ISPConfig source: Get Email interface text (field labels and messages)](https://git.ispconfig.org/ispconfig/ispconfig3/-/raw/3.3.1p1/interface/web/mail/lib/lang/en_mail_get.lng)
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- A destination mailbox already exists on your Noiz hosting account. If not, first [create an email mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/).
- You have the connection details for the external account: the incoming mail server hostname (for example `mail.example-provider.com`, an example placeholder), the username, the password, and whether the provider offers POP3 or IMAP with SSL.
- Your hosting package allows at least one Fetchmail account. If ISPConfig reports that your limit is reached, contact the Noiz support team.
## Step 1: Open the Fetchmail section
1. Log in to ISPConfig and click the **Email** tab in the top navigation.
2. In the left-hand menu, scroll to the **Fetchmail** section and click **Fetchmail**.
3. The list page titled **Fetch emails from external POP3 / IMAP servers** opens. Any retrieval accounts you have already set up are listed here.
4. Click the **Add new Account** button.
## Step 2: Complete the Get Email form
The **Get Email** tab contains all the settings for one external account. Fill in the fields as follows.
### Connection details
1. In the **Type** field, select the protocol used to collect mail from the external account: `POP3`, `IMAP`, `POP3SSL` or `IMAPSSL`. Choose one of the SSL options whenever the external provider supports encrypted connections; almost all modern providers do. If you are unsure whether to pick POP3 or IMAP, POP3 is the simpler choice for a one-way transfer of the inbox.
2. In the **Pop3/Imap Server** field, enter the hostname of the external provider's incoming mail server, for example `mail.example-provider.com` (an example placeholder; your provider will publish the real hostname in its settings pages). Enter the hostname only, with no `https://` prefix and no port number. ISPConfig validates this field on save and rejects anything that is not a hostname or an IP address with the message *Pop3/Imap Server is not a valid domain name.*
3. In the **Username** field, enter the username for the external account. With most providers this is the full email address, for example `info@yourdomain.com`, but some providers use only the part before the @ sign. Use exactly what you would type into that provider's webmail or mail client.
4. In the **Password** field, enter the password for the external account.
### Retrieval options
1. **Delete emails after retrieval**: tick this if messages should be removed from the external account once they have been copied to your Noiz mailbox. ISPConfig shows a note beside the option: *Please check first if email retrieval works, before you activate this option.* Leave it unticked for your first test so nothing is removed from the source account until you have confirmed messages are arriving.
2. **Retrieve all emails (incl. read mails)**: when this is left unticked, only new, unread messages are collected. Tick this if you also want messages that have already been read, which is usually what you want when migrating an old inbox. ISPConfig will not accept this option on its own. Ticking it while **Delete emails after retrieval** is unticked fails on save with *Illegal combination of options. You can not use "Delete emails after retrieval" = no together with "Retrieve all emails" = yes*, because that pairing would collect every read message again on every run. Tick the two together, or leave both unticked for a first test.
3. In the **Destination** field, select the mailbox on your Noiz hosting account that should receive the collected messages.
4. Make sure the **Active** checkbox is ticked, then click **Save**.
## Step 3: Confirm that mail is being collected
1. After saving, the new entry appears in the list under **Email** > **Fetchmail** > **Fetchmail**, showing the external server, username and destination mailbox.
2. Retrieval runs on a schedule rather than instantly; the server checks the external account roughly every five minutes. Allow up to ten minutes for the first collection.
3. Send a test message to the external address, wait a few minutes, then check the destination mailbox in webmail or your mail client. The test message should arrive there.
4. Once you have confirmed retrieval works, you can safely edit the entry and tick **Delete emails after retrieval** if you want the external account emptied as messages are copied across. If you are migrating a whole inbox, tick **Retrieve all emails (incl. read mails)** in the same edit, since ISPConfig only accepts that option alongside **Delete emails after retrieval**.
To stop collecting mail temporarily, open the entry and untick **Active**. To remove it permanently, use the delete button next to the entry in the list view. Deleting the retrieval entry does not delete any messages already copied into your Noiz mailbox.
## Troubleshooting
- **No mail arrives in the destination mailbox**: first allow at least ten minutes, as retrieval runs on a schedule. Then check the **Pop3/Imap Server** hostname for typing errors, confirm the **Type** matches what the provider supports (an SSL type against a non-SSL port will fail, and the other way round), and verify the username and password by logging in to the external provider's webmail with the same details.
- **Saving fails with "Illegal combination of options"**: ISPConfig refuses to store **Retrieve all emails (incl. read mails)** ticked while **Delete emails after retrieval** is unticked, because that pairing would re-collect every read message on each run and fill the destination mailbox with duplicates. Tick both options, or untick **Retrieve all emails (incl. read mails)** so only new messages are collected.
- **Old, already-read mail is not being collected**: only new, unread messages are retrieved while **Retrieve all emails (incl. read mails)** is unticked. To migrate a whole inbox, tick **Retrieve all emails (incl. read mails)** and **Delete emails after retrieval** together, which is the only combination ISPConfig will save.
- **The external provider rejects the login even though the password is correct**: some large providers block ordinary POP3 or IMAP logins by default. You may need to switch on POP3 or IMAP access in that provider's settings, or generate an app password if the account uses two-step verification, then use the app password in the **Password** field.
- **The max. number of Fetchmail records for your account is reached**: your hosting package sets a maximum number of Fetchmail accounts, and you have used them all. Remove an unused entry, or contact the Noiz support team about raising the limit.
If you get stuck at any point, open a support ticket with the Noiz support team and include the external server hostname, the **Type** you selected and the destination mailbox address. Never include the external account's password in a ticket.
# How to Fix a Blank White Screen in ISPConfig After a Sury PHP Upgrade (Read-Only Temp Folder)
Source: https://docs.noiz.ie/ispconfig/how-to-fix-a-blank-white-screen-in-ispconfig-after-a-sury-php-upgrade-read-only-/
After upgrading PHP from the deb.sury.org repository, the ISPConfig control panel interface may return a completely blank white page. The browser shows no error, just an empty body. This article explains how to diagnose the fault, why standard permission checks show nothing wrong, and how to fix it properly with a one-line systemd override.
## Affected Environment
This issue was diagnosed and resolved on the following stack. The fix applies to any comparable ISPConfig host running PHP-FPM from deb.sury.org under systemd.
```
OS: Debian GNU/Linux 12 (bookworm)
Kernel: 6.1.0-50-amd64
PHP-FPM: PHP 8.2.32 (Sury build)
Web server: nginx 1.22.1
ISPConfig: 3.3.1p1
systemd: 252
```
To capture the equivalent details on your own host, run:
```
echo "OS: $(. /etc/os-release; echo "$PRETTY_NAME")"
echo "Kernel: $(uname -r)"
echo "PHP-FPM: $(php -v | head -n1)"
echo "Web server: $(nginx -v 2>&1 || apache2 -v 2>&1 | head -n1)"
echo "ISPConfig: $(cat /usr/local/ispconfig/interface/lib/config.inc.php 2>/dev/null | grep -oP "ISPC_APP_VERSION'\s*,\s*'\K[^']+" || echo unknown)"
echo "systemd: $(systemctl --version | head -n1)"
```
## Symptom
The ISPConfig interface, which listens on port 8080 by default, loads to a blank white page. No error is displayed in the browser, and the login page is blank as well, so the panel cannot be reached at all.
## Step 1: Find the Real Error
A white screen is a PHP fatal error with `display_errors` switched off. The actual error lives in the web server's error log, not the browser. First identify which web server owns port 8080:
```
ss -tlnp | grep ':8080'
```
Then read the matching log. If nginx is serving the panel:
```
tail -n 60 /var/log/nginx/error.log
```
If Apache:
```
tail -n 60 /var/log/apache2/error.log
```
The fatal error will read:
```
PHP Fatal error: Uncaught InvalidArgumentException: Please make sure the folder
'/usr/local/ispconfig/interface/lib/classes/IDS/../../../temp' is writable in
/usr/local/ispconfig/interface/lib/classes/IDS/Monitor.php:159
```
That path resolves to `/usr/local/ispconfig/interface/temp`. This is not the same directory as `/usr/local/ispconfig/interface/web/temp`, which is the browser-accessible download area ISPConfig uses for exports such as language files. The fix below applies to the first path only.
The ISPConfig interface runs a PHPIDS intrusion-detection layer on every panel request, and it needs a writable working directory there for its scratch files and its `ids.log`. The layer is controlled by `/usr/local/ispconfig/security/security_settings.ini`, ISPConfig's panel security configuration file, and it is switched on for anonymous visitors by default, which is why the login page itself is blank before any credentials are entered. The remote API at `/remote/` on the same port skips the layer, so an API endpoint that still answers while the panel is blank is a useful early confirmation of this fault. When PHPIDS cannot write, it throws an uncaught exception and PHP fatals, producing the blank page.
## Step 2: The Trap, Permissions Look Correct
The obvious next step is checking permissions, and this is where the issue misleads. Confirm the directory ownership, the FPM pool user, and SELinux status. On an nginx panel install the control panel has its own PHP-FPM pool, `ispconfig.conf`, written by the ISPConfig installer and kept separate from the website pools:
```
ls -ld /usr/local/ispconfig/interface/temp
grep -E '^\s*(user|group)\s*=' /etc/php/8.2/fpm/pool.d/ispconfig.conf
getenforce 2>/dev/null || echo 'no SELinux'
```
On an affected host, everything checks out: the directory is owned by `ispconfig:ispconfig` with owner write permission, the FPM pool runs as `ispconfig`, and SELinux is not in play. The owning user has write access on disk, which is why a plain `chown` or `chmod` does not fix it.
## The Cause: systemd Sandboxing
The write is blocked above the filesystem, by systemd. Recent deb.sury.org PHP-FPM packages ship the service unit with `ProtectSystem=full`. That directive gives the service its own mount namespace in which `/usr`, `/boot`, and `/etc` are remounted read-only. Because the ISPConfig temp directory sits under `/usr/local/`, PHP-FPM sees it as read-only inside its private namespace, regardless of the real on-disk permissions.
This is not an ISPConfig defect. The Sury packages changed the service unit hardening in a way that the application's expected temp path did not account for.
## Step 3: Prove It
Reproduce the read-only behaviour in isolation. This test creates a throwaway systemd unit with the same directive and cleans itself up:
```
systemd-run --pty --property=ProtectSystem=full touch /usr/local/ispconfig/interface/temp/systest
```
A response of `Read-only file system` confirms systemd sandboxing is the blocker.
## Step 4: The Fix
`ReadWritePaths=` is the designed exception to `ProtectSystem`. It re-opens one specific path for writing while leaving the rest of the service hardening intact. Add it as a drop-in override, matching the PHP version to the running FPM service:
```
install -d -m 0755 /etc/systemd/system/php8.2-fpm.service.d
cat > /etc/systemd/system/php8.2-fpm.service.d/override.conf << 'EOF'
[Service]
ReadWritePaths=/usr/local/ispconfig/interface/temp
EOF
systemctl daemon-reload
systemctl restart php8.2-fpm
```
A **restart** is required, not a reload. Namespace properties only apply when the service process is re-spawned.
## Step 5: Verify
```
systemctl show php8.2-fpm -p ReadWritePaths
curl -k -s -o /dev/null -w '%{http_code}\n' https://localhost:8080/index.php
```
The temp path should appear in the `ReadWritePaths` output, and curl should return `302` (a redirect to the login page), confirming PHP now executes cleanly through to ISPConfig's routing. The panel answers on http or https depending on the choice made when ISPConfig was installed, so use `http://` in the curl check if no SSL vhost was created for the interface. Hard-refresh the browser (Ctrl+Shift+R) and the white screen is gone.
## Why Not Just Weaken the Hardening?
Alternatives such as setting `ProtectSystem=false` or editing the packaged unit file directly would also restore write access, but both are worse options. Disabling `ProtectSystem` entirely removes a meaningful security layer from PHP-FPM, and edits to the packaged unit file are overwritten on the next package upgrade. The drop-in override with `ReadWritePaths=` makes the narrowest possible exception and keeps every other protection active.
## Durability and Future Maintenance
The override lives in `/etc/systemd/system/`, entirely outside the ISPConfig tree, so it survives ISPConfig updates. systemd merges drop-ins on top of the packaged unit rather than replacing it, so it also survives normal PHP point-release upgrades.
Three points warrant attention going forward:
- If a future Sury unit change restructures the service, the drop-in could stop taking effect. The command `systemctl show php8.2-fpm -p ReadWritePaths` is the one-line canary for that check.
- If the panel is moved to a newer PHP-FPM version (for example 8.3), the same override must be created for that version's unit, since drop-ins are per-service. On nginx installs ISPConfig records the service and directory it uses under **System > Server Config**, on the **Web** tab, in the **PHP-FPM init script** and **PHP-FPM pool directory** fields, so confirm both there before writing the drop-in.
- Extra PHP builds registered under **System > Additional PHP Versions** are offered to websites, not to the control panel. Those services do not need this override. Only the service running the panel's own `ispconfig.conf` pool does.
## Related Articles
- [How to Fix the DEB.SURY.ORG Expired Signing Key Error (EXPKEYSIG) on Debian](/ispconfig/how-to-fix-the-debsuryorg-expired-signing-key-error-expkeysig-on-debian/), another issue originating from the deb.sury.org PHP repository.
## Need Help?
If the panel remains blank after applying the fix, or the error in your web server log differs from the one described here, contact the Noiz support team with the log output and the details captured in the environment commands above. Note that assistance on self-managed servers may be billable depending on your support plan.
# How to Fix the DEB.SURY.ORG Expired Signing Key Error (EXPKEYSIG) on Debian
Source: https://docs.noiz.ie/ispconfig/how-to-fix-the-debsuryorg-expired-signing-key-error-expkeysig-on-debian/
If your Debian server uses the DEB.SURY.ORG PHP repository (standard on ISPConfig "perfect server" builds), you may encounter the following error when running `apt-get update`:
```
W: An error occurred during the signature verification. The repository is not updated and the previous index files will be used. GPG error: https://packages.sury.org/php bookworm InRelease: The following signatures were invalid: EXPKEYSIG B188E2B695BD4743 DEB.SURY.ORG Automatic Signing Key
W: Failed to fetch https://packages.sury.org/php/dists/bookworm/InRelease The following signatures were invalid: EXPKEYSIG B188E2B695BD4743 DEB.SURY.ORG Automatic Signing Key
W: Some index files failed to download. They have been ignored, or old ones used instead.
```
This article explains what the error means and how to resolve it correctly on a modern Debian system.
## What the Error Means
The DEB.SURY.ORG repository, maintained by Debian PHP maintainer Ondลej Surรฝ, is the de facto source for current PHP versions on Debian. Like all APT repositories, its packages are cryptographically signed, and your server verifies every update against the repository's public signing key.
`EXPKEYSIG` means **the signing key has expired**. GPG keys carry built-in expiry dates as a security practice, and the repository periodically rotates to a fresh key. When that happens, every server still holding the old key fails signature verification until the new key is installed.
Two important things to understand before fixing it:
- **This is not a compromise or an attack.** The repository is fine; your server simply holds an out-of-date copy of its public key.
- **Your server is not broken, but it is no longer updating PHP.** APT ignores the unverifiable repository and uses stale index files, which means no new PHP packages, including security updates, will be installed until the key is refreshed. Do not leave this unresolved.
## Step 1: Verify the Environment
Before changing anything, confirm how the repository is configured on this particular server. Check which sources file references the Sury repository:
```
grep -r "sury" /etc/apt/sources.list /etc/apt/sources.list.d/
```
Typical output on an ISPConfig Debian 12 (Bookworm) server:
```
/etc/apt/sources.list.d/php.list:deb [signed-by=/usr/share/keyrings/deb.sury.org-php.gpg] https://packages.sury.org/php/ bookworm main
```
Note the `signed-by=` path: that is the keyring file holding the expired key. Yours may differ slightly depending on how and when the repository was originally added. If there is no `signed-by=` option, the key was added to the legacy global keyring instead, which the fix below also handles.
## Step 2: Apply the Official Fix
The repository maintainer publishes a setup script that configures the repository and installs the current signing key. Re-running it on an existing installation refreshes the key:
```
curl -sSL https://packages.sury.org/php/README.txt | bash -x
```
The script detects your Debian version, installs the current signing keyring package, and rewrites the repository sources entry to reference it. The `-x` flag prints each command as it executes, so you can see exactly what the script does to the system.
Then refresh the package index:
```
apt-get update
```
The Sury repository line should now complete without GPG warnings.
## Alternative: Manual Key Installation
If you prefer not to pipe a remote script into a root shell (a reasonable position for any administrator), the signing key can be installed manually. The repository distributes its current keys as a Debian package:
```
curl -sSLo /tmp/debsuryorg-archive-keyring.deb https://packages.sury.org/debsuryorg-archive-keyring.deb
dpkg -i /tmp/debsuryorg-archive-keyring.deb
```
After installing the keyring package, check where it placed the key:
```
dpkg -L debsuryorg-archive-keyring | grep gpg
```
If the keyring path shown differs from the `signed-by=` path in your sources file (from Step 1), update the sources file to reference the new path, then run:
```
apt-get update
```
## Step 3: Verify the Fix
A successful `apt-get update` with no GPG warnings on the Sury lines confirms the new key is in place. To confirm pending PHP updates are now visible again:
```
apt list --upgradable 2>/dev/null | grep -i php
```
If PHP updates appear after a period of the repository being ignored, install them at the next maintenance window, as they may include security fixes that were silently skipped while the key was expired.
## What Not to Do
- **Do not use `apt-key`.** Older guides for this exact error recommend commands like `apt-key adv --fetch-keys https://packages.sury.org/php/apt.gpg`. The `apt-key` utility is deprecated and has been removed from Debian 12 (Bookworm). These instructions no longer work and date the guides that contain them.
- **Do not disable signature verification** (for example with `[trusted=yes]` in the sources file or `--allow-unauthenticated`). This silences the error by removing the security check entirely, leaving the server installing unverified packages indefinitely.
- **Do not simply remove the repository** to make the warning disappear. The installed PHP packages came from it; removing the repository freezes PHP at its current version with no further security updates.
## Why This Happens Periodically
Signing keys with expiry dates are deliberate: a key that expires limits the damage window if it is ever leaked, and forces regular rotation. The Sury repository has rotated its signing key several times over the years, and each rotation produces a wave of this exact error across every Debian server using the repository. It is routine maintenance, not an incident, but it does need to be actioned promptly on every affected server, since PHP security updates are silently skipped until the new key is installed.
Administrators managing multiple servers should apply the fix fleet-wide when it occurs, as every Debian server using this repository will be affected at the same time.
## Related Articles
- [How to Fix a Blank White Screen in ISPConfig After a Sury PHP Upgrade (Read-Only Temp Folder)](/ispconfig/how-to-fix-a-blank-white-screen-in-ispconfig-after-a-sury-php-upgrade-read-only-/) - another issue originating from the deb.sury.org PHP repository.
## Need Help?
If the error persists after following the steps above, or the output of the verification steps differs from what is described, contact the Noiz support team with the full output of `apt-get update` and the contents of your Sury sources file. Note that assistance on self-managed servers may be billable depending on your support plan.
# How to Harden PHP Settings for a Website in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-harden-php-settings-for-a-website-in-ispconfig/
This guide shows you how to tighten the PHP configuration of a single website in the ISPConfig control panel on your Noiz hosting account. It is aimed at self-managed server administrators, and at resellers whose accounts have been granted the website option tab, because both of the fields involved sit on a tab that client-level logins do not see. You will learn how to pick a PHP execution mode that supports per-site overrides, how to limit which directories PHP may touch using the **PHP open\_basedir** field, and how to switch off risky PHP functions and apply other protective directives through the **Custom php.ini settings** field on a website's **Options** tab. Throughout, "hardening" simply means reducing the number of things an attacker or a compromised script can do. The examples are written for current PHP 8.x, not the older PHP 5 and PHP 7 defaults you may find in older tutorials.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below. ISPConfig evolves between releases, so if a screen differs from this guide, check those links.
### Official Documentation Reference
- [ISPConfig 3 User Manual](https://www.ispconfig.org/documentation/user-manual/): the official manual; the website **Options** tab, the **PHP open\_basedir** field and the **Custom php.ini settings** field are described in section 4.6.1.1 (Website), and PHP execution modes are compared in the same chapter.
- [PHP manual: disable\_functions](https://www.php.net/manual/en/ini.core.php#ini.disable-functions): the official reference for the directive used to switch off individual PHP functions. It confirms this setting is `INI_SYSTEM` only, meaning it must be applied in the PHP configuration and cannot be re-enabled by a script or an `.htaccess` file.
- [PHP manual: open\_basedir](https://www.php.net/manual/en/ini.core.php#ini.open-basedir): the official reference for confining PHP file access to a set of directories.
- [PHP manual: where a configuration setting may be set](https://www.php.net/manual/en/configuration.changes.modes.php): explains the directive classes (`INI_USER`, `INI_PERDIR`, `INI_SYSTEM`, `INI_ALL`) that decide whether a setting can be changed per site at all.
- [PHP supported versions](https://www.php.net/supported-versions.php): the official list of PHP releases that still receive security fixes, so you can choose a version that is not end-of-life.
## Prerequisites
- You know how to [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- You sign in as the ISPConfig administrator, or as a reseller whose account has the website option tab enabled. Both hardening fields live on the website's **Options** tab, and that tab is not shown to client-level logins.
- You already have a website in ISPConfig. If not, see [how to create a website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/) first.
- You understand basic `php.ini` syntax, which is one `directive = value` per line, with `;` starting a comment.
- You have a way to test the site after each change, ideally a staging copy or a quiet maintenance window, because an over-strict setting can take a live site offline until you undo it.
- Server-wide changes, adding PHP versions and per-account permissions require administrator access. If you are a managed Noiz client, those are handled by the Noiz support team on request.
## How PHP settings reach your site in ISPConfig
Two facts decide whether a hardening directive will actually work, so it helps to understand them before you start.
- **The PHP mode controls whether per-site overrides are possible at all.** ISPConfig can run PHP in several modes. Only some of them let you feed custom `php.ini` values to one website. In particular, the **Custom php.ini settings** field works with Fast-CGI, CGI, SuPHP and PHP-FPM, but it does **not** work with Mod-PHP. If a site runs under Mod-PHP, you cannot harden it with this field until you switch its mode.
- **Some directives can only be set at PHP startup.** The most important hardening directive, `disable_functions`, is in the `INI_SYSTEM` class. According to the PHP manual it must live in the PHP configuration itself and cannot be set in an `.htaccess` file or turned back on by a running script. That restriction is exactly what makes it useful for security: once applied, a compromised plugin cannot lift it. ISPConfig writes the value into the site's own `php.ini` for Fast-CGI, or into the site's PHP-FPM pool as a `php_admin_value` for PHP-FPM, both of which honour `INI_SYSTEM` directives.
## Step 1: Choose a secure PHP mode
### Open the website and find the PHP setting
1. In the ISPConfig panel, go to **Sites**.
2. Under **Websites**, click the domain you want to harden, for example `yourdomain.com` (an example value).
3. On the **Domain** tab, find the **PHP** drop-down.
### Which mode to choose
On a modern Noiz platform the two practical choices are **PHP-FPM** and **Fast-CGI**. Older modes still appear for compatibility but are not suitable for hardening a website:
- **PHP-FPM (recommended).** Scripts run as the website's own Linux user rather than as the web server, more than one PHP version can be offered, and per-site overrides work through the **Custom php.ini settings** field. This is the best default for almost every site.
- **Fast-CGI.** Also supports the **Custom php.ini settings** field, writing your values into a php.ini that belongs to the site. A reasonable alternative on Apache.
- **Mod-PHP.** Avoid it for hardening. Scripts run with the web server's privileges, which weakens isolation, only one PHP version is possible, and the **Custom php.ini settings** field cannot be used at all. On a site that must stay on Mod-PHP the same values can only be applied through the **Apache Directives** field on the **Options** tab, using `php_admin_value` and `php_admin_flag`. Changing the mode to PHP-FPM is the better fix.
- **CGI, SuPHP and HHVM.** Legacy modes that still appear in the drop-down. CGI and SuPHP do accept custom php.ini settings but offer no advantage over PHP-FPM, and SuPHP is no longer maintained upstream. HHVM does not support every PHP function. There is no reason to choose any of them for a new configuration.
Select **PHP-FPM** (or **Fast-CGI**) and, on the same **Domain** tab, confirm the **SuEXEC** checkbox is ticked. That checkbox is an Apache-only option, so it will not be present on an nginx server. SuEXEC is what makes Fast-CGI and CGI scripts execute as the website's own user and group rather than as the web server, and the official guidance is to activate it for PHP-FPM, Fast-CGI and CGI alike. Leave the site open, because the version selector appears next.
### Choose a supported PHP version
When the mode is PHP-FPM or Fast-CGI, a **PHP Version** selector appears. Running an end-of-life PHP release is itself a security weakness, because it no longer receives fixes, so pick a version that is still supported.
1. Open the **PHP Version** drop-down.
2. Select a currently supported PHP 8.x release. Check the [PHP supported versions](https://www.php.net/supported-versions.php) page if you are unsure which releases still receive security updates.
3. Confirm your application supports that version before switching a live site, as a major version jump can require code or plugin updates.
If the version you need is not listed, a server administrator adds it under **System > Additional PHP Versions**. Managed Noiz clients can ask the Noiz support team to make an additional version available.
Click **Save** to apply the mode and version. ISPConfig rebuilds the site's configuration within roughly a minute.
## Step 2: Restrict file access with PHP open\_basedir
The **PHP open\_basedir** field confines PHP file operations, such as opening, reading, writing and deleting, to a set of directories. If a script is exploited, this stops it wandering into other parts of the file system. ISPConfig manages this for you and pre-fills the field from a server-wide template, which normally covers the site's own `web`, `private` and `tmp` directories plus a small set of shared system paths.
1. Still on the website, open the **Options** tab.
2. Find the **PHP open\_basedir** field.
3. In most cases, leave the pre-filled value in place. It already limits PHP to the site's own tree.
4. If the site genuinely needs access to an extra directory, add it to the existing value and separate paths with a colon (`:`). Do not remove the paths ISPConfig placed there, or the site may stop working.
5. Only if you deliberately need no restriction at all, type the single word `none`. Leaving the field empty does not disable it. Removing the restriction is not recommended.
Because `open_basedir` is an `INI_ALL` directive, it can also be tightened further inside your application if needed, but the panel field is the right place to set the site-wide boundary.
The template that fills the field is a server administrator setting, in a second **PHP open\_basedir** field under **System > Server Config** on the **Web** tab. It uses the placeholders `[website_path]` and `[website_domain]`, which ISPConfig expands per site. Changing it there changes the default for sites created afterwards, so it is the place to adjust if every site on the server needs the same extra path.
## Step 3: Add hardening directives in Custom php.ini settings
### Open the field
1. On the website's **Options** tab, scroll to **Custom php.ini settings**.
2. This is a free-text box that accepts ordinary `php.ini` syntax, one directive per line. Any PHP directive snippets an administrator has defined under **System > Directive Snippets** are listed as **Available PHP Directive Snippets** beside the box, and clicking a name inserts its contents at the cursor.
### A recommended baseline for PHP 8.x
The block below is a conservative starting point that improves security without breaking most common applications. Paste it into the **Custom php.ini settings** field and adjust to taste. Lines starting with `;` are comments.
```
; Do not reveal the PHP version in response headers
expose_php = Off
; Never show PHP errors to visitors on a live site; log them instead
display_errors = Off
log_errors = On
; Switch off the highest-risk shell and process functions
disable_functions = exec,passthru,shell_exec,system,proc_open,popen,pcntl_exec
; Harden session cookies (cookie_secure needs the site served over HTTPS)
session.cookie_httponly = 1
session.cookie_secure = 1
session.use_strict_mode = 1
session.cookie_samesite = "Lax"
```
Notes on the choices:
- `disable_functions` is the core of the hardening. The functions listed above let PHP run operating-system commands or spawn processes, which is rarely needed by normal web applications and is a favourite of injected malware. Because the directive is `INI_SYSTEM`, once ISPConfig applies it a compromised script cannot switch it back on.
- `session.cookie_secure = 1` tells browsers to send the session cookie only over HTTPS. Set it only if the site is served over HTTPS, which every Noiz site should be. If the site is still plain HTTP, secure that first, otherwise sessions will break.
- Keep `disable_functions` on a single line. If you list the directive twice, only the last line counts, so add all function names to one comma-separated list.
### Stricter options to test carefully
The following directives increase protection further but are more likely to break a specific application, so add them one at a time and test after each.
```
; Block PHP from opening or including remote URLs
; (allow_url_include is already Off by default; allow_url_fopen
; breaks apps that fetch remote URLs with file functions)
allow_url_fopen = Off
allow_url_include = Off
; Turn off uploads entirely if the site never accepts file uploads
file_uploads = Off
; A wider function block list; some backup and imaging plugins need
; a few of these, so remove any that your application actually uses
disable_functions = exec,passthru,shell_exec,system,proc_open,popen,pcntl_exec,show_source,proc_get_status,proc_nice,proc_terminate,dl,symlink,link
```
Do not paste the baseline `disable_functions` line and this wider one at the same time. Choose one list, since the later line would override the earlier one.
### Save and apply
1. Click **Save**.
2. Wait about a minute for ISPConfig to rewrite the site's PHP configuration and reload the PHP-FPM pool.
3. Load the website in a fresh browser tab and click through its main pages to confirm everything still works.
Note that if a server administrator later changes the global `php.ini`, those global changes do not reach a site that uses this field until the site's own configuration is rewritten. Saving any change to the website in ISPConfig does that. ISPConfig can also do it unprompted: a server setting called **Check php.ini every X minutes for changes**, under **System > Server Config** on the **Web** tab, re-reads the system php.ini files on that interval and rewrites the per-site files belonging to websites that carry custom settings. Setting it to `0` switches the check off.
## Step 4: Verify your settings took effect
Do not assume a directive is active just because you saved it. Confirm it.
1. Create a temporary file in the site's document root, for example `phpcheck.php`, containing only `
## For self-managed server administrators
If you run your own Noiz server with root access, you have additional levers beyond a single website:
- **Set safe defaults for every site.** Applying a baseline `disable_functions` and `expose_php = Off` in the global `php.ini` of each PHP version means new sites are hardened from the start, while the per-site **Custom php.ini settings** field is used only for exceptions. Apply it to the web-facing php.ini files only. Never put `disable_functions` in the command-line php.ini, because ISPConfig runs its own maintenance scripts through the CLI binary and stops working correctly if those functions are taken away from it.
- **Add and retire PHP versions** under **System > Additional PHP Versions**, so clients can move off end-of-life releases.
- **Remember the mode difference when checking your work.** For Fast-CGI the site's values are written to a per-site `php.ini` read at PHP startup; for PHP-FPM they are written into the site's pool as `php_admin_value` and `php_admin_flag` entries, which is why `INI_SYSTEM` directives such as `disable_functions` are enforced and cannot be relaxed by a script.
- **Test after every global change,** because a directive that is safe for one application can break another.
## Troubleshooting
- **The site shows a blank page or a 500 error after saving.** A directive is probably too strict. The usual culprit is an over-long `disable_functions` list that removed a function the application needs. Go back to the **Custom php.ini settings** field, shorten the list to the conservative baseline, save, and test again. Add functions back one at a time.
- **The Custom php.ini settings field does nothing.** Confirm the site's PHP mode is PHP-FPM, Fast-CGI, CGI or SuPHP. The field is ignored under Mod-PHP. Change the mode, save, then re-enter your settings.
- **A value shows in phpinfo but is not enforced.** Give ISPConfig a minute to rebuild the configuration, then reload. If a function still runs despite being in `disable_functions`, check the list is on a single line and not duplicated lower down, and that the site really is on PHP-FPM or Fast-CGI. If it still will not enforce, ask the Noiz support team to confirm the mode and PHP version on the server.
- **Sessions or logins stop working.** This often follows `session.cookie_secure = 1` on a site that is not served over HTTPS. Secure the site with a certificate, or remove that line until you have.
- **The Options tab is not there at all.** The tab is shown to the ISPConfig administrator, and to a reseller only when **Reseller can use the option-tab for websites** is ticked under **System > Interface Config** on the **Sites** tab. A client-level login never sees it, so such an account can still change the PHP mode and version on the **Domain** tab but cannot reach either hardening field. Managed Noiz clients should send the directives they want to the Noiz support team to apply.
- **You need a PHP version that is not in the list.** Additional versions are installed at server level. Managed Noiz clients should request the version they need from the Noiz support team.
If you get stuck, or you would like Noiz to review a hardening profile before applying it to a live site, open a support ticket with the Noiz support team. Include your domain name, the PHP mode and version the site is using, and the exact directives you added to the **Custom php.ini settings** field, so support can reproduce and check the behaviour quickly.
# How to Log In to the ISPConfig Control Panel
Source: https://docs.noiz.ie/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/
This guide shows you how to sign in to the **ISPConfig** control panel from any web browser. ISPConfig is the hosting panel Noiz uses for a range of services, and reaching the login page is the first step to managing your email, websites, databases and DNS.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** (the version running on Noiz servers). This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig official documentation](https://www.ispconfig.org/documentation/)
## Prerequisites
- A device with an internet connection and a modern web browser (for example Firefox, Chrome or Brave).
- Your ISPConfig server hostname or IP address, supplied by Noiz.
- Your ISPConfig login details (username and password), issued by Noiz. These may be admin, reseller or client credentials depending on your account.
## How to log in to ISPConfig
1. Have your login details ready
- Locate the server hostname (for example `panel.yourdomain.com`) or IP address (for example `203.0.113.10`) that Noiz gave you when your service was set up.
- If you do not have your username and password, request them from Noiz support at [info@noiz.co.za](mailto:info@noiz.co.za).
2. Open your web browser
- Launch a web browser on your computer, tablet or phone.
3. Enter the ISPConfig address
- In the address bar, type your panel address followed by the ISPConfig port, `8080`. Using your hostname this looks like `https://panel.yourdomain.com:8080/`, or using an IP address, `https://203.0.113.10:8080/`. Both forms reach the same panel, whatever your account type.
- Replace `panel.yourdomain.com` or `203.0.113.10` with the details Noiz gave you, then press **Enter** to load the login page.
- The port matters. ISPConfig does not run on the standard web port, so leaving off `:8080` will not reach the panel. Port `8080` is the ISPConfig default and is fixed when the panel is installed, so if the address Noiz gave you names a different port, use exactly what you were given.
- Keep the `https://` prefix so your username and password are encrypted on the way to the server.
4. Sign in
- Type your username (for example `admin`, a reseller username, or your client username) into the **Username** field. The form carries no separate labels: the words **Username** and **Password** sit inside the empty boxes and disappear as you type.
- Type your password into the **Password** field.
- Click **Login** to open the control panel.
- If two-factor authentication is switched on for your account, ISPConfig adds a **Two Factor Authentication** step and asks for the one-time code from your authenticator app, or for the code it emails you. Emailed codes expire after 10 minutes, and **Request new code** issues a fresh one.
Once you are in, bookmark the login address in your browser so you do not have to type the port each time. ISPConfig opens on the module set as your **Startmodule** and shows only the tabs for the modules enabled on your account, so a client account sees far fewer tabs than an administrator does. Sessions time out after a period the server administrator sets, so you may be asked to sign in again after a spell of inactivity. Where the login page offers a **Keep me logged in** tick box, it holds the session open even after you close the browser, so leave it clear on a shared or public computer.
## Troubleshooting
- **The login page will not load**: confirm the hostname or IP address with Noiz, check that you included `:8080`, and make sure your network or firewall is not blocking that port.
- **Your browser shows a certificate or security warning**: confirm the address begins with `https://` and that you are connecting to the correct server. If Noiz has secured your panel with a valid certificate you should not see a warning, so if one appears, contact support before continuing rather than dismissing it blindly.
- **A maintenance notice appears instead of the login form**: an administrator has put ISPConfig into maintenance mode, which is normal during an upgrade and signs out everyone except administrators. Wait a short while and try again.
- **You have forgotten your password**: if a **Password lost** button sits beside **Login**, click it and supply the email address and username held on your client record. The two must match, and the reset only runs when the lost password option is enabled on your account. ISPConfig emails a confirmation link and issues the new password only after you follow it. The `admin` account cannot use this route, so for an administrator login contact [info@noiz.co.za](mailto:info@noiz.co.za) and Noiz will help you regain access.
- **Login is rejected repeatedly**: ISPConfig counts failed attempts against the IP address they come from, and once there have been more than five in quick succession it answers with a too many failed login attempts message instead of checking your password. Stop trying, wait a few minutes, and the count clears on its own. Repeated failures can also get your address blocked at the server itself, so see the related article below if the login page stops loading altogether.
## Related articles
- [Understanding ISPConfig User Levels: Admin, Reseller, and Client](/ispconfig/understanding-ispconfig-user-levels-admin-reseller-and-client/) explains what each account type can do once you are signed in.
- [How to Change Your ISPConfig Password and Interface Language](/ispconfig/how-to-change-your-ispconfig-password-and-interface-language/) covers updating your password after your first login.
- [What to Do If Your IP Address Is Blocked by an ISPConfig Server](/ispconfig/what-to-do-if-your-ip-address-is-blocked-by-an-ispconfig-server/) helps if you cannot reach the login page at all.
If you are on a managed Noiz plan and cannot reach your ISPConfig panel, contact Noiz support at [info@noiz.co.za](mailto:info@noiz.co.za) and the team will confirm your login address and check the server for you.
# How to Manage DNS Records in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-manage-dns-records-in-ispconfig/
This guide shows you how to add and edit DNS records in the ISPConfig control panel, covering the six record types you are most likely to need: A, AAAA, CNAME, MX, TXT and SRV. It also explains how to choose a sensible TTL and what to expect from DNS propagation once you save a change. It is written for Noiz clients whose domain already has a DNS zone in ISPConfig. A DNS zone is simply the collection of DNS records for one domain, and individual records are sometimes called zone entries or DNS entries.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**, the version Noiz runs. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [DNS Basics (ISPConfig 3 Documentation)](https://docs.ispconfig.org/dns-basics/): the official explanation of how DNS resolution works and where ISPConfig fits in.
- [Record type CNAME (ISPConfig 3 Documentation)](https://docs.ispconfig.org/modules/dns/record-type-cname/): the official walkthrough of adding a record on the zone's **Records** tab, including the trailing dot rule.
- [Setting up your own name service (DNS) with ISPConfig (HowtoForge)](https://www.howtoforge.com/tutorial/setting-up-your-own-name-service-with-ispconfig/): the DNS tutorial published by the ISPConfig developers, covering zones, records and testing.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- An existing DNS zone for your domain in the **DNS** module. If the module is empty, the zone for your domain is managed elsewhere, and changes you would like made should go through a support ticket instead.
- Your domain must actually use the nameservers that host this zone. If your registrar points the domain at different nameservers, records edited here have no effect on the live domain.
- The exact values for the record you want to add, for example an IP address from a service provider or a verification string from an email or search service.
## Open the DNS Zone for Your Domain
1. Log in to the ISPConfig control panel.
2. Click the **DNS** module in the top navigation.
3. In the left menu, under **DNS**, click **Zones**. A list of the DNS zones on your account appears. Zone names are shown with a trailing dot, for example `yourdomain.com.`, which is normal DNS notation.
4. Click the zone you want to edit. The zone opens on the **DNS Zone** tab, which holds the zone-wide settings. Leave those alone for day-to-day record changes.
5. Click the **Records** tab.
The **Records** tab lists every record in the zone in six columns: **Active**, **Type**, **Name**, **Data**, **Priority** and **TTL**. Each column has a filter box above it, which is worth using on a large zone. Across the top of the list is a row of buttons, one per record type, including **A**, **AAAA**, **CNAME**, **MX**, **TXT** and **SRV**. You will also see buttons for less common types such as ALIAS, CAA, NS, PTR, SPF, DMARC and TLSA; this guide covers the six you are most likely to need.
## Understand the Common Record Fields
Every record form shares a few fields, and one convention trips up almost everyone, so read this section before adding your first record.
- **Hostname**: the name the record describes. You can enter either a short name or a fully qualified name, and the difference matters:
- A short name without a trailing dot is relative to the zone. Entering `www` in the zone for `yourdomain.com` creates a record for `www.yourdomain.com`.
- A fully qualified name must end with a dot, for example `shop.yourdomain.com.` If you leave the dot off a fully qualified name, ISPConfig appends the zone to it and you end up with a broken name such as `shop.yourdomain.com.yourdomain.com`.
- Leaving the field empty means the record applies to the domain itself, `yourdomain.com`. Wildcards are supported on most record types, written as `*` or `*.sub`. SRV records are the exception and do not accept them.
- **TTL**: the time to live in seconds, which tells resolvers how long they may cache the record. The form is pre-filled with `3600` (1 hour). The lowest value ISPConfig accepts is `60`; anything smaller is refused with *Min. TTL time is 60 seconds*. See the TTL guidance section below before changing it.
- **Active**: whether the record is published. Unticking it removes the record from the live zone without deleting it, which is handy for testing.
## Add a New Record
On the **Records** tab, click the button for the record type you need, fill in the form and click **Save**. The sub-sections below describe each type.
### A Record: Point a Name at an IPv4 Address
An A record maps a hostname to an IPv4 address. Use it to point your domain, or a subdomain, at a web server.
1. Click the **A** button.
2. In the **Hostname** field, enter the name, for example `www`, or leave it empty for the domain itself.
3. In the **IP-Address** field, enter the IPv4 address, for example `203.0.113.10` (an example address; use the one you were given).
4. Leave **TTL** at `3600` unless you have a reason to change it, keep **Active** ticked and click **Save**.
### AAAA Record: Point a Name at an IPv6 Address
An AAAA record is the IPv6 equivalent of an A record. The form is identical except that the address field is labelled **IPv6-Address** and takes an IPv6 value, for example `2001:db8::10` (an example address). A name can have both an A and an AAAA record at the same time; clients on IPv6 networks will prefer the AAAA record.
### CNAME Record: Make One Name an Alias of Another
A CNAME record makes a hostname an alias for another name, so it always follows wherever the target points. Use it for names like `blog.yourdomain.com` that should track another hostname, including hostnames provided by external services.
1. Click the **CNAME** button.
2. In the **Hostname** field, enter the alias, for example `blog`.
3. In the **Target Hostname** field, enter the name it should point to. For a fully qualified target the trailing dot is essential, for example `sites.exampleservice.net.` ISPConfig checks this on save: a target without the trailing dot must already exist as a record in the same zone, otherwise the save is refused with *Target hostname not found in the current zone. It should end in a . when it's external.*
4. Click **Save**.
ISPConfig enforces two CNAME rules that catch people out:
- A CNAME cannot share a hostname with any other record. Adding one where another record already exists is refused with *A CNAME record already exists for this hostname. CNAME records cannot coexist with other record types at the same hostname.*
- A CNAME cannot be used on the bare domain. Leaving **Hostname** empty, or entering `@` or the zone name, is refused with *CNAME records are not allowed at the zone apex (empty hostname). Use an ALIAS record instead, or specify a subdomain hostname.* For the bare domain, use an A or AAAA record pointing at the address the service gives you.
### MX Record: Route Email for the Domain
MX records tell other mail servers where to deliver email for your domain. Edit these only when you are deliberately moving email, for example to or from an external email service, because a wrong MX record stops mail arriving.
1. Click the **MX** button.
2. Leave the **Hostname** field empty (or enter `yourdomain.com.` with the trailing dot) so the record applies to addresses of the form `user@yourdomain.com`.
3. In the **Mailserver hostname** field, enter the hostname of the mail server, for example `mail.yourdomain.com.` with the trailing dot. This must be a hostname with its own A (or AAAA) record. It must not be a CNAME, and it cannot be a bare IP address.
4. In the **Priority** field, enter a number. ISPConfig pre-fills `10`, and values are conventionally between `0` and `100`. Lower numbers are preferred, so if you have two MX records, the one with the lower priority value receives mail first and the other acts as a fallback.
5. Click **Save**.
### TXT Record: Verification Codes and Other Text
A TXT record attaches a free-text string to a hostname. The most common use is an ownership verification string issued by an email, search or analytics service.
1. Click the **TXT** button.
2. In the **Hostname** field, enter the name the service asked for. Leave it empty for the domain itself, or enter a name such as a selector label if the service specifies one. Underscore names are accepted here.
3. In the **Text** field, paste the string exactly as supplied, for example a verification code such as `example-site-verification=abc123`. Do not add a trailing dot here, and do not add surrounding quotation marks unless the service explicitly includes them.
4. Click **Save**.
A domain can have many TXT records, so add a second one rather than overwriting an unrelated value.
#### SPF, DMARC and DKIM Have Their Own Buttons
SPF, DMARC and DKIM records are all published as TXT records in the zone file, but ISPConfig will not let you type them into the TXT form. The **Text** field rejects anything containing `v=spf`, `v=DMARC1;` or `v=DKIM`, with a message telling you to use the matching button instead, for example *SPF is not allowed. Use the SPF button.*
Use the **SPF**, **DMARC** and **DKIM** buttons on the **Records** tab instead. Each opens a guided form rather than a free-text box. The SPF form, for example, builds the policy from tick boxes and lists: an **SPF Mechanism** choice covering Pass, Fail, SoftFail and Neutral, options to allow the domain's MX servers and its current A record address, and separate fields for additional IP addresses in CIDR format, other hostnames and other domains. It shows the finished record in a read-only **SPF-Record** field before you save.
These forms also guard against duplicates, which matters because more than one SPF record on a name makes the policy invalid and gets your mail rejected. If a record already exists, ISPConfig offers to edit it rather than adding a second one. If duplicates already exist it refuses outright and asks you to delete or merge them first. If you open an existing TXT record whose value starts with `v=spf1`, ISPConfig sends you to the SPF form automatically.
### SRV Record: Publish the Location of a Service
SRV records advertise the server, port and priority for a specific service, and are required by protocols such as SIP telephony, XMPP messaging and some autodiscovery systems. The service you are configuring will tell you the exact values to use.
1. Click the **SRV** button.
2. In the **Hostname** field, enter the service and protocol labels, for example `_sip._tcp`. Each label starts with an underscore; a short form like this is relative to the zone.
3. In the **Target** field, enter the hostname of the machine providing the service, for example `sipserver.yourdomain.com.` with the trailing dot for a fully qualified name.
4. In the **Weight** field, enter the relative weight used to share load between records of equal priority. If you only have one record, `0` is fine.
5. In the **Port** field, enter the TCP or UDP port of the service, for example `5060`.
6. In the **Priority** field, enter the preference for this target, commonly between `0` and `100`. As with MX records, lower values are preferred.
7. Click **Save**.
**Priority**, **Weight** and **Port** must each be between `0` and `65535`. Weight only comes into play between records that share the same priority: given two records at priority `10` with weights `60` and `40`, clients send roughly 60 per cent of requests to the first and 40 per cent to the second. A third record at priority `20` would be used only if both of the others failed.
## Edit, Deactivate or Delete an Existing Record
- **Edit**: on the **Records** tab, click the record in the list. The same form opens with its current values; change what you need and click **Save**.
- **Deactivate**: open the record, untick **Active** and click **Save**. The record disappears from the live zone but stays in the list so you can re-enable it later.
- **Delete**: click the delete icon at the end of the record's row and confirm. Deleting is permanent, so if you are unsure, deactivate the record first and confirm nothing breaks.
## Choosing Sensible TTL Values
The TTL controls how long resolvers around the world may cache a record before asking for it again. It is a trade-off: high TTLs mean fast, resilient lookups but slow changes; low TTLs mean quick changes but more queries.
- `86400` (24 hours): right for stable records that rarely change, such as MX records and the main A record of a settled website.
- `3600` (1 hour): what ISPConfig pre-fills, and a sensible choice for records you adjust from time to time.
- `300` (5 minutes): useful temporarily around a planned change. The day before moving a website or mail service, lower the TTL of the affected records to `300`, wait for the old TTL to expire, make the change, confirm everything works, then raise the TTL again.
- `60` (1 minute): the lowest value ISPConfig will accept. Do not leave a record here permanently, because every expiry costs another lookup. A TTL of `0` is not an option; the form refuses it.
## Check Your Changes and Allow for Propagation
Saving a record does not update the nameserver instantly. ISPConfig queues the change and shows a pulsing red counter near the top right of the panel while work is pending. Click it and a panel opens headed *The following changes are not yet populated to all servers*, listing what is outstanding, for example **Create DNS record** or **Update DNS zone**. ISPConfig's own guidance is that storing updates can take up to a minute. The counter disappears once the zone has been rewritten on the nameserver.
After that, propagation takes over. Resolvers that have never seen the record pick it up immediately, but any resolver that cached the old value keeps serving it until the previous TTL expires. In practice most of the internet sees a change within the old TTL, and the commonly quoted worst case is 24 to 48 hours.
You can check what the world sees from any computer with these commands, replacing `yourdomain.com` with your own domain:
```
dig yourdomain.com A +short
dig yourdomain.com MX +short
dig yourdomain.com TXT +short
```
On Windows, `nslookup` does the same job:
```
nslookup -type=A yourdomain.com
nslookup -type=MX yourdomain.com
nslookup -type=TXT yourdomain.com
```
To bypass caches and query the zone's own nameserver directly, first list the domain's nameservers with `dig yourdomain.com NS +short`, then repeat the lookup against one of them, for example `dig yourdomain.com A @ns1.yourdomain.com +short` (substitute the actual nameserver hostname returned). If the authoritative answer is correct, the record itself is right and any stale result elsewhere is just caching that will expire on its own.
## Troubleshooting
- **Symptom**: a newly saved record does not resolve at all. Wait a couple of minutes for the red change counter in the panel to clear, then check that **Active** is ticked on the record and that the zone itself is active on the **DNS Zone** tab.
- **Symptom**: a lookup returns a doubled name such as `shop.yourdomain.com.yourdomain.com`. A fully qualified name was entered without its trailing dot, so the zone was appended to it. Edit the record and add the dot, or use the short form instead.
- **Symptom**: email stops arriving after an MX change. Open the MX record and confirm the **Mailserver hostname** points to a hostname that has an A record, not a CNAME and not an IP address, and that the trailing dot is present on a fully qualified value. Also confirm no stray second MX record points somewhere obsolete.
- **Symptom**: the old value keeps coming back on some networks. This is TTL caching, not a fault. Query the authoritative nameserver directly as shown above; if it returns the new value, the change is live and cached copies will expire by themselves.
- **Symptom**: changes in ISPConfig never affect the live domain. The domain is probably delegated to different nameservers at the registrar, so the zone you are editing is not the one the world reads. Check the delegation with `dig yourdomain.com NS +short` and raise a ticket if the result looks wrong.
If you get stuck at any point, open a support ticket with the Noiz support team and include your domain name, the record type and exact values you are trying to set, and a screenshot of the zone's **Records** tab.
# How to Migrate Maildir Emails from a Plesk Server to an ISPConfig Server
Source: https://docs.noiz.ie/ispconfig/how-to-migrate-maildir-emails-from-a-plesk-server-to-an-ispconfig-server/
This guide walks you through migrating Maildir email accounts from a Plesk source server to an ISPConfig destination server, moving all email data (user mailboxes, folders, and read/seen state) across intact. It is an administrator-level procedure intended for server operators performing a platform migration at the shell, not a client-area task.
The workflow is the same in both directions: stop the mail services, copy the Maildir tree with `rsync`, correct ownership, restart Dovecot, and reindex. Two approaches are covered: migrating users one at a time (best for small moves or a first test run), and a bulk pass that migrates every mailbox under a domain in a single loop.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** and Plesk Obsidian **18.0.x** on Debian GNU/Linux 12 (bookworm), with Dovecot as the destination IMAP server. This guide is written for Noiz hosting and is kept current against ISPConfig and Dovecot. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [ISPConfig Documentation](https://www.ispconfig.org/documentation/) (mail domains, mailboxes, and the remote API)
- [Dovecot Documentation](https://doc.dovecot.org/) (`doveadm index`, `doveadm quota`, and Maildir handling)
- [rsync manual page](https://download.samba.org/pub/rsync/rsync.1) (transfer flags, ownership mapping, and exclusions)
## Prerequisites
Before you begin, make sure the following assumptions and preparations are in place:
- The commands below assume Debian GNU/Linux 12 (bookworm), Plesk Obsidian on the source server, and ISPConfig 3.3.1p1 on the destination server. Different distributions or major versions may need adjusted paths.
- Every destination mailbox must already exist in ISPConfig **before** you copy any data. Create each one through the ISPConfig control panel (or via the remote API) so the database records and on-disk directory structure (`/var/vmail/domain/user`) are in place. Copying data into a mailbox that ISPConfig does not know about will not authenticate, because the matching row in the `mail_user` table is missing.
- The paths and ownership used below are the ISPConfig defaults. Confirm them for your own server under **System > Server Config > Mail**, which holds **Maildir Path** (default `/var/vmail/[domain]/[localpart]`), **Homedir Path** (default `/var/vmail`), and **Mailuser Name** and **Mailuser Group** (both default `vmail`). **Maildir Path** is the mailbox home; Dovecot keeps the messages themselves in a `Maildir` subdirectory of it, which is why the ownership commands below target `/var/vmail/test.co.za/test/Maildir` rather than the home itself. The same tab holds **POP3/IMAP Daemon**, which ISPConfig can set to either Courier or Dovecot: the `doveadm` steps below apply only where it is set to **Dovecot**.
- You have shell (SSH) access as `root` to the destination server and a login on the source server, ideally with SSH key authentication configured between the two so `rsync` and `ssh` run without interactive password prompts.
- Replace the example Linux usernames (for example `source`, `root`) and hostnames (for example `plesk`, `ispconfig.test.co.za`) with your own server-specific identifiers.
- Replace the example domain name `test.co.za` with your actual domain throughout every command and path.
## Section 1: Migrating Individual Users (One by One)
Here you migrate a single user at a time, which makes verification and troubleshooting easier. Use this approach for smaller moves, or run it once as a test before committing to a bulk migration.
1. **Stop the mail services.** Freezing both ends prevents new mail arriving mid-copy and prevents index corruption.
- On the source (Plesk) server: `systemctl stop qmail`
- On the destination (ISPConfig) server: `systemctl stop dovecot`
2. **Copy the Maildir with rsync.** Run this from either end, whichever has the cleaner network path. The `--chown=vmail:vmail` flag maps ownership to the Dovecot mail user on arrival.
- **Push from the source (Plesk) shell:** `rsync -avz --chown=vmail:vmail --exclude '@attachments' /var/qmail/mailnames/test.co.za/test/ root@ispconfig.test.co.za:/var/vmail/test.co.za/test/` Replace `root@ispconfig.test.co.za` with the actual destination login and hostname or IP.
- **Pull from the destination (ISPConfig) shell:** `rsync -avz --chown=vmail:vmail --exclude '@attachments' source@plesk:/var/qmail/mailnames/test.co.za/test/ /var/vmail/test.co.za/test/` Replace `source@plesk` with the source login and hostname or IP.
3. **Start the mail service.** On the destination (ISPConfig) server: `systemctl start dovecot`. Dovecot now sees the freshly copied Maildir.
4. **Reindex the mailbox.** Rebuild the Dovecot indices so the transferred messages are searchable and consistent: `doveadm -v index -u test@test.co.za '*'` This aligns the indices with the copied data and clears most access glitches that appear immediately after a transfer.
5. **Verify.**
- **Watch the log:** `tail -f /var/log/mail.log`
- **Test IMAP login** for `test@test.co.za` with a mail client or webmail and confirm the folders and message counts match the source.
- **Fix ownership and permissions** only if you see permission-denied errors: `chown -R vmail:vmail /var/vmail/test.co.za/test/Maildir chmod -R u+rwx /var/vmail/test.co.za/test/Maildir` These give the `vmail` user full access to the Maildir tree.
### Downtime Tip: Pre-sync, Then Final Sync
To keep mailboxes reachable for as long as possible, run the `rsync` in step 2 once **while both services are still running**. That first pass copies the bulk of the data. Then stop the services and run the identical `rsync` again: because rsync only transfers what has changed, the second pass is fast, so the actual downtime window shrinks to seconds or minutes rather than the full copy time.
### Notes on Special Maildir Files
- **Excluding `@attachments`:** The `@attachments` directory belongs to Plesk's webmail interface and holds temporary attachment files. It plays no part in email delivery on ISPConfig and can cause clutter or permission conflicts if copied, so `--exclude '@attachments'` keeps the migration focused on the mail itself.
- **`maildirfolder` and `maildirsize`:** `maildirfolder` is a Dovecot marker file used for folder organisation and access; `maildirsize` records the mailbox quota usage. Both may travel across with the data, and Dovecot will regenerate or adjust them during reindexing to match the destination. There is no need to delete them. If quotas look wrong afterwards, check with `doveadm quota get -u test@test.co.za` and correct the quota value in ISPConfig if needed.
### Repeat for Other Users
Apply the same steps to each additional user by changing the paths (replace `test` with the next username under `/var/qmail/mailnames/test.co.za/`) and updating the email address in the `doveadm` command.
## Section 2: Migrating All Users in Bulk
This section migrates every mailbox under `/var/qmail/mailnames/` on the source server in one pass. It assumes every email domain and mailbox already exists in ISPConfig (created in the panel or through the remote API), so the destination directories and authentication records are ready before any data moves.
**Account existence is mandatory.** Without a pre-existing ISPConfig account, rsync writes into a directory the mail system cannot authenticate against, because there is no matching row in the `mail_user` table. To prepare:
- Recreate every email domain and mailbox in the ISPConfig panel under **Email > Email Accounts > Domain** and **Email > Email Accounts > Email Mailbox**, replicating the source settings (quotas, aliases, and so on). The **Quota** field on the mailbox form is in MB.
- For large lists, use the ISPConfig remote API from a script (for example PHP calling `mail_user_add`) to add users in bulk. Create the API login first under **System > User Management > Remote Users**, and tick every call the script makes in the **Functions** list, for example `mail_domain_add` and `mail_user_add`. Calls to functions that are not ticked are refused.
1. **Stop the mail services.**
- On the source (Plesk) server: `systemctl stop qmail`
- On the destination (ISPConfig) server: `systemctl stop dovecot`
2. **Bulk rsync (run from the destination shell).** Loop over every user directory for the domain: `for user in $(ssh source@plesk "ls /var/qmail/mailnames/test.co.za/"); do rsync -avz --chown=vmail:vmail --exclude '@attachments' source@plesk:/var/qmail/mailnames/test.co.za/$user/ /var/vmail/test.co.za/$user/ done` Replace `source@plesk` with the source login, and nest a second loop over domains if you are migrating more than one.
3. **Bulk fix ownership and permissions.** `for user in $(ls /var/vmail/test.co.za/); do chown -R vmail:vmail /var/vmail/test.co.za/$user/Maildir chmod -R u+rwx /var/vmail/test.co.za/$user/Maildir done`
4. **Bulk reindex (assumes usernames match directory names).** `for user in $(ls /var/vmail/test.co.za/); do doveadm -v index -u $user@test.co.za '*' done`
5. **Start the mail service.** On the destination (ISPConfig) server: `systemctl start dovecot`.
6. **Verify.** Watch `/var/log/mail.log` with `tail -f`, and test IMAP login for a sample of migrated accounts. See the notes in Section 1 for the behaviour of `@attachments`, `maildirfolder`, and `maildirsize`.
## Troubleshooting
- **Login fails after migration**: the mailbox was not created in ISPConfig before the copy. Create it in the panel (or via the API), then rerun the rsync and reindex for that user.
- **Permission denied reading mail**: ownership was not mapped to `vmail`. Rerun the `chown -R vmail:vmail` and `chmod -R u+rwx` commands against that mailbox's `Maildir`.
- **Messages or folders missing in the client**: the indices are stale. Rerun `doveadm -v index -u user@test.co.za '*'`, then reconnect the client.
- **Quota reported incorrectly**: check the live figure with `doveadm quota get -u user@test.co.za`, compare it against the panel report under **Email > Statistics > Mailbox quota** (that report is produced only for Dovecot, not for Courier), and correct the **Quota** value on the mailbox under **Email > Email Accounts > Email Mailbox**.
Migrations of this kind sit on Noiz managed platforms and are ordinarily carried out by the Noiz team as part of a move onto Noiz hosting. If you are moving mail onto Noiz and would like the migration handled or checked over, open a ticket from your Noiz client area and support will assist.
# How to Monitor Website Usage and Logs in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-monitor-website-usage-and-logs-in-ispconfig/
This guide shows you how to keep an eye on how a website on your Noiz hosting account is being used, and how to read its logs, all from the ISPConfig control panel. You will learn where to find traffic figures (sometimes called bandwidth or usage), disk space usage (also called quota or webspace), the raw web server logs (the access log and error log), and the daily visitor statistics reports produced by AWStats, GoAccess or Webalizer. It is written for Noiz clients managing a website through ISPConfig. The final section covers the Monitor module, which shows server-wide health and system logs and is only available if you log in with a server administrator account, as you would on a self-managed Noiz server.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**, the version Noiz runs. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [Site Statistics (ISPConfig Documentation)](https://docs.ispconfig.org/creating-web-sites/site-statistics/): the current guide to enabling website statistics reports and viewing them at the site's stats address.
- [ISPConfig User Manual](https://www.ispconfig.org/documentation/user-manual/): the official manual, whose Statistics and Monitor chapters document these screens field by field.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- At least one website on your account. If you have not created one yet, see [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/).
- To download the raw log files, an FTP or SFTP client such as FileZilla or WinSCP, and the FTP or shell login details for the website.
- To use the Monitor module, a server administrator login. Standard shared hosting client logins do not show the Monitor module, and that is normal.
## What You Can Monitor
ISPConfig gives you four different views of how a site is being used, and it helps to know which one answers which question:
- **Usage tables** under the **Sites** module **Statistics** menu: read-only figures for web traffic, FTP traffic, disk quota and database quota.
- The **Statistics** tab on an individual website: where you switch on the daily visitor statistics reports and set their password.
- The **stats** reports themselves, produced once a day by AWStats, GoAccess or Webalizer and viewed in a browser.
- The **raw web server logs** (the access log and error log), downloaded from the website's `log` directory over FTP or SFTP.
Each of these is covered in its own section below.
## View Traffic and Quota in the Statistics Menu
The **Statistics** menu shows read-only usage figures for every website on your account. There is nothing to configure here; the panel simply reports the numbers.
### Open the Statistics Menu
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, find the **Statistics** section and click the item you want to view, such as **Web traffic**.
### Web Traffic
Under **Web traffic** you see the traffic served by your websites, in megabytes, for the current month, the previous month, the current year and the previous year, with a total row at the foot of the table adding up every site. These figures are close to live: ISPConfig updates them roughly once a minute, so they are the best place to check how much bandwidth a site is using right now.
### FTP Traffic
Under **FTP traffic** you see the same style of table for data transferred over FTP, again for the current month, previous month, current year and previous year. Unlike web traffic, these figures are refreshed only once a day, so a recent upload or download may not appear until the next day.
### Website Quota (Harddisk)
Under **Website quota (Harddisk)** you see how much disk space each website is using (the **Used space** column, in megabytes) alongside its **Soft limit** and **Hard limit**, the Linux user the site runs as, and the percentage of the allowance in use. These figures update every five minutes. The two limits work as follows:
- The **soft limit** is the level at which the account starts receiving warnings that it is close to full. It can be exceeded for a short grace period.
- The **hard limit** is the absolute ceiling. Once a site reaches its hard limit it can no longer write new files, which can stop uploads, log writes and content management systems from saving.
On a shared hosting account these limits are set for you by Noiz to match your plan, so treat this table as a way to watch how close a site is to its allowance. If a site is approaching its limit, tidy up unneeded files or contact the Noiz support team about more space.
### Database Quota
Under **Database quota** you see the disk space used by each MySQL database on the account, in megabytes, against the quota set for it. Like the website quota, these figures update every five minutes.
### Backup Stats
If your plan includes backups, a **Backup Stats** item appears, showing the backup interval, how many backup copies exist for each site and the space they take up. These counts and sizes are read from the backup records each time you open the page, so they move as soon as a backup job finishes rather than waiting for a daily refresh. Because backup jobs normally run overnight, in practice that still means the figures change about once a day.
## Check Usage for a Single Website
To focus on one site rather than the whole account, open the website itself:
1. In the **Sites** module, click **Website** in the left menu.
2. Click the domain you want in the list.
The website form opens with tabs across the top: **Domain**, **Redirect**, **SSL**, **Statistics** and, where backups are enabled for the site, **Backup**. A further **Options** tab appears only for administrators, and for resellers where the panel has been configured to allow it. The disk space limit for the site is shown on the **Domain** tab (the **Harddisk Quota** field). On a shared hosting account this field is set by Noiz to match your plan, so you can read it but not raise it yourself.
## Turn On Web Statistics Reports
Separately from the raw usage tables, ISPConfig can build visitor statistics reports for a site once a day. These reports show visits, page views, referrers, browsers and similar detail in a browser-friendly format. They are switched on per website and are password-protected.
### Enable the Reports and Set a Password
1. In the **Sites** module, open **Website** and click the domain you want.
2. Click the **Statistics** tab.
3. In the **Webstatistics program** drop-down, choose **AWStats**, **GoAccess** or **Webalizer**. Choosing **None** disables the reports.
4. Type a password in the **Set Webstatistics password** field and confirm it in **Repeat Password**, or use the **Generate Password** button. The username is fixed by ISPConfig as `admin` and cannot be changed.
5. Click **Save**.
Setting the password is not optional. ISPConfig always password-protects the `stats` folder, but it only writes the login file once a password has been saved, so switching the reports on and leaving the password blank produces a stats page that nobody can open.
The reports are generated once a day by a job that runs just after midnight on the server, so a site you have just enabled will show no data until the following day.
### View the Reports
Once the first report has been built, open a browser and go to the `stats` folder of the site. Using `yourdomain.com` as an example domain, that is:
```
https://yourdomain.com/stats/
```
When prompted, log in with the username `admin` and the webstatistics password you set on the **Statistics** tab. As a shortcut, each domain name in the **Web traffic** table is itself a link to that site's stats page, so you can open it from the panel without typing the address.
## Access the Raw Web Server Logs
For a request-by-request record of what the web server did, use the raw logs rather than the statistics reports. Every ISPConfig website has a `log` directory in its home folder, sitting alongside the `web` folder that holds your site content. The two main files are:
- **access.log**: one line for every request the site received, including the visitor's address, the page or file requested, the response code and the size of the response. This is where you check what is being requested and by whom.
- **error.log**: messages the web server and PHP wrote when something went wrong, such as missing files, permission problems or script errors. This is the first place to look when a page shows an error.
Alongside the current files you will usually find earlier days already archived: access logs as dated files named for the day they cover, such as `20260726-access.log.gz`, and previous error logs numbered `error.log.1.gz`, `error.log.2.gz` and so on. The `log` directory keeps only a limited recent history, since files older than the retention period set on the server are deleted automatically. This folder is also deliberately excluded from your website backups, so do not rely on a backup to recover an old log.
### Download the Log Files
1. Open your FTP or SFTP client and connect to the website using the login details for that site.
2. Once connected, open the `log` directory in the site's home folder.
3. Download `access.log` or `error.log` (or one of the dated `.gz` archives for an earlier day) to your computer.
4. Open the file in a plain text editor. Compressed `.gz` files need to be extracted first with a tool such as 7-Zip or your operating system's built-in archive support.
The log files are provided for reading, so treat this directory as read-only: download and inspect the files rather than editing them in place.
## Monitor the Server (Administrator Access Only)
The **Monitor** module reports on the health of the whole server rather than a single website: processor and memory load, disk usage, running services, available updates and the system logs. It appears in the top navigation only when you log in with a **server administrator** account, as you would on a self-managed Noiz server. On a standard shared hosting client login the Monitor module is not shown, and you use the **Statistics** menu and the site logs described above instead.
If you do have administrator access, click the **Monitor** module in the top navigation. Its left menu is grouped as follows.
### System State (All Servers)
- **Overview**: a summary of every server. Each server sits in a coloured panel: green when everything is in order, blue for informational notices such as operating system updates being available, amber for warnings, and red for a critical failure that needs attention. Each status carries a **[More...]** link through to the detail behind it. The **Refresh Sequence** option lets the page update itself automatically at an interval you choose, and no refresh is the default.
- **ISPConfig Log**: the ISPConfig log, which records what ISPConfig itself is doing in the background and any warnings or errors. How much detail appears depends on the log level configured for the server.
- **Jobqueue**: the list of background tasks ISPConfig still has to carry out. An empty list means everything has been applied.
- **Data Log History**: a history of the configuration changes ISPConfig has written out, useful for establishing what was changed and when.
### Server State
The **Server to Monitor** drop-down decides which server every menu item below it reports on. With a server selected, **Hardware Information** gives you **CPU Info**, and the **Server State** group reports on that one server:
- **Overview**: the same summary as above, for the selected server only.
- **Disk Usage**: free and used space per partition, the same information as the `df -h` command.
- **Server Load**: the current load averages, the same as the `uptime` command.
- **Memory Usage**: how much memory is in use, the same information as `cat /proc/meminfo`.
- **Services**: whether the web, FTP, SMTP, POP3, IMAP, DNS and MySQL services are online.
- **Update State**: whether operating system updates are available.
- **MySQL Database size**: the size of every database on the server, with the client and domain each one belongs to.
The same group also holds **RAID State** and, where they have been set up on the server, links through to Monit and Munin.
### Logfiles
The **Logfiles** group shows the last 100 lines of the server's main system logs without needing a shell session, including **Mail Log**, **System-Log** and **ISPC Cron-Log**, alongside **Mail Queue** and the logs of whichever security tools the server runs. These are server-wide logs and are separate from the per-website access and error logs described earlier.
## Troubleshooting
- **The stats page shows nothing or returns a not-found error**: check that the **Webstatistics program** on the site's **Statistics** tab is set to **AWStats**, **GoAccess** or **Webalizer** and not **None**. Remember the reports are built only once a day just after midnight, so a newly enabled site shows data from the next day onwards.
- **The stats page returns a server error instead of a login prompt**: this is the signature of statistics being switched on with no webstatistics password saved. Open the site's **Statistics** tab, set a password, and save.
- **The stats page asks for a password you do not have**: the username is always `admin`, and the password is the one set in the **Set Webstatistics password** field. If you are unsure of it, open the site's **Statistics** tab, set a new password, save, and use that.
- **FTP traffic or web traffic looks lower than expected**: web traffic updates about once a minute, but FTP traffic updates only once a day, so very recent activity may not be reflected yet.
- **The log directory is empty or missing in your FTP client**: confirm you opened the `log` folder in the website's own home directory. A brand-new site may have very little logged so far. If the folder stays empty for an active site over several days, open a support ticket so the Noiz support team can check the log setup on the server.
- **A site is near or over its disk quota**: use **Website quota (Harddisk)** to confirm the **Used space** against the limits, remove unneeded files, and contact the Noiz support team if the site genuinely needs more space than the plan allows.
- **The Monitor module is not in the top navigation**: this is expected on a client login. The Monitor module is part of the administrator interface, so use the **Statistics** menu and the site logs instead.
If you get stuck at any point, open a support ticket with the Noiz support team and include the website's domain, which figure or log you are looking at, and what you expected to see compared with what the panel shows.
# How to Password-Protect a Folder in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-password-protect-a-folder-in-ispconfig/
This guide shows you how to password-protect a folder inside your website using the ISPConfig control panel, so that visitors must enter a username and password before they can view anything in it. It is written for Noiz clients managing their own hosting account through ISPConfig. This kind of protection is sometimes called htaccess protection, basic authentication or a password-protected directory; in ISPConfig the feature is split across two screens, **Protected Folders** and **Protected Folder Users**, and this guide covers both. The panel does all the technical work for you: there is no need to create or edit any files by hand.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig 3 User Manual](https://www.ispconfig.org/documentation/user-manual/): the official manual; folder protection is covered under Sites, in the Web Access sections "Protected Folders" and "Protected Folder Users".
- [Sites module (ISPConfig 3 Documentation)](https://docs.ispconfig.org/category/modules/sites/): the current official documentation for the Sites module.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation.
- [ISPConfig 3 source repository](https://git.ispconfig.org/ispconfig/ispconfig3): the official source code, against which the current field and button labels in this guide were verified.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- An existing website on your account. If you have not set one up yet, see [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/).
- The path of the folder you want to protect, relative to the website's document root, for example `/private`. The folder does not have to exist yet: if it is missing, ISPConfig creates it for you.
## How Folder Protection Works
ISPConfig protects folders with basic HTTP authentication, the same mechanism traditionally configured with `.htaccess` and `.htpasswd` files. Once protection is active, anyone who browses to the folder, or to any page or file inside it, sees a plain login prompt from their browser before the content loads. ISPConfig labels the protected area `Members Only`, so that is the name most browsers show in the prompt; it is fixed and not something you set. Only the usernames and passwords you create on the **Protected Folder Users** screen are accepted. These credentials are completely separate from your ISPConfig login and your FTP accounts.
Two records work together: a **Protected Folder** record defines which folder is locked, and one or more **Protected Folder User** records define who may enter. You need both, and the order matters. Creating the folder record on its own does not yet change anything on the server: ISPConfig writes the authentication files the first time you save a user for that folder. So the folder stays public until Step 2 is done, and you should treat the job as finished only once a user exists.
One security note before you start: basic authentication sends the username and password with every request in a lightly encoded, easily reversed form. Always use the protected area over HTTPS, so the credentials travel inside an encrypted connection.
## Step 1: Create the Protected Folder
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, under **Web Access**, click **Protected Folders**. A list of any existing protected folders on your account appears.
4. Click the **Add new Folder** button.
The **Web Folder** form opens on its **Folder** tab. It has just three fields, **Website**, **Path** and **Active**. Complete them as follows, then click **Save**.
### Website
In the **Website** drop-down, select the website that contains the folder you want to protect, for example `yourdomain.com`. Any subdomain or alias domain that was created with its own vhost is listed here in its own right, so pick the entry whose document root actually holds the folder.
### Path
In the **Path** field, enter the folder to protect, relative to the website's document root (the `web` directory where your site files live). Examples:
- `/private` protects the folder `private` in the document root, reached in a browser at `https://yourdomain.com/private/`.
- `/files/secret` protects the subfolder `secret` inside the folder `files`.
- `/` protects the entire website, which is handy for a staging or development site you do not want the public, or search engines, to see.
If the folder you enter does not exist yet, ISPConfig creates it automatically. Protection always covers everything inside the folder, including its subfolders. The field accepts letters, digits, dots, hyphens, underscores and slashes only, so a folder name containing a space cannot be protected this way; rename the folder first. A leading or trailing slash is optional, because ISPConfig trims them before it works out the real path.
### Active
Leave the **Active** checkbox ticked. This is the master switch for the folder: unticking it later removes the protection without deleting the record or its users, and re-ticking it puts the protection back.
After you click **Save**, a small red change indicator appears near the top of the panel. Clicking it lists the changes that are not yet applied to the server, in this case `Create folder protection`, and the panel notes that storing updates can take up to a minute. Wait for it to clear before you judge the result. The folder is still public at this stage; the protection itself is put in place in Step 2.
## Step 2: Create a Protected Folder User
Now create at least one username and password that will be accepted at the login prompt. This step is what actually switches the protection on: saving the first user is the point at which ISPConfig creates the folder if it is missing and writes the authentication files into it.
1. In the left menu of the **Sites** module, under **Web Access**, click **Protected Folder Users**.
2. Click the **Add new Folder User** button. The **Web folder user** form opens on its **Folder** tab.
3. In the **Folder** drop-down, select the protected folder you created in Step 1. Each entry reads as the website followed by the folder path, so you can tell similar paths apart. Every protected folder on your account is listed here whether or not it is ticked **Active**, so check the entry you pick is the one you want.
4. In the **Username** field, enter the username this person will type at the login prompt, for example `reports`. Use letters, digits, dots, hyphens and underscores only, up to 64 characters.
5. In the **Password** field, enter a strong password, or click the **Generate Password** button beside it to have ISPConfig create one for you. The **Password strength** bar rates your choice as you type. ISPConfig also enforces a minimum length and strength, and refuses to save a password it judges too weak, so generating one is the quickest way through. Note the password down now if it was generated, because it is stored as a one-way hash and ISPConfig cannot show it to you again.
6. Confirm the password in the **Repeat Password** field.
7. Leave the **Active** checkbox ticked, then click **Save**.
Repeat these steps for each person who needs access. Giving every person their own username and password means you can later remove one person's access without disturbing anyone else.
## Step 3: Test the Protection
1. Wait until the red change indicator at the top of the panel has cleared.
2. Open a private (incognito) browser window. This matters because browsers remember basic authentication credentials, and a normal window may let you straight in from an earlier session.
3. Browse to the protected folder, for example `https://yourdomain.com/private/`. The browser should show a username and password prompt before any content appears.
4. Enter the username and password you created in Step 2. The folder's content should now load. If you cancel the prompt instead, the server returns an authorisation error page, which confirms the protection is working.
Once a visitor has signed in, the browser keeps sending the credentials automatically, so the prompt appears only once per browser session.
## Managing and Removing Protection
- **Change a password**: go to **Sites**, then **Protected Folder Users**, click the username, enter a new password in the **Password** and **Repeat Password** fields and click **Save**.
- **Remove one person's access**: delete their record from the **Protected Folder Users** list, or untick their **Active** checkbox to suspend it temporarily.
- **Move the protection to a different folder**: edit the folder record and change the **Path**. ISPConfig moves the existing users across to the new folder, so nobody has to be recreated, and it clears the protection out of the old folder.
- **Switch protection off temporarily**: open the folder record under **Protected Folders** and untick **Active**. The folder becomes public again until you re-tick it; the users you created are kept.
- **Remove protection permanently**: delete the folder record from the **Protected Folders** list. Its Protected Folder Users are deleted along with it, so there is no need to tidy them up separately. Your files stay exactly where they are; only the password requirement is removed.
ISPConfig writes and maintains the authentication files for the protected folder itself. It marks its own work inside `.htaccess` with a pair of comment lines reading `### ISPConfig folder protection begin ###` and `### ISPConfig folder protection end ###`, and it rewrites everything between them whenever the record changes. Any rules of your own that sit outside those markers, such as redirects or caching directives, are left alone. So do not hand-edit the lines between the markers, because your changes will be replaced, and keep your own directives outside them.
## Troubleshooting
- **No password prompt appears**: first check that the folder has at least one Protected Folder User, because a folder record on its own does not protect anything. If it does, the change may still be processing, so wait for the red change indicator to clear and try again. If it still fails, your browser may be replaying remembered credentials, so retest in a private window. Also check that the folder record is **Active** and that the **Path** matches the folder's real location relative to the document root, since a path that points at the wrong folder simply protects the wrong folder rather than reporting an error.
- **The correct username and password are rejected**: open the user record and confirm the **Folder** drop-down points at the right folder and the user is **Active**. Passwords are case sensitive, so retype the password in the **Password** and **Repeat Password** fields to be sure, save, and allow a minute for the change to apply.
- **Everyone is locked out, including you**: the folder is protected but has no user who is ticked **Active**. This happens most often after unticking **Active** on the last remaining user, or after re-saving the folder record while its users are all inactive: the prompt appears but no password is accepted. Create or reactivate a user under **Protected Folder Users**, or untick **Active** on the folder record until you are ready.
- **The Folder drop-down is empty when creating a user**: no protected folder exists on your account yet. Create and save one first (Step 1). Being ticked **Active** is not a condition for appearing in this list, so if the folder is missing from it the record was not saved.
- **The prompt appears on a plain http address**: the protection is working, but credentials typed over plain HTTP are easy to intercept. Share only the `https://` address of the protected area with your users.
If you get stuck at any point, open a support ticket with the Noiz support team and include the website domain, the exact **Path** value you entered, the username that is failing (never include the password) and a note of what happens when you visit the folder in a private browser window.
# How to Remove a Subdomain in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-remove-a-subdomain-in-ispconfig/
This guide shows you how to remove a subdomain, such as `blog.yourdomain.com`, from the ISPConfig control panel on your Noiz hosting account, and what that removal actually changes on the server. It is a two-click job, but what happens behind those two clicks depends on which kind of subdomain you created in the first place: one kind leaves every file where it was, another can delete a folder and everything inside it without a second prompt. If you are creating a subdomain rather than removing one, see [How to Create a Subdomain in ISPConfig](/ispconfig/how-to-create-a-subdomain-in-ispconfig/).
**Last reviewed:** 27 July 2026, against the current ISPConfig release. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [Subdomains (ISPConfig 3 Documentation)](https://docs.ispconfig.org/modules/sites/subdomains/): a short primer on the two ways a subdomain can be created. It covers creating them only, which is why the removal behaviour is set out here rather than referred onwards.
- [DNS Basics (ISPConfig 3 Documentation)](https://docs.ispconfig.org/dns-basics/): background on the DNS side, which ISPConfig keeps in a separate module from the website.
- [ISPConfig user manual](https://www.ispconfig.org/documentation/): the field-by-field reference for the panel's forms, including the **Web folder** field that decides whether your files survive a removal.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/). The panel address for your account is in your Noiz welcome email and in the client area.
- A copy of anything on the subdomain you might want again, taken before you start. Deletion happens immediately, there is no undo and no recycle bin in the panel.
- Access to wherever the domain's DNS is managed, if you want the address to stop resolving as well.
## Work Out Which Kind of Subdomain You Are Removing
ISPConfig can hold the same name, `blog.yourdomain.com`, in three different places, and each is removed from a different list. Open the **Sites** module and check them in this order:
- **Websites > Subdomain for website**: a standard subdomain, attached to a parent website and sharing its content or redirecting elsewhere. It has no document root of its own, only a **Redirect Type** and **Redirect Path**; everything else comes from the parent.
- **Websites > Subdomain (Vhost)**: a vhost subdomain, which has its own document root, its own PHP settings and possibly its own SSL certificate. This menu item only appears when vhost subdomains are switched on for the server and your plan allows subdomains.
- **Websites > Website**: a full website that happens to be named after a subdomain. Removing this is removing a website, not a subdomain, and it takes the whole site with it.
Each list has a filter row under the column headings. Select the parent site in the **Website** drop-down, or type part of the name into the search box in that same row and click the filter button, rather than paging through a long list.
If the name is in none of those three lists, look at **Aliasdomain for website** and **Aliasdomain (Vhost)**, and at the **Auto-Subdomain** setting on the parent website. A parent site set to the wildcard option (`*.`) answers on any subdomain that is not configured elsewhere, so the address can work without a subdomain record existing for it in **Sites** at all. In that case there is nothing to remove; change the parent website's **Auto-Subdomain** setting instead.
## Remove the Subdomain
Both kinds are removed the same way, from the list rather than from the edit form. The edit form normally carries only **Save** and **Cancel**, so if you have opened the record and cannot find a delete button, go back to the list.
1. Open the **Sites** module and click **Subdomain for website** or **Subdomain (Vhost)** in the left menu, as appropriate.
2. Find the row for the subdomain. Check the **Website** column, not just the name, if you host several domains that use similar names.
3. Click the red delete button at the right-hand end of that row.
4. ISPConfig asks **Do you really want to delete this record?** and then deletes it. The prompt does not repeat the name back to you, so satisfy yourself that you are on the correct row before you click it.
The entry disappears from the list at once, but the web server configuration is rewritten a moment later by a background job. Watch for the red change indicator near the top of the panel, which lists changes not yet applied to the server. It normally clears in under a minute.
The subdomain also goes back into your plan's subdomain allowance, so you can create another one straight away.
## What Happens to the Files
This is the part worth reading before you click delete rather than after.
A **standard subdomain** never had a folder of its own. It was only an extra name on the parent website's configuration, so removing it touches no files whatsoever. The parent website's configuration is simply rebuilt without that name, and everything on disk stays exactly as it was.
A **vhost subdomain** is different, and the outcome depends on the value that was typed into its **Web folder** field when it was created. Open the subdomain first and read that field:
- **A path whose first segment is exactly `web`**, so `web` on its own or something under it such as `web/blog`: the folder and its contents are deliberately left in place. That path sits inside the parent website's public directory, and ISPConfig refuses to delete anything there in case it takes the parent site down with it. Your files survive, they keep counting towards your disk quota, and they may still be reachable through the parent site at an address such as `yourdomain.com/blog/`. Delete them yourself over FTP or SSH if you want them gone. Read that first segment carefully, because it has to be `web` and nothing else: a folder named `webshop` or `web2` is a different segment and gets none of this protection.
- **Anything else**, for example `blog`, which sits alongside the parent site's public directory rather than inside it: ISPConfig deletes that folder and everything in it, then works upwards removing now-unused parent folders, stopping as soon as it reaches one that another vhost subdomain or vhost alias on the same website still uses. This is permanent and there is no confirmation beyond the single prompt you already answered.
Two subdomains created on the same afternoon can therefore behave completely differently on removal, so take a copy of anything you care about first.
Removing a vhost subdomain also clears its own web server configuration, its PHP handler and its log directory, along with any folder protection set against the subdomain itself. The generated web statistics pages sit inside the web folder, so they live or die by the rule above rather than being removed separately. It does **not** remove databases, FTP accounts, shell users or cron jobs, which belong to the parent website. If any of those only existed to serve the subdomain, tidy them up in the relevant list.
## What Happens to the SSL Certificate
Any certificate that covered the subdomain stops covering it. What that looks like depends on the kind of subdomain.
For a **standard subdomain** on a parent website using a free certificate, the subdomain was one of the extra names on the parent's certificate, and removing it makes ISPConfig request a fresh certificate for the parent site straight away without that name. Two things follow. If that request fails, typically because another name on the same site no longer resolves to the server, ISPConfig clears the **Let's Encrypt SSL** tick box on the parent website rather than leave a broken renewal in place, so check that box is still ticked afterwards; if it is not, fix the DNS for every name on the site, tick it again and save. See [How to Secure a Website with a Free SSL Certificate in ISPConfig](/ispconfig/how-to-secure-a-website-with-a-free-ssl-certificate-in-ispconfig/). Free certificate authorities also apply rate limits, so removing and recreating the same subdomain repeatedly in a short period can leave the parent site waiting for its next certificate. None of this applies if the subdomain had **Don't add to Let's Encrypt certificate** ticked, because it was never on the parent's certificate to begin with.
For a **vhost subdomain**, the certificate belonged to the subdomain and goes with it. Nothing on the parent website changes.
In both cases, if the subdomain's DNS record is still in place after removal, visitors typing the old address are likely to meet a certificate warning. That is expected, and the fix is to remove the DNS record, not to try to put a certificate back.
## The DNS Record Is Yours to Remove
ISPConfig keeps websites and DNS in separate modules, and deleting a subdomain in **Sites** does not touch the DNS zone. The A or CNAME record for `blog.yourdomain.com` is still there afterwards, still pointing at the hosting server.
Left in place, that record does not produce a clean "site not found". The name still resolves, the request still reaches the server, and the server answers with whatever it treats as the default site, so visitors may land on an unrelated page or a placeholder. Remove the record wherever the zone actually lives:
- If the zone is in ISPConfig, open the **DNS** module and delete the record. See [How to Manage DNS Records in ISPConfig](/ispconfig/how-to-manage-dns-records-in-ispconfig/).
- If the domain uses nameservers elsewhere, such as your registrar or another DNS provider, the record has to be removed there. The panel cannot reach it.
- If Noiz manages the DNS for the domain and you are not sure, open a support ticket with the exact name and it can be checked and removed for you.
One exception is worth knowing: if the parent website's **Auto-Subdomain** is set to the wildcard option, the web server answers for any name under the domain, so the old address keeps loading the parent site's content for as long as it still resolves. That is the wildcard doing its job, not a failed deletion. Removing the DNS record is still what stops it, unless the zone also holds a wildcard record, in which case the parent website's **Auto-Subdomain** setting is what has to change.
## Email Addresses on the Subdomain Are a Separate Thing
A mailbox such as `info@blog.yourdomain.com` has nothing to do with the website subdomain you just removed. Email lives in the **Email** module, under its own email domain record, and it is not created, changed or deleted when you add or remove a web subdomain.
So mail carries on. The mailboxes stay on the server and keep using disk space, webmail keeps working, and messages keep being delivered for as long as the MX and address records for the subdomain remain in DNS. If you want the email gone as well, remove it deliberately: open **Email > Email Accounts > Domain**, delete the mailboxes, aliases and forwards on that email domain, then remove the email domain itself. That works the other way round too, so removing an email domain has no effect on a website subdomain of the same name. See [How to Create an Email Mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/) for where these live in the panel.
## Check That It Worked
1. The subdomain is gone from the list you deleted it in, and the red change indicator at the top of the panel has cleared.
2. The parent website still loads normally over HTTPS. This is the check people skip and the one that matters, because the removal rewrites the parent site's configuration and certificate.
3. The parent site's certificate no longer lists the subdomain. Click the padlock in your browser and view the certificate, or run this from any machine with the `openssl` tools installed:
```
openssl s_client -connect yourdomain.com:443 -servername yourdomain.com < /dev/null 2>/dev/null | openssl x509 -noout -text | grep -A1 "Subject Alternative Name"
dig +short blog.yourdomain.com
```
Replace `yourdomain.com` and `blog.yourdomain.com` with your own names. The first command lists every name the live certificate covers, and the removed subdomain should not appear. The second shows whether the old address still resolves, which tells you whether a DNS record is left to tidy up.
## Troubleshooting
- **The subdomain is not in the Subdomain for website list**: it was created as a **Subdomain (Vhost)**, as a full **Website**, or as an aliasdomain. Check each list in turn. If the account holds many sites, use the filter row rather than scrolling.
- **The delete button does nothing, or you get a permissions error**: your login may not own that record, for example if the site sits under a different client account. Open a support ticket rather than working around it.
- **The address still loads the old content**: check the parent website's **Auto-Subdomain** setting for the wildcard option, then retry in a private window. Browsers hold on to redirects and DNS answers for a long time.
- **The address shows an unrelated site or a certificate warning**: the DNS record is still pointing at the server. Remove the record as described above.
- **Disk usage has not gone down**: the vhost subdomain's **Web folder** had `web` as its first segment, so its files were deliberately left in place. Delete the folder yourself over FTP or SSH once you are sure of the contents.
- **The parent website lost its free certificate**: the certificate request that followed the removal failed. Make sure every name still attached to that site resolves to the server, then re-enable **Let's Encrypt SSL** on the parent website and save.
- **Email to the subdomain still arrives**: expected. The email domain is a separate record in the **Email** module and has to be removed there.
- **You deleted the wrong one**: recreate it with the same settings, then restore the files from your own backup. Recreating the record does not bring content back.
## Need a Hand?
If you are on a managed Noiz plan, or you are not certain whether a subdomain is safe to remove, open a ticket from your [Noiz client area](https://www.noiz.co.za/clientarea.php) before you delete anything. Include the full subdomain name, the parent website it belongs to, and whether you want the files and the DNS record removed as well, and the support team will handle it for you.
# How to Remove an Alias Domain in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-remove-an-alias-domain-in-ispconfig/
This guide covers removing an alias domain from a website in the ISPConfig control panel on your Noiz hosting account, and, more importantly, what actually happens afterwards. Adding an alias domain (ISPConfig calls it an "aliasdomain"; you may also see it called a parked domain or a domain alias) is covered in [How to Add an Alias Domain in ISPConfig](/ispconfig/how-to-add-an-alias-domain-in-ispconfig/). Taking one away is a two-click job, so the deletion itself is not the interesting part. What is worth reading is how to be certain you are deleting an alias and not a whole website, whether you want to delete it at all or simply switch it off, and the knock-on effects on DNS and on your main site's SSL certificate that are easy to trip over.
**Last reviewed:** 27 July 2026, against the current ISPConfig release. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig Documentation: Alias Web Domains](https://docs.ispconfig.org/creating-web-sites/alias-web-domains/): the official walk-through for creating an alias domain. It documents creation only, which is why removal is covered here.
- [ISPConfig 3 User Manual](https://www.ispconfig.org/documentation/user-manual/): the official manual. Section **4.6.1.4 Aliasdomain for website** is the field-by-field reference for the Web Aliasdomain form, useful if you decide to edit rather than delete, and **4.6.1.5 Aliasdomain (Vhost)** covers the variant discussed below.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of official ISPConfig documentation.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- You know which domain you want to stop serving, and which website it is currently attached to.
- You know where the domain's DNS is managed, because the panel change and the DNS change are two separate jobs. If the zone is on Noiz nameservers, see [How to Manage DNS Records in ISPConfig](/ispconfig/how-to-manage-dns-records-in-ispconfig/).
## First, Confirm It Really Is an Alias Domain
This is the one step that genuinely matters, because the panel puts several different objects in lists that look almost identical, and only one of them is safe to delete casually.
### An alias domain is a name; a website is a container
- An **alias domain** is nothing more than an extra name bolted onto an existing website. It has no files of its own, no document root of its own, no database, no PHP settings, no logs and no disk quota. Everything it shows belongs to the parent website. Deleting it removes the name and nothing else. If you get it wrong, you simply add it back.
- A **website** is the container itself: its own virtual host, its own document root and files, its own PHP configuration, its own certificate, its own statistics and logs. Deleting a website in ISPConfig removes the site's directory and its contents. There is no undo button in the panel for that, and recovery means a restore from backup.
- A **subdomain** (such as `shop.yourdomain.com`) sits under the parent website's own domain name, whereas an alias domain is a different domain name entirely. If the name you want gone is a subdomain, see [How to Create a Subdomain in ISPConfig](/ispconfig/how-to-create-a-subdomain-in-ispconfig/) for where those live in the panel.
### How to tell which one you are looking at
1. Log in to ISPConfig and open the **Sites** module.
2. In the left-hand menu under **Websites**, open **Aliasdomain for website**. The page is headed **Aliasdomains**, and each row shows the alias domain name with the site it is attached to in the **Website** column. If the domain appears in this list, it is a true alias domain and safe to delete.
3. If it does not appear there, check the **Websites** list. A domain sitting in that list is a full website. Deleting it deletes its files, so treat it as a completely different task and take a backup first.
4. If your server has the feature enabled, you may also see **Aliasdomain (Vhost)** in the left menu. That is a hybrid: an alias name that does have a document root of its own, inside the parent website's directory. Deleting one of those can take a folder of files with it, so download anything you want to keep before you remove it.
A useful sanity check: if the domain has ever had its own files uploaded to it, its own WordPress install or its own database, it is not a plain alias domain, whatever it is called in conversation.
## Decide: Switch It Off, or Delete It
The panel gives you two ways to stop an alias domain serving your site, and the official documentation does not draw the distinction. It matters more than it looks.
- **Deactivate (recommended when you are not certain).** Open the alias domain, clear the **Active** tick box and save. The name stops answering, but the record, its redirect settings and its link to the parent website all survive. Re-ticking the box puts everything back exactly as it was. This is the right choice for a temporary change, a trial, or any situation where somebody might ask for the domain back next week. The trade-off is that the entry still counts against your hosting package's alias domain allowance, because the client limit ISPConfig calls **Max. number of web aliasdomains** counts the records rather than the active ones. The name also stays reserved inside the panel, so you cannot use it elsewhere.
- **Delete.** The record is removed for good. This frees the alias domain allowance for another domain, and it releases the name so it can be used again in the panel, which is exactly what you need if the plan is to promote the domain to a website of its own. Any redirect type, redirect path, auto-subdomain and SEO redirect settings you configured on it are gone, and recreating the alias means re-entering them.
One decision worth pausing on: if the alias domain is currently a permanent (`R=301,L`) redirect to your main address, it is doing real work for search engines by consolidating an old domain onto the new one. Deleting it throws that away, and any ranking or backlink value attached to the old domain stops being passed on. If the only reason for removal is tidiness, leaving a 301 alias in place costs you nothing. See [Google Search Central: redirects and Google Search](https://developers.google.com/search/docs/crawling-indexing/301-redirects) for why that matters, and [How to Set Up a Website Redirect in ISPConfig](/ispconfig/how-to-set-up-a-website-redirect-in-ispconfig/) if you would rather change the redirect than remove the domain.
## Remove the Alias Domain
1. In **Sites > Aliasdomain for website**, find the row for the domain and check the **Website** column one last time. The same setting is labelled **Parent Website** when you open the record itself. Two similar-looking domains in the same list is exactly how the wrong one gets deleted.
2. Click the delete control at the right-hand end of the row (a small bin or cross icon, depending on the panel theme).
3. Confirm when the panel asks whether you really want to delete the record.
4. The row disappears from the list. ISPConfig then queues the change, rewrites the parent website's virtual host without that name and reloads the web server. That queue is processed on a schedule rather than instantly, so allow a minute or two: the panel showing the record as gone and the live server actually behaving differently are not the same moment.
## What Changes the Moment It Is Gone
### Visitors using that domain stop reaching the site
That is the whole point, but it is worth being precise about what a visitor actually sees, because it is rarely a tidy error page from your own site.
- **If the domain's DNS still points at the Noiz server** (the usual case immediately after removal), the request still arrives, but no website on that server claims the name any more. The web server hands it to whatever it treats as the default, so visitors typically land on a generic placeholder or "site not configured" page rather than anything of yours. Over `https://` they will usually hit a certificate name-mismatch warning before they get that far.
- **If you have also removed the DNS records**, the browser fails at the lookup instead and reports that the server cannot be found.
- **Everything that hard-codes the domain breaks with it**: bookmarks, links from other sites, search engine results still listing the alias, email signatures, printed material, QR codes, and any third-party integration, webhook or callback URL configured to use that hostname. Search results in particular can take weeks to drop away, so people will keep arriving at a broken address for a while.
Removing an alias domain never touches the parent website's own domain, its files or its content. If your main site goes down at the same moment, something else has happened; see Troubleshooting below.
### DNS is not touched at all
ISPConfig's alias domain record configures the web server, and nothing else. Deleting it leaves the domain's A records, CNAMEs and everything else in the zone exactly as they were, still pointing at the server. Tidying the DNS is a separate job, done either in the panel if the zone is hosted with Noiz or at whichever provider holds the zone. If the domain is moving to a new host, changing the A record is what actually moves it; removing the alias in ISPConfig only stops the old server answering for it.
### SSL: the order you do things in matters
This is the trap that catches people, because the risk lands on the certificate for your *main* site rather than on the alias.
ISPConfig builds the parent website's free SSL certificate request from all the names currently attached to that site: the site's own domain, its auto-subdomain, and every alias domain and subdomain that is marked active, plus the www form of any of those whose auto-subdomain is set. Deactivating an alias domain takes it off that list just as surely as deleting it does. Every one of those names has to answer a validation request from the internet each time the certificate is issued or renewed, which is why the official documentation insists that all of them resolve to the server before you switch free SSL on.
Before the request goes out, ISPConfig tests each name over HTTP and quietly leaves out any that does not answer on this server, so a name whose DNS has already gone is usually dropped rather than sinking the request. What does sink it is a name that answers but then fails the certificate authority's own validation, a redirect sitting in front of it being the common cause: the request fails for the whole site, and the site keeps serving its existing certificate until a later attempt succeeds. Do it in this order and neither case can bite you:
1. Remove (or deactivate) the alias domain in ISPConfig.
2. Let the parent website's certificate be reissued without that name. Removing an alias domain makes ISPConfig rebuild the parent site and ask for a fresh certificate as part of the same job. If it does not refresh on its own, re-saving the website in **Sites > Websites** triggers another request. See [How to Secure a Website with a Free SSL Certificate in ISPConfig](/ispconfig/how-to-secure-a-website-with-a-free-ssl-certificate-in-ispconfig/).
3. Only then change or remove the domain's DNS records.
If the alias has to stay attached but can no longer answer for itself, there is a third option: the alias domain form carries a **Don't add to Let's Encrypt certificate** tick box, which keeps the name off the request without deleting or deactivating the record.
Two smaller points. The certificate already installed on the server keeps listing the removed name until it is next reissued, which is harmless: a name being listed on a certificate does not make the server serve a site for it. And no certificate is revoked by this; the old name simply stops appearing on the next one issued. Background on how those certificates are issued and renewed is in the [Let's Encrypt FAQ](https://letsencrypt.org/docs/faq/).
### Email for that domain is a separate matter
A web alias domain and a mail domain are unrelated objects in ISPConfig. Deleting the alias under **Sites** does not remove anything under **Email**: mailboxes, aliases, forwards and the mail domain itself all keep working, and mail carries on being delivered. If you want mail for the domain gone too, that is a deliberate separate deletion in the Email module, and removing an email domain takes its mailboxes and their stored messages with it. Download anything you need first.
## Confirm It Worked
1. The row no longer appears in **Sites > Aliasdomain for website**. If you deactivated instead, the row is still there but no longer marked active.
2. Open the removed domain in a **private or incognito window**, or on a phone using mobile data. Your normal browser is the least reliable place to test this, especially if the alias was a permanent redirect: browsers cache a 301 aggressively and will keep sending you to the old destination long after the server has stopped issuing it.
3. Check what the server now says for that name from a command line: `curl -sI http://yourseconddomain.com` Replace `yourseconddomain.com` with the domain you removed. You should no longer see a response that belongs to your site.
4. Most important, confirm the parent website is still healthy, both the page itself and the padlock: `curl -sI https://www.yourdomain.com` Replace `yourdomain.com` with your real domain. Load it in a browser too and check the certificate has not developed a warning.
## Troubleshooting
**Symptom**: the removed domain still shows your website. Almost always caching rather than a failed deletion. Retest in a private window or from a different network. If the domain sits behind a proxy or CDN, that service is serving its own cached copy and needs its cache purged. If it genuinely still serves your content from a clean client, check whether the same name also exists as a website, a subdomain or a Vhost alias domain elsewhere in the **Sites** module.
**Symptom**: the domain now shows a page belonging to somebody else, or an unfamiliar placeholder. This is expected, not a fault. The DNS still points at the server while no site claims the name, so the request falls through to the server default. Repoint or remove the domain's DNS records to stop it.
**Symptom**: the deletion is refused with "You dont have the permission to delete this record!". Every row in the list carries a delete control, so this is a permissions block rather than a missing button: a record that an administrator created on your behalf can be handed to your account with read and edit rights but not delete, which is most often seen on a website or a Vhost alias domain. A domain belonging to a different client does not appear in your list at all. Open a support ticket rather than trying to work around it.
**Symptom**: your main website shows a certificate warning after the removal. The site's certificate request is failing on one of the names still attached to it. Re-save the website in **Sites > Websites** to trigger a fresh request, and check that every remaining alias domain and subdomain on that site still resolves to the server. If it does not clear, raise a ticket.
**Symptom**: ISPConfig reports "There is already a website or sub / aliasdomain with this domain name" when you try to recreate the domain as a website of its own. The old alias record is still in the panel. A name can only be held by one object at a time, so delete the alias first, then create the website. The full procedure is in [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/). Note that promoting a domain this way gives it an empty document root, so the content has to be put there separately.
**Symptom**: you deleted the wrong entry. If it was an alias domain, no harm is done: recreate it using [How to Add an Alias Domain in ISPConfig](/ispconfig/how-to-add-an-alias-domain-in-ispconfig/) and re-enter the redirect and auto-subdomain settings. If it was a website or a Vhost alias domain, stop making further changes and contact Noiz support immediately, because the sooner a restore is attempted the better the outcome.
If you are unsure whether the domain in front of you is an alias or a full website, ask before you click delete rather than after. Open a support ticket with the Noiz support team, quoting the domain name and the website you believe it belongs to, and on managed plans the team will confirm what the record actually is, remove it for you, and check that the parent site's certificate reissues cleanly afterwards.
# How to Restore a Backup in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-restore-a-backup-in-ispconfig/
This guide covers putting a Noiz hosting account back to an earlier state from a backup ISPConfig has already taken: a website's files, a database, or a mailbox. It is written for Noiz clients who manage their own hosting through ISPConfig, and it deliberately spends more time on the decisions than on the clicking, because the clicking is the easy part. A restore is the one action in the panel that destroys current data on purpose, cannot be undone, and behaves differently depending on which of the three backup types you are restoring.
**If you came here looking for how to restore part of a backup rather than all of it, you are in the right place, and there is nothing extra to do.** ISPConfig has no single account-wide archive to take apart. It stores website files, databases and mailboxes as separate backups with separate restore buttons, so a partial restore is the only kind ISPConfig performs. Restoring a database without touching the files, or one mailbox without touching the website, is the normal case rather than an advanced one.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** (the most recent release tag published by the ISPConfig project, and the version Noiz runs). This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [The ISPConfig User Manual](https://www.ispconfig.org/documentation/user-manual/): the vendor's own reference for every form and field in the panel, including the **Backup** tab settings that decide what exists to restore in the first place.
- [ISPConfig 3 Documentation](https://docs.ispconfig.org/): the official online documentation for the current interface.
- [The backup and restore routine in the ISPConfig source, at release 3.3.1p1](https://git.ispconfig.org/ispconfig/ispconfig3/-/blob/3.3.1p1/server/lib/classes/backup.inc.php): the authoritative answer to what a restore actually does to your data. The behaviour described in this article was read from this file rather than assumed.
- [ISPConfig release tags](https://git.ispconfig.org/ispconfig/ispconfig3/-/tags): the project's own list of releases, useful for checking whether guidance you find elsewhere was written for the version you are running.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- Backups already exist. A restore can only offer you what was captured earlier, so if backups were never switched on for the site or mailbox there is nothing in the list to restore. Setting that up is covered in [How to Back Up Websites, Databases and Mailboxes in ISPConfig](/ispconfig/how-to-back-up-your-websites-databases-and-mailboxes-in-ispconfig/).
- An [FTP account](/ispconfig/how-to-create-an-ftp-account-in-ispconfig/) for the website, if you want to take your own copy of anything before you overwrite it. This is strongly recommended and the reason is explained below.
- A clear answer to one question: *what exactly is wrong, and when did it start?* Restoring is not a diagnostic tool. If you do not know roughly when the problem began, you do not know which backup to pick, and a restore to the wrong date destroys good data as thoroughly as bad data.
## Read This Before You Click Restore
### A restore cannot be undone
There is no undo, no staging copy, and no option to restore somewhere else so you can compare before committing. ISPConfig writes the backup straight over the live website, database or mailbox. The panel asks you to confirm once, and after that the current state of whatever you restored is gone.
### Take a fresh backup first, and mind the trap in doing so
The safe habit is to capture the current state before replacing it, so that if the restore turns out to be the wrong call you can get back to where you started. On the website **Backup** tab, under the heading **Manual backup**, ISPConfig gives you two on-demand buttons for exactly this, **Make backup of databases** and **Make backup of web files**, so you do not have to wait for the overnight run.
**The trap:** ISPConfig warns you about this when you click, and the warning is easy to skim past. Manual backups count towards the **Number of backup copies** limit set on the site. If that limit is already reached, taking a fresh backup deletes the oldest one to make room, and the oldest one may be precisely the backup you were about to restore. Look at the dates in the **Existing backups** list first. If the backup you want is the oldest row, do not take a manual backup: take your own copy over FTP instead, which does not touch the panel's retention at all.
Mailboxes have no on-demand backup button and no download button, so there is no in-panel way to snapshot a mailbox before restoring it. To keep your own copy, connect a mail client over IMAP and drag the folders you care about into a local folder before you restore. This is worth doing, because a mailbox restore is the type most likely to surprise you.
### Backups hold content, not settings
A restore brings back files, database contents and messages. It does not bring back anything you configured in the panel itself: PHP version, SSL certificates, redirects, cron jobs, DNS records, FTP accounts, mailbox settings and spam filter policies are all unaffected by a restore, in either direction. If your problem is a setting rather than content, restoring will not fix it and you will have overwritten good data for nothing.
## The Three Backup Types, and What Each Restore Really Does
This is the section the official documentation does not give you, and it matters because the three types are not equally destructive. In the panel they all look like the same **Restore** button.
### Website files: a mirror, not a merge
Restoring a website file backup puts the site's directory back to exactly the state captured in the archive. Changed files are reverted, deleted files are put back, and **files created since the backup are removed**. The panel's confirmation says only that restoring "will overwrite existing files in your website", which understates it: anything added after the backup date, including uploads, generated files and anything you installed since, is not merged in and does not survive.
Two consequences worth planning around:
- **Content added since the backup is lost.** On a site where visitors or customers upload files, that can mean losing real work even though the restore itself succeeded exactly as designed.
- **Directories you excluded from backups are at risk.** Anything listed in **Excluded Directories** on the site's **Backup** tab was never captured, and the restore makes no exception for it. Because the archive does not contain those paths, mirroring the archive over the site removes their contents too, so an exclusion protects a directory from being backed up but not from being emptied. Copy those directories down over FTP before restoring.
### Databases: table by table, with leftovers
A database restore replays the stored dump into the existing database. Every table present in the dump is dropped and recreated, so the data in those tables is fully replaced. Tables that exist in the live database but are *not* in the dump are left exactly where they are.
The practical effect is that a database restore is not a clean slate. If a plugin, extension or update created new tables after the backup was taken, those tables survive the restore and sit alongside restored older data. That mismatch is a common cause of a site that is still broken after what looked like a successful restore.
### Mailboxes: additive
A mailbox restore is the gentlest of the three. Messages from the backup are written back into the mailbox, and mail that arrived after the backup date is not removed. Depending on how the server stores mail for your account, restored messages either merge back into your existing folders or appear as a separate dated folder you can browse in your mail client.
Two things to expect. First, duplicates: messages that were already there and are also in the backup can appear twice. Second, a resync. Your mail client will not show the change until it has talked to the server again, and on a large mailbox that can take a while. Mail already downloaded and removed from the server by a POP3 client is not affected by any of this.
## Restore a Website's Files
1. Log in to the ISPConfig control panel and open the **Sites** module.
2. Under **Websites**, click **Website**, then click the site you want to restore.
3. Open the **Backup** tab. Below the backup settings you will find **Existing backups**, a table of everything currently stored for this site.
Read the table before you touch anything. The columns tell you what you are choosing between:
- **Date**: when the backup was taken. Backups run overnight, so the newest scheduled row is usually from the early hours of the current day, not from a few minutes ago.
- **Type**: **Website files** or **MySQL Database**. Both types share this one list, which is the single most common source of confusion on this screen. Check the type before you click **Restore**.
- **Scheduler**: **Auto** for the scheduled run, **Manual** for one you triggered yourself.
- **Backup format**, **Encrypted**, **Backup file** and **File size**: mostly informational. A file size far smaller than you expect is a warning sign worth investigating before you restore from it.
4. **Optional but recommended:** click **Download** on the row you intend to restore, and on the newest row as well. Within a few minutes each file appears in a folder named `backup` in your website's directory, alongside the public `web` folder rather than inside it, so it is not exposed to visitors. A website restore leaves that folder alone, so a copy downloaded beforehand is still on the server afterwards. Collect them over FTP, then delete them from the server, because they count against your disk quota while they sit there. Having the archive on your own machine is what turns an irreversible action into a recoverable one.
5. Click **Restore** on the row you want, with **Type** showing **Website files**.
6. Read the confirmation and accept it. ISPConfig replies that the restore has started and will take several minutes.
The restore is queued rather than instant. ISPConfig hands it to the server and works through it in the background, which is why the panel says minutes rather than seconds. The site stays live throughout, and visitors during the restore may see a half-replaced site. If that matters, put up a holding page first.
## Restore a Database
Database backups live in the same **Existing backups** list on the website's **Backup** tab, not under **Databases** in the left menu. If you went looking under **Databases** and found no backups, that is why. ISPConfig groups a site's databases with the site they belong to.
1. Open the website's **Backup** tab as above.
2. In **Existing backups**, find a row whose **Type** is **MySQL Database** and whose **Backup file** names the database you mean. A site with more than one database has one row per database per backup run, so match the name, not just the date.
3. Click **Restore** and confirm.
Before you do, decide whether you also need the files from the same date. A database and the code that reads it are a matched pair, and restoring one without the other is a frequent cause of a site that gets worse rather than better. As a rule of thumb: restore the database alone when the data is wrong but the site works; restore both, from the same date, when the site broke after an update or an installation.
Restoring a database does not change the database user or its password, and it does not touch your application's configuration file, since that lives in the files backup. If your site cannot connect after a restore, the cause is almost always a mismatch between a restored configuration file and the current credentials rather than a failed restore. [How to Create a Database and Database User in ISPConfig](/ispconfig/how-to-create-a-database-and-database-user-in-ispconfig/) sets out the four values an application needs, and [How to Set Database User Privileges in ISPConfig](/ispconfig/how-to-set-database-user-privileges-in-ispconfig/) covers what that user is allowed to do.
## Restore a Mailbox
Mailbox backups are managed per mailbox, in the **Email** module, and are entirely separate from anything on the website side. A mailbox is backed up and restored on its own even when the domain it belongs to is also being backed up.
1. Open the **Email** module and, under **Email Accounts**, click **Email Mailbox**.
2. Click the mailbox you want to restore.
3. Open its **Backup** tab. Below the backup interval and copy count you will find that mailbox's own **Existing backups** list, showing **Date**, **Backup file** and **Filesize**.
4. Click **Restore** on the row you want and confirm. As with a website, the job is queued and takes several minutes.
Two differences from the website side are worth knowing in advance, because they change how you prepare. There is no on-demand backup button for a mailbox, so you cannot snapshot it in the panel before restoring. There is also no download button, so a mailbox backup can only be restored in place. If you need your own copy of the current mail, take it over IMAP with a mail client before you restore. [How to Access Your Webmail in ISPConfig](/ispconfig/how-to-access-your-webmail-in-ispconfig/) covers reaching the mailbox, and [How to Create an Email Mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/) covers the settings a client needs.
## How to Tell It Worked
The panel's message means the job was accepted, not that it has finished. Confirm the result yourself:
- **Website files**: load the site in a private browser window so you are not looking at a cached copy. Then check a file you know changed after the backup date and confirm it is back to its earlier state. Over FTP, check the modification dates in the site's `web` folder.
- **Database**: open the database in phpMyAdmin from the **Databases** list and spot-check a record you know was different. Confirming the restore in the data is quicker and far more conclusive than inferring it from the site's behaviour.
- **Mailbox**: let the mail client finish a full sync before judging it. Messages may land in a dated folder rather than in the folder they came from.
- **Nothing happened at all**: give it longer before repeating the action. Large sites take longer, and ISPConfig will not stack a second restore on top of a pending one: click **Restore** again while a job is queued and the panel tells you there is already a pending backup restore job rather than starting another.
If the site is still wrong after a verified restore, resist the urge to work backwards through older backups. Each attempt destroys the state left by the previous one. Stop, and open a ticket while you still have the copies you downloaded. [How to Monitor Website Usage and Logs in ISPConfig](/ispconfig/how-to-monitor-website-usage-and-logs-in-ispconfig/) shows where the error logs are, and they usually name the real problem in one line.
## When the Backup You Need Has Aged Out
ISPConfig keeps a fixed number of backups per site and per mailbox, set by **Number of backup copies**. Once that many exist, each new backup deletes the oldest, permanently, from both the disk and the panel's records. Multiply the copy count by the interval and you have your real window: ten daily copies is ten days, four weekly copies is roughly a month. Nothing older than that window is recoverable through the panel, and no amount of clicking will bring back a row that is no longer listed.
To see where you stand before you need to know, open **Statistics** in the left menu of the **Sites** module and click **Backup Stats**. The **Email** module has its own **Backup Stats** under **Statistics** for mailboxes. Both pages show the interval and the copy limit together in one column, then the number of backups that actually exist and the space they use, so you can see at a glance how much of your allowance is filled. The figures are read when you open the page rather than from a nightly snapshot, so a backup that has just finished is counted straight away.
If what you need is already outside that window:
- **Open a ticket straight away rather than after investigating.** Do not wait until you have finished working out what happened. Options narrow with time on a hosting server, so the sooner Noiz support hears from you, the more there is to work with. Say which domain, mailbox or database, what date you need, and what changed.
- **Stop making changes to the affected site or mailbox.** Every backup run, and every manual backup, pushes the retention window forward and deletes one more old copy. Leave it alone until you have an answer.
- **Look for copies that are not ISPConfig's.** Application-level backups are separate from the panel's and often reach further back: a WordPress backup plugin's own archives, an installer's backups, an export you took before an upgrade, or an old copy in a folder on the server. A previous host's final backup is also worth chasing if the site was migrated.
- **Then fix the window so this cannot repeat.** Raise **Number of backup copies** on the site or mailbox, and keep periodic copies somewhere that is not the hosting server. A backup that lives only on the machine it protects is not a backup. [How to Back Up Websites, Databases and Mailboxes in ISPConfig](/ispconfig/how-to-back-up-your-websites-databases-and-mailboxes-in-ispconfig/) covers the settings and what your plan allows.
## Troubleshooting
**Symptom**: there is no **Backup** tab on the website or mailbox. Backups are a plan feature, and ISPConfig hides the tab entirely when the allowance is not enabled on your account rather than showing it greyed out. The tab also appears on the main website entry rather than on subdomain or alias entries, which is normal: their files sit inside the parent site's directory and travel with the parent's backup. If you expected backups on your plan and the tab is absent, open a ticket rather than assuming it is broken.
**Symptom**: the **Backup** tab is there but **Existing backups** is empty. Nothing has been captured yet. Either **Backup interval** is set to **No backup**, or it was only just switched on and the first overnight run has not happened. An empty list is a correct result, not a fault. For a website you can fill it immediately with **Make backup of web files**; a mailbox has to wait for its next scheduled run.
**Symptom**: you need one file or one database table back, not the whole thing. The panel cannot do this, and restoring everything to get one file back would undo far more than you intend. Click **Download** on the backup instead, collect the archive over FTP, open it on your own machine, and upload just the file you want. For a single table, open the downloaded database dump in a text editor, copy out the statements for that table and run them in phpMyAdmin. [How to Connect to Your FTP Account Using FileZilla](/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/) covers the transfer.
**Symptom**: no **Download** button on a row that has a working **Restore** button. Downloading is only offered where the backup is held on the same server as the site. Restoring still works. If you need the archive itself rather than a restore, ask Noiz support to retrieve it for you.
**Symptom**: the restore reports that it started but nothing changes. Wait longer than feels reasonable, since a large site takes many minutes, then reload the site in a private window to rule out browser caching. Check whether your application has its own cache layer that is still serving the old pages. If a plugin, extension or edge cache sits in front of the site, clear it before concluding the restore failed.
**Symptom**: the site is broken in a new way after a restore. The usual cause is a mismatch, not a bad backup: restored files against a current database, or a restored database against current files. Restore the matching partner from the same date. If you restored files only and the site now reports a database connection error, the restored configuration file is holding older credentials that no longer exist.
**Symptom**: files you expected to survive are gone after a website restore. This is the restore working as designed rather than a failure. A website restore mirrors the archive over the site directory, so anything added since the backup date is removed. Recover it from the copy you downloaded beforehand. If you did not take one, open a ticket promptly and stop making further changes to the site.
**Symptom**: restored email appears in an unfamiliar folder, or messages are duplicated. Both are expected. Restored mail may arrive in a separate dated folder depending on how the server stores mail, and messages present both in the mailbox and in the backup can end up twice. Let the mail client complete a full sync before tidying anything up, and delete duplicates from the client rather than restoring again.
## Related Guides
- [How to Back Up Websites, Databases and Mailboxes in ISPConfig](/ispconfig/how-to-back-up-your-websites-databases-and-mailboxes-in-ispconfig/)
- [How to Log In to the ISPConfig Control Panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/)
- [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/)
- [How to Create a Database and Database User in ISPConfig](/ispconfig/how-to-create-a-database-and-database-user-in-ispconfig/)
- [How to Create an FTP Account in ISPConfig](/ispconfig/how-to-create-an-ftp-account-in-ispconfig/)
- [How to Monitor Website Usage and Logs in ISPConfig](/ispconfig/how-to-monitor-website-usage-and-logs-in-ispconfig/)
If you are not certain a restore is the right move, ask before you click rather than after. Open a ticket from your Noiz client area with the domain, mailbox or database name, the date you are thinking of restoring to, and what went wrong, and the support team will tell you whether a restore will fix it. Asking costs nothing, and it is the only part of this process that can still be taken back. On Noiz managed plans the team can carry out the restore for you, take the safety copies first, and check the result afterwards.
# How to Secure a Website with a Free SSL Certificate in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-secure-a-website-with-a-free-ssl-certificate-in-ispconfig/
This guide shows you how to secure a website on your Noiz hosting account with a free SSL certificate from Let's Encrypt, so that visitors reach your site over an encrypted `https://` address and see the padlock in their browser. It is written for Noiz clients managing their own hosting through the ISPConfig control panel. An SSL certificate is sometimes called a TLS certificate or an HTTPS certificate; they all mean the same thing. Let's Encrypt is a free, globally trusted certificate authority, and ISPConfig requests and renews its certificates for you automatically, so there is nothing to buy and nothing to renew by hand.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This article follows the official ISPConfig manual procedure for enabling SSL on a website, cross-checked against the current interface. ISPConfig evolves between releases, so if a screen differs from this guide, check the official documentation links below.
### Official Documentation Reference
- [Let's Encrypt Error FAQ (HowtoForge forum)](https://forum.howtoforge.com/threads/lets-encrypt-error-faq.74179/): the official troubleshooting FAQ for ISPConfig's Let's Encrypt integration, maintained by the ISPConfig developers.
- [ISPConfig 3 Documentation](https://docs.ispconfig.org/): the current official documentation site for ISPConfig.
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- The website already exists in ISPConfig. If not, first follow [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/).
- The domain's DNS records point at your Noiz hosting server. This matters more than usual here, as explained in the next section.
## How the Free Certificate Is Issued
Before Let's Encrypt issues a certificate, it proves that you control the domain. ISPConfig places a small verification file on your website, and Let's Encrypt then tries to download that file from the public internet for **every name attached to the website**: the main domain in the **Domain** field, the auto-subdomain (usually `www.yourdomain.com`), and any alias domains or subdomains you have added to the site. If even one of those names does not reach your hosting server, no certificate is issued.
This is why DNS must be right first:
- Every name on the site, for example `yourdomain.com` and `www.yourdomain.com`, must resolve to the Noiz hosting server from the public internet.
- If you have only just pointed the domain at Noiz, allow time for DNS propagation. Changes usually take effect within minutes to a few hours, but can take up to 24 hours worldwide. Ticking the checkbox too early is the single most common reason the certificate fails.
- If the domain sits behind an external proxy or CDN service, requests may not reach the hosting server directly. Switch such a service to DNS-only mode, or pause it, until the certificate has been issued.
A quick test: open `http://yourdomain.com` and `http://www.yourdomain.com` in a browser. If both show your site (or the default welcome page) served from your Noiz account, you are ready to continue.
## Enable the Free SSL Certificate
### Open the website settings
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, under **Websites**, click **Website**, then click the domain name of the site you want to secure. The **Web Domain** form opens on the **Domain** tab.
### Tick SSL and Let's Encrypt SSL
1. On the **Domain** tab, tick the **SSL** checkbox. This enables HTTPS for the website.
2. Tick the **Let's Encrypt SSL** checkbox. This tells ISPConfig to request a free certificate from Let's Encrypt and to keep renewing it automatically. Both boxes must be ticked together, and the panel enforces this for you: ticking **Let's Encrypt SSL** ticks **SSL** automatically, and unticking **SSL** clears **Let's Encrypt SSL**.
3. Click **Save**.
You do not need to visit the **SSL** tab at all. That tab is for creating a self-signed certificate together with a certificate signing request (CSR), which you would use to apply for a certificate from a commercial certificate authority. With Let's Encrypt enabled, the **SSL** tab stays visible but displays a notice that everything on it applies to non-Let's Encrypt certificates only. Leave it alone; ISPConfig fills in and rotates the certificate for you. If you ever want to move to a purchased certificate instead, untick **Let's Encrypt SSL** on the **Domain** tab first.
### Wait for the certificate to be issued
1. After saving, watch for the small red change indicator near the top of the panel. It shows a count of changes not yet applied to the server, and clicking it lists what is still outstanding. ISPConfig is contacting Let's Encrypt, running the domain verification and writing the new web server configuration in the background. This normally takes a minute or two.
2. Once the indicator clears, open the website's settings again and check the **Domain** tab. If **Let's Encrypt SSL** is still ticked, the certificate was issued successfully.
Important: if the verification fails, ISPConfig quietly unticks the **Let's Encrypt SSL** checkbox. If the website did not already have **SSL** switched on before you started, that box is cleared too. The panel does not show an error message, so always re-open the site and check. **Let's Encrypt SSL** is the box to watch, as it is the one that always clears on failure. If it has unticked itself, see the Troubleshooting section below.
## Verify HTTPS Is Working
1. Open `https://yourdomain.com` in a browser. Note the `https://` at the start of the address.
2. Check for the padlock icon next to the address. Click it to view the certificate details; the issuer shows as Let's Encrypt.
3. Repeat for `https://www.yourdomain.com` if the site uses the `www` auto-subdomain.
Let's Encrypt certificates are valid for 90 days, and ISPConfig renews them automatically well before they expire. There is nothing you need to do for renewals; the checkbox stays ticked and the certificate keeps rotating in the background.
## Redirect All Visitors to HTTPS
With the certificate in place, the site answers on both `http://` and `https://`. To make sure every visitor uses the encrypted address:
1. Open the website's settings again and click the **Redirect** tab.
2. Tick the **Rewrite HTTP to HTTPS** checkbox.
3. Click **Save** and wait for the red change indicator to clear.
Anyone who now types the plain `http://` address is sent straight to the secure `https://` version. This also avoids duplicate content issues for search engines. Only enable this after you have confirmed HTTPS works, otherwise visitors would be redirected to an address that fails.
This redirect does not interfere with certificate renewals. ISPConfig writes its redirect rules so that the verification path Let's Encrypt uses, `/.well-known/acme-challenge/`, is left alone. The same applies to the **SEO Redirect** options on the same tab. A redirect you add yourself, however, in an `.htaccess` file or inside your application, can block that path and cause renewal to fail, so exclude `/.well-known/` from any redirect rule you write by hand.
## Troubleshooting
- **The Let's Encrypt SSL checkbox unticks itself after saving**: the Let's Encrypt verification failed, and this is by far the most common problem. Almost always, one of the names attached to the site does not resolve to the hosting server yet. Check the main domain, the `www` name and every alias domain or subdomain on the site, fix the DNS records, wait for propagation, then edit the site and tick the boxes again.
- **DNS was changed recently and the certificate still fails**: propagation may not have finished. Wait a few hours and try again. Repeatedly re-ticking the box within minutes does not help and can trigger temporary rate limits at Let's Encrypt, which then force a longer wait.
- **The certificate fails while a proxy or CDN service sits in front of the domain**: the verification requests are not reaching the hosting server. Set the service to DNS-only mode, or pause it, tick the boxes again, and re-enable the proxy once the certificate has been issued.
- **HTTPS works on `yourdomain.com` but not on `www.yourdomain.com`**: the `www` name is either missing a DNS record or is not attached to the website. Check that **Auto-Subdomain** on the **Domain** tab is set to **www.** and that a DNS record for `www` points at the server, then save and re-tick the checkboxes if needed.
- **The browser shows a certificate warning straight after enabling SSL**: the new configuration may still be rolling out. Wait for the red change indicator to clear, then reload the page with a hard refresh. If the warning persists, re-open the site settings and confirm the checkboxes are still ticked.
- **The padlock shows "not fully secure" or a warning triangle**: the certificate is fine, but the page loads some images, styles or scripts over plain `http://`. This is called mixed content. Update your site's own settings and content to use `https://` addresses; in WordPress, for example, change the site address settings to the `https://` version.
- **An alias domain or subdomain added later broke the certificate renewal**: every name on the site is re-verified at renewal time, so a new alias without working DNS can cause a failure. Make sure any name you add to the website resolves to the server before you add it. If a particular name cannot be made to resolve, for example one that is parked elsewhere, open that alias domain or subdomain and tick **Don't add to Let's Encrypt certificate**. That leaves the name off the certificate so it stops blocking issue and renewal for the rest of the site.
If you get stuck at any point, open a support ticket with the Noiz support team and include the domain name, the approximate time you ticked the **Let's Encrypt SSL** checkbox, and whether that checkbox was still ticked when you re-opened the website settings.
# How to Secure the ISPConfig Control Panel with an SSL Certificate
Source: https://docs.noiz.ie/ispconfig/how-to-secure-the-ispconfig-control-panel-with-an-ssl-certificate/
This guide shows you how to secure the ISPConfig control panel with a valid SSL certificate, so that the panel loads over an encrypted `https` connection with no browser warning. It is written for clients who run their own **self-managed ISPConfig server**, meaning a virtual or dedicated server on which you hold root and SSH access. The control panel, also called the ISPConfig web interface or admin interface, listens on port `8080`. When no trusted certificate is in place, ISPConfig falls back to a self-signed one, which encrypts the traffic but makes your browser show a "not secure" or "your connection is not private" warning because nothing external vouches for it. Replacing that with a free certificate from Let's Encrypt, a trusted public certificate authority, removes the warning and proves the panel genuinely belongs to your server. SSL certificates are also called TLS certificates; the two terms mean the same thing here.
If Noiz manages your server for you, the panel certificate is already handled and you do not need to follow this guide. It applies only when you administer the ISPConfig server yourself.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig 3 User Manual](https://www.ispconfig.org/documentation/user-manual/): the official manual; enabling SSL for the ISPConfig web interface is covered in section 6.2, and the control panel port is described in section 4.2.
- [Securing ISPConfig With a Free Let's Encrypt SSL Certificate (ISPConfig blog)](https://www.ispconfig.org/blog/securing-ispconfig-3-1-free-lets-encrypt-ssl-certificate/): the official article on using Let's Encrypt for the panel, noting that ISPConfig 3.2 and newer do this automatically through the built-in acme.sh client.
- [HowtoForge: Securing ISPConfig With a Free Let's Encrypt SSL Certificate](https://www.howtoforge.com/tutorial/securing-ispconfig-3-with-a-free-lets-encrypt-ssl-certificate/): community walkthrough that states clearly that from ISPConfig 3.2 onward Let's Encrypt is built in and the panel certificate is configured for you at install time.
- [Let's Encrypt: Getting Started](https://letsencrypt.org/getting-started/): background on the free certificate authority ISPConfig uses, including how domain validation works over ports 80 and 443.
- [acme.sh project page](https://github.com/acmesh-official/acme.sh): the ACME client that ISPConfig 3.2 and newer use behind the scenes to request and renew the certificate.
## Prerequisites
- You know how to [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/) as the `admin` user, which you need for the second method below and to confirm the result.
- Root or `sudo` access to the server over SSH, because the recommended method runs a command-line script.
- The server has a fully qualified hostname (FQDN), for example `server1.yourdomain.com` (an example value), set as its system hostname. Confirm it with `hostname -f`.
- That hostname resolves in **public DNS** to the server's public IP address, through an `A` record (and an `AAAA` record if you use IPv6).
- Ports `80` and `443` are open to the internet. Let's Encrypt validates ownership over those ports, not over `8080`.
- The server runs ISPConfig 3.2 or newer, so Let's Encrypt is built in. Noiz servers run 3.3.1p1, which meets this.
- A short maintenance window, because issuing the certificate briefly restarts the web, mail and FTP services.
## How Panel SSL Works in ISPConfig 3.3
Since version 3.2, ISPConfig manages Let's Encrypt for every service itself, using the `acme.sh` client rather than the older Certbot scripts. On a fresh install, if the server hostname already resolves publicly and ports 80 and 443 are reachable, ISPConfig requests a Let's Encrypt certificate for the hostname and points the control panel at it automatically. In that case there is nothing more to do.
You need this guide when that did not happen: the hostname was not yet pointed at the server during installation, the firewall was closed at the time, or the server was installed before DNS was ready. In those cases the panel keeps its self-signed certificate until you ask ISPConfig to issue a proper one.
The panel certificate always lives in one place, whichever web server you run:
```
/usr/local/ispconfig/interface/ssl/ispserver.crt the certificate and chain
/usr/local/ispconfig/interface/ssl/ispserver.key the private key
/usr/local/ispconfig/interface/ssl/ispserver.pem key and certificate combined
/usr/local/ispconfig/interface/ssl/ispserver.bundle the certificate authority chain, used only if present
```
The panel virtual host (`/etc/apache2/sites-available/ispconfig.vhost` on Apache, or `/etc/nginx/sites-available/ispconfig.vhost` on nginx) references `ispserver.crt` and `ispserver.key` by these fixed paths, so nothing has to be re-pointed when the certificate changes. When ISPConfig obtains a Let's Encrypt certificate for the hostname, `acme.sh` writes the new certificate and key straight into those two files, and ISPConfig rebuilds `ispserver.pem` from them. Mail and FTP are then attached by symbolic link: Postfix's `smtpd.cert` and `smtpd.key` point at `ispserver.crt` and `ispserver.key`, Dovecot reads the Postfix pair, and Pure-FTPd's `/etc/ssl/private/pure-ftpd.pem` points at `ispserver.pem`. That is why one certificate covers the panel, mail and FTP at once.
## Method 1: Issue the Certificate With the ISPConfig Updater
This is the recommended way on ISPConfig 3.3. The updater has a built-in step that requests a fresh Let's Encrypt certificate for the hostname and wires the panel, mail and FTP services to it in one pass. It does not require you to create a website first.
### Step 1: Confirm the Hostname Resolves and the Ports Are Open
Log in to the server over SSH and check that the hostname points at this server in public DNS:
```
hostname -f
dig +short A server1.yourdomain.com
```
The `dig` result must return the server's own public IP address. If it returns nothing or the wrong address, fix the DNS `A` record first and wait for it to propagate, otherwise the certificate request will fail. Confirm that inbound ports 80 and 443 are open in any firewall in front of the server. The validation request arrives on those ports, so a block there is the most common cause of failure.
### Step 2: Run the ISPConfig Updater
As root, start the updater:
```
ispconfig_update.sh
```
At `Select update method (stable,git-stable,git-master) [stable]:` choose `stable`, which is the method ISPConfig documents for production systems. Allow the updater to create a backup when prompted, and at `Reconfigure Services? (yes,no,selected) [yes]:` accept `yes`. Reconfiguring services is what lets the updater refresh the certificate.
### Step 3: Answer the SSL Certificate Prompt
During the reconfigure stage the updater reaches this question:
```
Create new ISPConfig SSL certificate (yes,no) [no]:
```
Type `yes` and press Enter. ISPConfig first checks that the hostname's `A` or `AAAA` record already resolves to one of the server's own public addresses. If it does not, the updater asks **Ignore DNS check and continue to request certificate?**. Treat that question as a warning that the DNS is wrong: answer `n`, correct the record, and start again, because forcing past it almost always ends in a failed validation.
With the check passed, ISPConfig asks `acme.sh` to request a Let's Encrypt certificate for the hostname, writes it into `ispserver.crt` and `ispserver.key`, and rebuilds `ispserver.pem`. Two follow-up questions, **Symlink ISPConfig SSL certs to Postfix?** and **Symlink ISPConfig SSL certs to Pure-FTPd?**, both default to `y`; accept both so that mail and FTP present the same certificate as the panel. If Let's Encrypt cannot validate the hostname for any reason, ISPConfig falls back to a self-signed certificate so the panel still works; in that case see the Troubleshooting section.
Let the updater finish. It restarts the affected services at the end.
### Step 4: Verify the New Certificate
Check who issued the certificate that is now in place:
```
openssl x509 -in /usr/local/ispconfig/interface/ssl/ispserver.crt -noout -issuer -subject -dates
```
The issuer should name Let's Encrypt and the subject should match your hostname. `acme.sh` also keeps its own copy under `/root/.acme.sh/`, in a directory named after the hostname with an `_ecc` suffix, so `ls /root/.acme.sh/` is a quick second confirmation that a certificate was really issued. Now check the certificate the panel actually presents:
```
echo | openssl s_client -connect server1.yourdomain.com:8080 -servername server1.yourdomain.com 2>/dev/null | openssl x509 -noout -issuer -subject -dates
```
This should report the same issuer and subject, which proves the panel is serving the new certificate and not a cached one. Finally, open `https://server1.yourdomain.com:8080` in a browser. The address bar should show a padlock with no warning. Use the exact hostname, not the IP address, because a public certificate authority cannot certify a bare IP.
## Method 2: Issue the Certificate Through a Hostname Website
Use this alternative when the updater step reports success but the certificate still comes back self-signed, or when you prefer to manage the hostname the same way as any other site. You create a website in ISPConfig whose domain is the server hostname, let Let's Encrypt issue against it, then adopt that certificate for the panel.
### Step 1: Add the Server Hostname as a Website
1. Log in to the control panel as `admin`.
2. Go to **Sites** > **Websites** > **Website**, then click **Add new website**.
3. In **Domain**, enter the server hostname, for example `server1.yourdomain.com` (an example value).
4. Set **Auto-Subdomain** to `none`. It defaults to `www.`, which pulls `www.server1.yourdomain.com` into the certificate request, and that name rarely exists for a server hostname.
5. Tick **Let's Encrypt SSL**, which ticks **SSL** for you. Leave the remaining defaults alone.
6. Click **Save**.
### Step 2: Wait for Let's Encrypt to Issue
ISPConfig creates the site first and only then turns Let's Encrypt on, so the request runs a moment after the save rather than during it. It normally completes within a minute or two, provided the hostname resolves and ports 80 and 443 are open. You can confirm issuance from the server:
```
ls -l /root/.acme.sh/server1.yourdomain.com_ecc/
```
A certificate file appearing in that directory means the request succeeded. If instead the **Let's Encrypt SSL** and **SSL** boxes have quietly cleared themselves when you reopen the site, the request failed and ISPConfig turned them back off; work through the Troubleshooting section before continuing.
### Step 3: Point the Panel Certificate at It
With a valid Let's Encrypt certificate now present for the hostname, run the updater again and answer `yes` to the SSL prompt exactly as in Method 1, Steps 2 and 3. This time ISPConfig finds the certificate that already exists for the hostname and installs it into the `ispserver` files rather than requesting a new one. Verify the result with Step 4 of Method 1.
## Keeping the Certificate Valid
Let's Encrypt certificates last 90 days. ISPConfig, through `acme.sh`, installs a scheduled task that renews the certificate automatically around the 60-day mark, well before it expires. At each renewal `acme.sh` writes the new certificate back into the same `ispserver` files and runs an ISPConfig hook that rebuilds `ispserver.pem` and restarts the web, mail, FTP and database services, so every one of them picks up the fresh certificate with no action from you. You do not need to repeat this procedure at each renewal; you would only repeat it if you rebuild the server, change its hostname, or move it to a new IP address.
To confirm the renewal schedule is in place, check the root crontab for the acme.sh entry:
```
crontab -l | grep acme
```
## Troubleshooting
- **The certificate came back self-signed.** Let's Encrypt could not validate the hostname. Confirm `dig +short A server1.yourdomain.com` returns this server's public IP, and that ports 80 and 443 are open from the internet. Review the client log at `/var/log/ispconfig/acme.log` for the exact reason, then rerun Method 1.
- **The browser still warns after issuing.** The old certificate may be cached in the browser or the web server was not reloaded. Restart the panel's web server, either `systemctl restart apache2` or `systemctl restart nginx` depending on your install, then close and reopen the browser or do a hard refresh.
- **Validation times out on port 80.** A firewall rule or an automatic security block can silently drop the incoming validation request. Make sure inbound port 80 is permitted from any address during issuance, as Let's Encrypt does not announce which of its servers will connect.
- **"Too many certificates already issued."** Let's Encrypt limits how many identical certificates you can request in a rolling week. If you have retried many times, wait an hour or a day and try once more rather than repeating immediately.
- **The certificate names the wrong host.** A public certificate is tied to the exact hostname. Always open the panel at `https://server1.yourdomain.com:8080`, using the certified hostname, not at `https://:8080`. IP addresses cannot receive a Let's Encrypt certificate.
- **A CAA record is blocking issuance.** If the domain has a `CAA` DNS record that names a different authority, Let's Encrypt refuses to issue. Either remove it or add `letsencrypt.org` to the allowed authorities.
- **You run more than one ISPConfig server.** Each server certifies its own hostname. Repeat the procedure on every server whose panel you want secured.
If the certificate will not issue after these checks, or you are unsure whether a firewall or DNS change is safe to make, open a support ticket with the Noiz support team. Include your server hostname, the output of `dig +short A server1.yourdomain.com`, and the last few lines of `/var/log/ispconfig/acme.log`, and the Noiz team will help you get the panel secured.
# How to Set Database User Privileges in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-set-database-user-privileges-in-ispconfig/
This guide explains what a database user is allowed to do in ISPConfig, how to control it, and how to apply the security principle of **least privilege** so that each application on your Noiz hosting account can only do what it genuinely needs. "Privileges" are the same thing as database permissions or grants: the specific actions, such as reading rows or creating tables, that a MySQL or MariaDB user is authorised to perform. This is the companion to creating the database itself; if you have not yet made a database and a database user, do that first, then return here to understand and tighten what that user can do.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1** (latest stable). This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig and MySQL/MariaDB documentation linked below. ISPConfig and the underlying database server evolve between releases, so if a privilege list on your system differs slightly from the examples here, treat the official references as authoritative for the exact wording.
### Official Documentation Reference
- [ISPConfig 3 Documentation](https://docs.ispconfig.org/): the official online documentation for the current ISPConfig interface, including the Sites module and its Databases and Database Users forms.
- [How to Add a Website, MySQL Database and Users in ISPConfig (HowtoForge)](https://www.howtoforge.com/ispconfig-website/): a current walkthrough of the database and database-user forms, maintained by the ISPConfig developers' documentation site.
- [Privileges Provided by MySQL](https://dev.mysql.com/doc/refman/8.0/en/privileges-provided.html): the authoritative reference for exactly what each privilege (SELECT, INSERT, CREATE, GRANT OPTION, SUPER, FILE and the rest) permits.
- [MariaDB GRANT statement](https://mariadb.com/kb/en/grant/): the equivalent reference for MariaDB, the database engine used on much of Noiz's Linux hosting; the privilege names match MySQL.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- A database and at least one database user already exist on your account. If not, follow [How to Create a Database and Database User in ISPConfig](/ispconfig/how-to-create-a-database-and-database-user-in-ispconfig/) first; that guide also shows how to open the database in phpMyAdmin, which you will use later on this page to fine-tune privileges.
## How ISPConfig Handles Database Privileges
This is the single most important thing to understand, because it differs from what you might expect if you have used raw MySQL commands. ISPConfig does **not** give you a grid of privilege checkboxes on the Database User form. Instead it offers a deliberately simple, two-role model on the **Database** form, and it sets the underlying grants for you:
- **Database user** (the main, read-write role): the user you select here is granted the full working set of privileges on that one database, by way of a single `GRANT ALL PRIVILEGES` scoped to that database alone. In practical terms that means it can read, write, and change the structure of the database: everything a normal web application needs to install and run.
- **Read-only database user** (optional second role): a user attached here is granted exactly one privilege, `SELECT`. It can browse and export data but cannot insert, update, delete, or alter anything.
Crucially, whichever role you choose, ISPConfig scopes the grant to that specific database and never hands out server-wide administrative privileges. A hosting database user on Noiz can only ever touch the database (or databases) it is linked to. It is never given the ability to manage the database server, other clients' data, or the underlying operating system. That platform-level boundary does a large part of the least-privilege job for you before you make any choices at all.
There is a third state that you do not choose, and it catches people out. If a database exceeds its **Database quota**, ISPConfig automatically downgrades the main user's grant: the user keeps `SELECT`, `DELETE`, `ALTER` and `DROP`, but loses `INSERT` and `UPDATE`. The intention is to let you clear space rather than lock you out of the data entirely. The full grant is restored automatically once usage falls back below the quota. A site that suddenly cannot write, with no privilege change on your part, is very often an over-quota database rather than a broken user.
## The Principle of Least Privilege
Least privilege means giving each user exactly the permissions it needs to do its job, and nothing more. If a database user is ever compromised, for example through a vulnerability in a plugin or a leaked configuration file, an attacker inherits precisely that user's privileges. A tightly scoped user limits the blast radius to a single database; an over-privileged one can become a foothold into much more.
The reassuring news on Noiz ISPConfig hosting is that the most dangerous privileges are never granted to a hosting database user in the first place. An application user almost never needs any of these, and ISPConfig does not give them out:
- **GRANT OPTION**: lets a user hand its own privileges to other users. On shared hosting this would let one account escalate its own access, so it is withheld.
- **SUPER** (and its modern replacements): server-administration power such as killing other sessions or changing global server settings. This is a server-management privilege, not an application one.
- **FILE**: the ability to read and write files on the server's filesystem through the database (via `LOAD DATA INFILE` and `SELECT ... INTO OUTFILE`). This is a classic route for reading files that do not belong to you, and it is never appropriate for a website's database login.
- **PROCESS, RELOAD, SHUTDOWN, CREATE USER**: other server-wide administrative privileges that a single website has no reason to hold.
Because ISPConfig withholds all of these automatically, the one least-privilege decision that is actually in your hands is simple: **does this particular user need to write, or only to read?** Give an application its normal read-write user, but if you are wiring up something that should only ever look at data (a reporting dashboard, an analytics feed, a public read-only mirror), attach it as the read-only user instead of the main one.
## What the Common Privileges Actually Mean
Even though ISPConfig sets the grants for you, it helps to know what the read-write user is being given, so you can reason about what an application needs. Privileges fall into a few natural groups.
### Data privileges (day-to-day application use)
These are the four your application uses on every page load. Collectively they are known as DML, or data manipulation:
- **SELECT**: read rows from tables. Needed by absolutely everything, including read-only users.
- **INSERT**: add new rows, for example when a visitor submits a comment or an order.
- **UPDATE**: change existing rows, for example editing a post or updating a stock count.
- **DELETE**: remove rows.
A content-managed site that has already been installed spends almost all of its time using only these four. In principle, a fully installed and settled application could run on SELECT, INSERT, UPDATE and DELETE alone.
### Structure privileges (installers and updates)
These change the shape of the database rather than its contents, and are known as DDL, or data definition:
- **CREATE** and **DROP**: make and remove tables.
- **ALTER**: change a table's columns or indexes, for example adding a new field.
- **INDEX**: add or remove indexes to speed up queries.
An application needs these at two specific moments: during initial installation, when it builds its tables, and during upgrades, when a new version of the software or a plugin adds or reshapes tables. WordPress core updates, Joomla extension installs, and database migration scripts all rely on DDL privileges. This is why installers ask for a user with full access rather than a read-only one.
### Utility privileges
- **LOCK TABLES** and **CREATE TEMPORARY TABLES**: used by some applications for consistency during multi-step operations, and by backup tools such as `mysqldump` to produce a consistent export.
- **CREATE VIEW / SHOW VIEW**, **CREATE ROUTINE / ALTER ROUTINE / EXECUTE**, **TRIGGER**, **EVENT**: used by more advanced applications that define views, stored procedures, triggers, or scheduled events. Most simple sites never use them, but the read-write user holds them so that software which does use them works without a support ticket.
The ISPConfig read-write user is granted the data, structure, and utility privileges above, all confined to its own database. It is not granted GRANT OPTION or any server-wide privilege. The read-only user is granted exactly one privilege, **SELECT**. That is enough to browse and export data but not to change it. Note that it does not include LOCK TABLES, so a `mysqldump` run as the read-only user needs `--single-transaction` or `--skip-lock-tables` to complete.
## Choosing the Right Role in ISPConfig
Applying least privilege in the ISPConfig interface comes down to picking the correct role when you link a user to a database:
1. Log in to the ISPConfig control panel and open the **Sites** module.
2. Under **Databases** in the left menu, click **Databases** and open the database you want to configure, or click **Add new Database** to create one.
3. In the **Database user** drop-down, select the user that your application will use to read and write data. This is the read-write role and suits the vast majority of websites.
4. Use the **Read-only database user** drop-down only when you have a second user that must never modify data. Leave it set to **None** otherwise. Do not put the same user in both fields: ISPConfig applies the read-only grant after the read-write one, so a user named in both ends up holding SELECT alone and the application loses its write access.
5. Click **Save** and wait for the small red change indicator near the top of the panel to clear; ISPConfig applies the grants on the server in the background, usually within a minute.
A single database user can be linked to more than one database if you reuse it across the Database form for several sites. Each link is scoped independently, so the same login can be read-write on one database and never touch another.
## Fine-Tuning Privileges Beyond the Two Roles
ISPConfig's two-role model is the right tool for almost every situation, and Noiz recommends staying with it. If you have a specific hardening requirement that the two roles cannot express, for example trimming a settled application's user down to data privileges only after installation, the panel-agnostic tool for that is **phpMyAdmin**, which you reach from the database row in ISPConfig as described in [How to Create a Database and Database User in ISPConfig](/ispconfig/how-to-create-a-database-and-database-user-in-ispconfig/).
Inside phpMyAdmin, with the database selected, the **Privileges** tab lists the users attached to that database and lets you edit the exact privileges a user holds on it. From there you could, for instance, remove the structure (DDL) privileges from an application user once it is fully installed, then re-grant them temporarily whenever you run an upgrade.
Two important cautions before you do this:
- **Many applications break if you remove structure privileges.** Auto-updaters in WordPress, Joomla, and similar software expect to be able to alter tables at any time. If you strip DDL from the user, updates can fail with permission errors until you restore it. Only trim privileges on an application you understand well, and document what you changed.
- **ISPConfig may reassert its own grants.** Because ISPConfig manages the read-write and read-only roles, editing the same database later in the panel (for example re-saving the Database form) can restore the full role grants. Treat manual privilege trimming as an advanced, self-managed customisation, and re-check it after any change made through ISPConfig.
## How ISPConfig Keeps a User Scoped to One Database
Three mechanisms work together so that a hosting database user stays inside its own lane:
- **Per-database grants.** When you link a user to a database, ISPConfig grants privileges on that one named database, not on the whole server. A user linked to `c1shop` has no access to `c1blog` unless you separately link it there too.
- **Account name prefixes.** ISPConfig automatically prefixes database and user names with a per-account code, for example `c1`, so names cannot collide with, or be confused for, another client's. Your real database and username always include this prefix.
- **Connection host restriction.** On a standard Noiz hosting account the database is reached over `localhost`, meaning the user only works for software running on the same server as the database. External connections are refused unless you deliberately enable **Remote Access** on the Database form. If you do enable it, fill in **Remote Access IPs** as well, which takes a comma-separated list of addresses. Read that field's label carefully: leaving it blank does not mean "no remote hosts", it means *any* host may connect. Access over `localhost` remains available either way. Leaving remote access off entirely is both the more secure and the least-privilege default.
## Troubleshooting
- **An install or upgrade fails with a permissions or "command denied" error**: the user probably lacks the structure (DDL) privileges the installer needs, most often because it was attached as the read-only user or was manually trimmed in phpMyAdmin. Re-link it as the main **Database user** on the Database form, or restore its structure privileges, then run the install again.
- **Writes fail but reads still work**: check the database against its **Database quota** on the Database form. An over-quota database has its main user's INSERT and UPDATE privileges withdrawn automatically, which leaves reads and deletions working and makes the fault look like a corrupted user. Free up space or ask for a larger quota, and the full grant returns on its own.
- **A read-only integration can still write data**: check the Database form. The user must be in the **Read-only database user** field, not the main **Database user** field. A user placed in the main field always has full read-write access regardless of your intent.
- **You cannot find privilege checkboxes in ISPConfig**: this is expected. ISPConfig intentionally exposes only the read-write and read-only roles. Per-privilege editing is done in phpMyAdmin, not in the ISPConfig panel.
- **Manual privilege changes disappeared**: re-saving the database in ISPConfig can reapply the role's standard grants. Reapply your customisation in phpMyAdmin, and avoid re-editing that database through the panel unless necessary.
- **An external tool is refused**: the user is scoped to `localhost` by default. Remote connections require **Remote Access** to be enabled with the connecting IP address listed. For occasional administration, using phpMyAdmin from within the panel avoids opening remote access at all.
If you are unsure which privileges an application needs, or you want help hardening a database user without breaking updates, open a support ticket with the Noiz support team and include the database name, the database username, and the website it belongs to. Never include the database password in a ticket. On managed plans, Noiz can review and apply a least-privilege configuration for you.
# How to Set Up Email Forwarding in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-set-up-email-forwarding-in-ispconfig/
This guide shows you how to set up email forwarding in the ISPConfig control panel on your Noiz hosting account, so that mail sent to an address on your domain is automatically passed on to one or more other addresses. Those destinations can be on the same domain, on another domain hosted with Noiz, or completely external (for example a Gmail or Outlook.com address). An email forward is sometimes called a redirect or a forwarder, and this guide also explains how it differs from an email alias and from sending a copy of a mailbox's mail elsewhere.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This article follows the official ISPConfig manual procedure for creating an email forward, cross-checked against the current interface. ISPConfig evolves between releases, so if a screen differs from this guide, check the official documentation links below.
### Official Documentation Reference
- [ISPConfig 3 Documentation: Mail module](https://docs.ispconfig.org/category/modules/mail/)
- [ISPConfig official documentation and manual overview](https://www.ispconfig.org/documentation/)
- [ISPConfig developer guidance on forwarding to external mailboxes](https://forum.howtoforge.com/threads/forwarding-emails-to-external-mailbox.87152/)
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- The domain you want to forward from is already set up as an email domain on your account. You can check this under the **Email** tab, in the **Domain** list under **Email Accounts**.
- You know the destination address or addresses the mail should be delivered to.
- If you want to keep a copy in a mailbox as well as forwarding, that mailbox must already exist. See [how to create an email mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/).
## Forward, alias or mailbox copy: which one do you need?
ISPConfig offers three related features, and picking the right one saves you time:
- **Email Forward**: passes mail for an address on to one or more destination addresses, which may be internal or external. No mailbox exists for the forwarding address itself, so no copy is stored on the server. This is the feature covered by this guide.
- **Email Alias**: an alternative name for exactly one existing mailbox on your hosting account. You pick the destination mailbox from a drop-down list, so an alias can never point to an external address and cannot have multiple targets. Use an alias when you want `info@yourdomain.com` and `enquiries@yourdomain.com` to be the same mailbox.
- **Send copy to** on a mailbox: the mailbox keeps receiving and storing mail as normal, and a copy of each incoming message is also sent to another address. Use this when the address already has a mailbox, because ISPConfig will not let you create an Email Forward for an address that already has an active mailbox.
## Create an email forward
### Step 1: Open the Email Forward list
1. Log in to the ISPConfig control panel.
2. Click the **Email** tab in the top menu.
3. In the left-hand menu, under **Email Accounts**, click **Email Forward**. A list of any existing forwards on your account appears.
### Step 2: Add the forward
1. Click **Add new Email forward**. The **Email Forward** form opens.
2. The **Email** field is split in two. Type the part of the address before the @ sign, known as the local part, into the text box, then select your domain from the drop-down after the @ sign. For example, to forward mail sent to `sales@yourdomain.com`, type `sales` and select `yourdomain.com`. The local part must not already exist as a mailbox or alias on the domain.
3. In the **Destination Email** box, enter the address the mail should be forwarded to, for example `owner@example-destination.com`. The destination can be any valid email address, internal or external.
4. Make sure **Active** is ticked, otherwise the forward is saved but does nothing.
5. Leave **Send as** and **Enable greylisting** unticked unless you need them (both are explained below).
6. Click **Save**.
ISPConfig applies the change to the mail server through a background job, so allow a minute or two before sending a test message to the new address.
### Forward to multiple destinations
To send incoming mail to several people at once, enter one address per line in the **Destination Email** box:
```
owner@example-destination.com
manager@yourdomain.com
accounts@another-example.com
```
Every destination receives its own copy of each incoming message. This is a simple way to run a small group address, for example `team@yourdomain.com` reaching everyone in the team, without creating a mailing list.
### Optional settings on the forward
- **Send as**: if the destination is a mailbox hosted on your Noiz account, ticking this lets the person logged in to that mailbox use the forwarding address as the sender address on outgoing mail. ISPConfig spells this out beside the checkbox: it only applies if the target is internal, so it has no effect for external destinations.
- **Enable greylisting**: briefly delays the very first message from an unknown sender as an anti-spam measure. Legitimate mail servers retry automatically, but expect a short delay on first contact from new senders if you enable this.
## Forward mail for an existing mailbox
If the address already has a mailbox with **Enable receiving** switched on, ISPConfig refuses to create a forward for it and shows the error **There is already a mailbox with this email address**. Use the mailbox's copy setting instead:
1. Go to **Email** and click **Email Mailbox** in the left-hand menu.
2. Click the mailbox address to open it. Stay on the **Mailbox** tab.
3. In the **Send copy to** field, enter the address that should receive a copy of every incoming message. Separate multiple addresses with commas, for example `owner@example-destination.com, backup@another-example.com`.
4. Click **Save**.
The mailbox keeps a full copy of everything, and the destination receives a copy too. If you want the mail passed on without a copy building up in the mailbox, tick **Disable (local) delivering** on the same tab. Mail is then forwarded to the **Send copy to** address instead of being delivered to the inbox, and the mailbox, its password and its existing mail all stay in place. The other option is to delete the mailbox and create an Email Forward for the address as described above, but only do that after saving any messages you still need, because deleting a mailbox deletes its stored mail.
## Edit, disable or delete a forward
1. Go to **Email** and click **Email Forward** in the left-hand menu.
2. Click the forward you want to change.
3. Add or remove lines in the **Destination Email** box to change where mail goes, or untick **Active** to switch the forward off while keeping it saved.
4. Click **Save**, or click **Delete** to remove the forward entirely.
## Troubleshooting
**Symptom**: saving the forward fails with **There is already a mailbox with this email address**. Fix: the address has an active mailbox, so use the mailbox's **Send copy to** field instead, as described above, or delete the mailbox first if you no longer need it.
**Symptom**: forwarded mail bounces at the destination or lands in its spam folder. Fix: forwarding passes messages on with the original sender's address, and strict sender-checking policies (SPF and DMARC) at the receiving provider can mark such mail as suspicious. Ask the recipient to add the forwarded address to their contacts or safe senders list. For important mail, a more reliable setup is a real mailbox with **Send copy to**, or collecting mail directly from a mailbox on your domain instead of forwarding it.
**Symptom**: the error **The max. number of email forwarders for your account is reached** appears. Fix: your hosting package has reached its forward limit. Open a support ticket with the Noiz support team to discuss raising the limit.
**Symptom**: a new forward does not work straight after saving. Fix: allow a minute or two for the server to apply the change, confirm **Active** is ticked, and check every destination address for typing errors. Each destination must be a complete, valid email address.
**Symptom**: saving fails with **The destination contains at least one invalid email address**. Fix: the **Destination Email** box must contain only email addresses, one per line, with no extra text, angle brackets or trailing punctuation.
If you get stuck at any point, open a support ticket with the Noiz support team and include the forwarding address, the destination addresses, and the exact error message or what happened to your test message.
# How to Set Up a Website Redirect in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-set-up-a-website-redirect-in-ispconfig/
This guide shows you how to set up a website redirect in the ISPConfig control panel, so that visitors who open one address are sent on to another website, to a folder within your own site, or to your preferred `www` or non-`www` address. It is written for Noiz clients managing their own hosting account through ISPConfig. A redirect is sometimes called web forwarding, URL forwarding or domain forwarding; in ISPConfig it is configured on the **Redirect** tab of a website. This article also explains the difference between permanent (301) and temporary (302) redirects, which matters for search engine rankings.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This article follows the official ISPConfig manual procedure for redirecting a website, cross-checked against the current interface. ISPConfig evolves between releases, so if a screen differs from this guide, check the official documentation links below.
### Official Documentation Reference
- [ISPConfig Documentation overview](https://www.ispconfig.org/documentation/): the index of all official ISPConfig documentation, including the full manual that describes the Redirect tab.
- [The basics of setting up your first site (ISPConfig 3 Documentation)](https://docs.ispconfig.org/modules/sites/the-basics-of-setting-up-your-first-site/): the official walkthrough of the Sites module where the website form and its tabs live.
- [Subdomains (ISPConfig 3 Documentation)](https://docs.ispconfig.org/creating-web-sites/subdomains/): the official notes on subdomains, which can also be redirected using the same fields described here.
- [Apache mod\_rewrite flags reference](https://httpd.apache.org/docs/current/rewrite/flags.html): the upstream documentation for the `R` and `L` flags that ISPConfig's redirect types are built on.
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- An existing website in ISPConfig to attach the redirect to. If you have not created one yet, follow [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/) first.
- The DNS records of the domain you are redirecting must point at your Noiz hosting server. The redirect is performed by the web server, so the visitor's browser has to reach your server before it can be sent anywhere else.
- The full target address you want visitors to end up at, for example `https://www.anotherdomain.com/`.
## How ISPConfig Redirects Work
Behind the scenes, ISPConfig turns the settings on the **Redirect** tab into web server rewrite rules, so you get a proper server-side redirect without editing any configuration files. The tab covers three separate jobs, and you can use each one on its own:
- **URL and directory redirects**: the **Redirect Type** and **Redirect Path** fields send the whole website to another address, or serve it from a subfolder of its own web space.
- **SEO redirects**: the **SEO Redirect** drop-down permanently redirects between the `www` and non-`www` versions of your domain so search engines only ever see one address.
- **HTTPS enforcement**: the **Rewrite HTTP to HTTPS** checkbox sends every plain `http://` request to the secure `https://` version of your site.
### Permanent (301) or temporary (302)?
Every visible redirect carries an HTTP status code, and the two that matter are:
- `301` (permanent): tells browsers and search engines the move is final. Search engines transfer the old address's rankings to the new one and update their index, which makes 301 the right choice when a site has moved for good. Browsers cache 301 redirects aggressively, so once one has been seen it keeps working even if you later change the setting.
- `302` (temporary): tells browsers and search engines the move is short-term. Search engines keep the original address in their index, so use 302 for maintenance pages, short campaigns or anything you plan to undo.
The rule of thumb for search engine optimisation: if the old address should disappear from search results in favour of the new one, use a 301. If you are experimenting or the redirect is temporary, use a 302, and switch to a 301 once you are sure. In ISPConfig's **Redirect Type** list, options labelled **Temporary redirect** issue a 302 and the option labelled **Permanent redirect** issues a 301.
## Open the Redirect Tab
1. Log in to the ISPConfig control panel.
2. Click the **Sites** module in the top navigation.
3. In the left menu, under **Websites**, click **Website**, then click the domain name of the site you want to redirect.
4. Click the **Redirect** tab at the top of the website form.
The drop-downs only list the options that apply to the web server behind your site, so you may see fewer entries than a screenshot from another server shows. The **Redirect Type** labels used below are the Apache ones; on a server running nginx the list shows nginx flags such as **last**, **break**, **redirect** and **permanent** instead. An advanced **proxy** entry may also appear in the **Redirect Type** list; the manual documents it as an nginx-only option that displays content from another location without changing the address in the browser, so leave it alone unless Noiz support asks you to use it.
## Redirect Your Website to Another Website
Use this when the whole site should send visitors to a different address, for example after a rebrand from `yourolddomain.com` to `yournewdomain.com`.
### Choose the Redirect Type
1. Open the **Redirect Type** drop-down.
2. For a permanent move, select **R=301,L (Permanent redirect + last rule)**. This is the SEO-friendly 301 redirect described above.
3. For a temporary move, select **R,L (Temporary redirect + last rule)** instead, which issues a 302.
The official manual recommends the combined `R,L` style flags for any redirect to a URL. Avoid **R (Temporary redirect)** on its own: the manual explains that without the accompanying `L` flag, `R` passes the rewritten address on to the next rule in the set, which often results in "Invalid URI in request" warnings.
### Enter the Redirect Path
1. In the **Redirect Path** field, enter the full target URL, including the scheme and a trailing slash, for example `https://www.yournewdomain.com/`. You can also target a specific folder on the destination site, for example `https://www.yournewdomain.com/shop/`. The manual is explicit that the URL should end in a trailing slash, and the slash does real work: with it, the rest of the requested address is carried across, so a visitor asking for `/about.html` lands on `/about.html` at the new domain. Leave the slash off and every request lands on the bare target address instead.
2. Click **Save**.
## Redirect Your Website to a Directory Within the Site
Use this when your site's real content lives in a subfolder of its web space, a common situation when a content management system is installed in its own directory, and you want visitors to `yourdomain.com` to see that content.
1. Open the **Redirect Type** drop-down and select **L (Last redirect rule)**. The manual recommends the plain `L` flag for directory redirects: the content is served from the subfolder while the address in the visitor's browser stays unchanged.
2. In the **Redirect Path** field, enter the folder path relative to the website's document root. The path must begin and end with a slash, for example `/shop/` or `/subdirectory/anothersubdirectory/`.
3. Click **Save**.
If you would rather have the browser's address bar visibly change to show the subfolder, select **R=301,L (Permanent redirect + last rule)** or **R,L (Temporary redirect + last rule)** instead of **L**.
## Set Up an SEO Redirect Between www and non-www
Search engines treat `yourdomain.com` and `www.yourdomain.com` as two different addresses. If both serve the same pages, your site competes with itself, a problem known as duplicate content. The **SEO Redirect** drop-down fixes this with a permanent redirect to whichever form you prefer; either choice is fine, the important thing is to pick one and stay with it.
1. Open the **SEO Redirect** drop-down and choose one of the following:
- **No redirect**: no SEO redirect is applied.
- **domain.tld => www.domain.tld**: sends `yourdomain.com` to `www.yourdomain.com`.
- **www.domain.tld => domain.tld**: sends `www.yourdomain.com` to `yourdomain.com`.
- **\*.domain.tld => domain.tld**: sends every subdomain, including `www`, to `yourdomain.com`.
- **\*.domain.tld => www.domain.tld**: sends every subdomain, and the bare domain itself, to `www.yourdomain.com`.
- **\* => domain.tld**: sends everything that is not `yourdomain.com`, including subdomains and alias domains, to `yourdomain.com`.
- **\* => www.domain.tld**: sends everything that is not `www.yourdomain.com`, including the bare domain, subdomains and alias domains, to `www.yourdomain.com`.
2. Click **Save**.
For a typical website, **domain.tld => www.domain.tld** or **www.domain.tld => domain.tld** is all you need. Whichever form you redirect to must actually exist and resolve: if you redirect to the `www` address, the website's **Auto-Subdomain** setting on the **Domain** tab should be **www.** and a DNS record for `www.yourdomain.com` must point at the server. SEO redirects work independently of the **Redirect Type** and **Redirect Path** fields, so you can use one without the other.
## Force HTTPS with Rewrite HTTP to HTTPS
If your website has an SSL certificate, every visitor should use the secure address. This also avoids duplicate content between the `http://` and `https://` versions of your pages.
1. On the **Redirect** tab, tick the **Rewrite HTTP to HTTPS** checkbox.
2. Click **Save**.
The checkbox only appears when **SSL** is enabled on the website's **Domain** tab. If you do not see it, enable **SSL** and **Let's Encrypt SSL** there first, save, then return to the **Redirect** tab.
## Save and Test the Redirect
1. After clicking **Save**, watch for the small red change indicator near the top of the panel. ISPConfig is writing the new web server configuration in the background; this normally takes under a minute.
2. Open a private or incognito browser window and visit the old address, for example `http://yourdomain.com`. You should land on the target address you configured.
3. Test the variations that matter to you: with and without `www`, and with `http://` as well as `https://`.
Always test in a private window. Browsers cache permanent redirects, so a normal window may show you an old redirect long after you have changed the settings. To remove a redirect later, set **Redirect Type** to **No redirect**, clear the **Redirect Path** field and click **Save**. Do not confuse **No redirect** with the separate **No flag** entry in the same list: **No flag** still applies the redirect, it simply applies it with no rewrite flags at all.
## Troubleshooting
- **Saving fails with "Invalid redirect path"**: the **Redirect Path** format is wrong, and ISPConfig names the two shapes it accepts in the message itself. Use either a full URL, such as `https://www.yournewdomain.com/`, or a directory path that begins and ends with a slash, such as `/shop/`. A directory path missing its leading or trailing slash is the usual cause.
- **The redirect does not happen**: wait for the red change indicator to clear, then retest in a private browser window. If it still does not work, confirm the domain's DNS records point at your Noiz hosting server, because a redirect can only fire once the browser reaches the server.
- **The old redirect keeps happening after I changed it**: your browser cached the previous permanent redirect. Test in a private window or a different browser; other visitors' caches will expire on their own.
- **The browser reports too many redirects**: the target is redirecting back to the source, creating a loop. This often happens when the target site, or software such as a content management system with its own site URL setting, redirects to the address you are redirecting away from. Set **Redirect Type** to **No redirect** to break the loop, then re-check where the target address really leads.
- **The Rewrite HTTP to HTTPS checkbox is missing**: SSL is not enabled for the website. Tick **SSL** and **Let's Encrypt SSL** on the **Domain** tab, save, and the checkbox will appear on the **Redirect** tab.
- **The SEO redirect to www gives an error**: the `www` address does not resolve. Set **Auto-Subdomain** to **www.** on the **Domain** tab and make sure a DNS record for `www.yourdomain.com` points at the server.
If you get stuck at any point, open a support ticket with the Noiz support team and include the domain being redirected, the exact values in the **Redirect Type** and **Redirect Path** fields, the target address you expect visitors to reach, and what happens instead when you test in a private browser window.
# How to Whitelist or Blacklist Email Senders in ISPConfig
Source: https://docs.noiz.ie/ispconfig/how-to-whitelist-or-blacklist-email-senders-in-ispconfig/
This guide shows you how to whitelist or blacklist email senders in the ISPConfig control panel on your Noiz hosting account. A whitelist entry (sometimes called an allow list or safe senders list) tells the spamfilter that mail from a sender must never be tagged as spam. A blacklist entry (sometimes called a block list) tells the spamfilter that mail from a sender must always be treated as spam. You will learn how to add entries for a single sender or a whole sending domain, and how the **Priority** field decides which rule wins when a whitelist and a blacklist entry both match the same message.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig official documentation index (includes the ISPConfig 3 manual)](https://www.ispconfig.org/documentation/)
- [ISPConfig frequently asked questions](https://www.ispconfig.org/documentation/frequently-asked-questions/)
- [ISPConfig support forum: how the spamfilter whitelist is applied](https://forum.howtoforge.com/threads/ispconfig-spamfilter-whitelist.92269/)
## Prerequisites
- You can [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- At least one mailbox exists on your account. If not, first [create an email mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/).
- You know the exact sender address (for example `sender@example.com`) or sending domain (for example `@example.com`) that you want to allow or block. These are placeholders; substitute the real sender details.
- The spamfilter is enabled for the mailbox or domain the rule should protect. A mailbox whose **Spamfilter** setting is `Uncensored` is not filtered, so whitelist and blacklist entries have no effect on it.
## How the Whitelist and Blacklist Work
Both lists live under the **Email** module in ISPConfig and act on the *sender* of incoming mail:
- A **whitelist** entry means mail from that sender is never tagged as spam for the recipient you choose.
- A **blacklist** entry means mail from that sender is always treated as spam for the recipient you choose.
Every entry is scoped to a recipient through its **User** field: it applies only to the mailbox or mail domain you select there, not to your whole account. The **User** list is built from the spamfilter records ISPConfig creates automatically for each mail domain and each mailbox, so email aliases and domain aliases do not appear in it. Scope the entry to the underlying mailbox or to the mail domain instead. Each entry also carries a **Priority** value from 1 to 10, which matters only when more than one whitelist or blacklist entry matches the same message; see the precedence section below.
## Whitelist an Email Sender
### Open the whitelist
1. Log in to ISPConfig and click the **Email** module in the top navigation bar.
2. In the left-hand menu, under the **Spamfilter** section, click **Whitelist**. A list of your existing whitelist entries appears.
3. Click the **Add Whitelist record** button.
### Complete the Whitelist form
The form opens on the **Whitelist** tab and has the following fields:
1. **User**: select the recipient mailbox, or the whole recipient mail domain, that this rule protects. The entry applies only to the mailbox or domain you pick here.
2. **Email**: enter the sender you want to allow.
- For a single sender, enter the full address, for example `newsletter@example.com`.
- For every sender at a domain, leave out the part before the @ sign, for example `@example.com`.
3. **Priority**: a drop-down of 1 to 10 that defaults to `5 - medium`. Leave it alone unless this entry needs to override a blacklist entry (see the precedence section below); `10 - highest` is the strongest and `1 - lowest` the weakest.
4. **Active**: make sure this checkbox is ticked, otherwise the entry is saved but ignored.
5. Click **Save**.
The new entry now appears in the list under **Email** > **Spamfilter** > **Whitelist**. Allow a minute or two for the change to be applied on the mail server before testing.
## Blacklist an Email Sender
### Open the blacklist
1. In the **Email** module, under the **Spamfilter** section of the left-hand menu, click **Blacklist**.
2. Click the **Add Blacklist record** button.
### Complete the Blacklist form
The form opens on the **Blacklist** tab and mirrors the whitelist form:
1. **User**: select the recipient mailbox or whole recipient mail domain that this rule protects.
2. **Email**: enter the sender you want to block. Use a full address such as `sender@example.com`, or block every sender at a domain with `@example.com`.
3. **Priority**: leave the default of `5 - medium` unless you are combining this entry with a whitelist exception (see below).
4. **Active**: make sure this checkbox is ticked.
5. Click **Save**.
The entry now appears under **Email** > **Spamfilter** > **Blacklist**, and mail from that sender to the selected recipient is treated as spam from then on. Depending on how the spamfilter is configured on the mail server, blacklisted mail may be refused at delivery rather than filed in the junk folder, in which case the sender receives a bounce message.
## Precedence: When a Whitelist and a Blacklist Entry Both Match
If only one entry matches a message, the **Priority** field does not matter and you can leave it at its default. It comes into play when more than one whitelist or blacklist entry matches the same message, typically a domain-wide rule in one list and a single-address rule in the other. The entry with the *higher* priority number wins (10 is highest, 1 is lowest).
A worked example using placeholder domains:
- You blacklist the whole domain `@example.com` with priority `5`, so all mail from that domain is treated as spam.
- One correspondent at that domain is legitimate, so you whitelist `gooduser@example.com` with priority `6`.
- Because 6 is higher than 5, mail from `gooduser@example.com` is delivered normally while the rest of the domain stays blocked.
The same technique works the other way around: whitelist a whole domain and blacklist one troublesome address from it with a higher priority. As a rule of thumb, give the more specific entry the higher number.
## Edit, Disable or Delete an Entry
- To edit an entry, open **Email** > **Spamfilter** > **Whitelist** or **Blacklist**, click the entry in the list, change the fields and click **Save**.
- To disable an entry temporarily without losing it, open the entry, untick **Active** and click **Save**.
- To delete an entry permanently, click the delete button on the entry's row in the list view and confirm.
## Troubleshooting
**Symptom: mail from a whitelisted sender still lands in the junk folder.** Open the entry and check three things: the **Active** checkbox is ticked, the **User** field points at the correct recipient mailbox or domain, and the **Email** value exactly matches the sender address shown in the message. Also allow a minute or two after saving for the change to reach the mail server.
**Symptom: you whitelisted a domain but some of its mail is still flagged.** Many senders use subdomains, for example `news.example.com` instead of `example.com`. An entry for `@example.com` does not automatically cover `@news.example.com`. Check the exact From address of an affected message and add a separate entry for the subdomain.
**Symptom: mail from a blacklisted sender is still delivered to the inbox.** Confirm the entry is **Active** and scoped to the right recipient in the **User** field. Check the whitelist for an entry that also matches the sender with an equal or higher **Priority**; if one exists, lower its priority or remove it. Finally, confirm the recipient mailbox actually has the spamfilter enabled: a mailbox set to `Uncensored` is not filtered at all, so blacklist entries are ignored for it.
**Symptom: a whitelisted sender's mail is rejected outright rather than tagged as spam.** A whitelist entry only changes what the spamfilter does with a message. It does not override checks that happen outside the spamfilter, so mail can still be refused for reasons such as an unknown recipient address or a mailbox that is over quota. Ask the sender for the exact wording of the bounce, or open a support ticket with it.
**Symptom: ISPConfig refuses to save a new entry and reports that the maximum number of white- or blacklist records for your account has been reached.** Your hosting account allows a set number of entries shared between the two lists. Delete entries you no longer need, or contact the Noiz support team about raising the limit. If the **Spamfilter** section is missing from the **Email** module menu altogether, that allowance is set to zero on your account, so ask the Noiz support team to enable it.
If you get stuck at any point, open a support ticket with the Noiz support team and include the sender address or domain you are trying to allow or block, the recipient mailbox it applies to, and a copy of an affected message's headers if delivery is not behaving as expected.
# Understanding ISPConfig User Levels: Admin, Reseller, and Client
Source: https://docs.noiz.ie/ispconfig/understanding-ispconfig-user-levels-admin-reseller-and-client/
This guide explains the three user levels in the ISPConfig control panel, admin, reseller, and client, what each level can see and do, and how to work out which level your own Noiz account uses. User levels are sometimes called roles or account types, and a client account is sometimes called a customer account. Understanding your level saves time: it explains why your panel shows certain tabs and not others, and why some guides in this knowledgebase describe screens you may not have. This article is for anyone using the ISPConfig panel on a Noiz hosting account, and the admin section is mainly relevant to self-managed server administrators.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig Documentation: Users and Clients](https://docs.ispconfig.org/users-and-clients/), the official overview of admin, reseller, and client accounts
- [ISPConfig Documentation: Control Panel Users](https://docs.ispconfig.org/users-and-clients/control-panel-users/), covering how panel accounts and their permissions are structured
- [ISPConfig Documentation: Adding a New User](https://docs.ispconfig.org/modules/admin/adding-a-new-user/), covering how administrators grant module access to individual users
## Prerequisites
- The ability to [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/) with your Noiz account details.
- Optionally, your Noiz welcome email, which states which hosting plan you are on.
## The Three User Levels at a Glance
Every ISPConfig user, regardless of level, logs in at the same panel address in the same way. The panel then decides what to show based on the level and permissions of the account. The three levels are:
- **Admin**: the built-in administrator account. It has full control over the panel, every hosted account on the server, and the server configuration itself.
- **Reseller**: an account that sells or manages hosting for its own set of clients. A reseller can create and manage client accounts within limits set by the administrator, but cannot change the server configuration.
- **Client**: the standard end-user account. A client manages their own websites, mailboxes, databases, and similar resources, within the limits set by the administrator or their reseller.
The levels are hierarchical. Admin can create resellers and clients, resellers can create clients, and clients cannot create other accounts. On Noiz shared hosting the admin level is held by Noiz, so your account will normally be either client level (standard hosting plans) or reseller level (reseller hosting plans).
## What Each User Level Can See and Do
### Admin
The `admin` account is created automatically when ISPConfig is installed and has full control over the panel and all of its functions. Admin can:
- Create, edit, and delete resellers, clients, and additional control panel users.
- Manage every website, mailbox, DNS zone, and database on the server, regardless of who owns it.
- Configure the server itself through the **System** tab, which no other user level can see.
- Monitor server health, load, and services through the **Monitor** tab.
- Set the resource limits (web space, number of websites, mailboxes, databases, and so on) that apply to resellers and clients.
- Create additional panel users under **System** > **User Management** > **CP Users**, each with its own selection of modules, for example a user who can only manage email. These are permission variations created by admin rather than a separate level.
Do not confuse the ISPConfig `admin` user with the Linux `root` user. Admin is a control panel login only; it is not a shell account on the server. On a self-managed server you hold both, but they are separate credentials used in separate places.
**CP Users** is intended for creating further administrator accounts. Ordinary client and reseller accounts should always be created from the **Client** tab instead, because editing users or groups directly under **User Management** can leave an existing account unable to reach its own websites and mailboxes.
### Reseller
A reseller is a company or individual that buys hosting in bulk and resells it to its own customers, without having to manage the server behind it. A reseller logs in to the same panel as everyone else and manages its clients, their websites, and their mailboxes from there. A reseller can:
- Create, edit, and delete their own client accounts under **Client** > **Clients**.
- Set per-client limits, such as how many websites or mailboxes each client may create, within the overall limits the administrator has granted the reseller. In those limit fields, `-1` means unlimited and `0` means none allowed, which switches that function off for the client.
- Manage the websites, mailboxes, DNS records, and databases belonging to their clients.
- Use almost every module of the panel except the server configuration: a reseller never sees the **System** tab. An administrator can narrow this further and grant a reseller only a limited set of modules.
A reseller only ever sees their own clients and their clients' resources. Accounts belonging to the administrator or to other resellers are invisible to them. How many clients a reseller may create is capped by the **Max. number of Clients** limit the administrator sets on the reseller account.
In ISPConfig terms a reseller is simply a client account that has sub-clients. An administrator promotes an existing client by ticking the **Reseller** checkbox on the account, at which point it disappears from the client list and appears in the reseller list instead. That is why moving from a client plan to a reseller plan does not mean rebuilding your account.
### Client
A client is the standard end-user level, and it is the level most Noiz hosting customers use. A client can:
- Create and manage their own websites, FTP users, and shell users from the **Sites** tab, where enabled for the account.
- Create and manage mailboxes, forwarders, and spam filter settings from the **Email** tab.
- Manage DNS records from the **DNS** tab, if DNS management is enabled for the account.
- Change their own panel password and language under **Tools** > **User Settings** > **Password and Language**.
Exactly which tabs and functions a client sees depends entirely on the limits and modules assigned by the administrator or reseller. One client account might have a single website and five mailboxes; another might have twenty websites, unlimited mailboxes, and DNS access. If a function is not enabled for your account, its tab or button simply does not appear. Clients cannot create other clients and cannot see any account other than their own.
## How to Tell Which User Level You Are
The tabs across the top of the panel are the reliable indicator. The username shown in the panel is just your login name and does not reveal your level. To check your level:
1. Log in to the ISPConfig control panel.
2. Look at the row of tabs across the top of the screen.
3. Match what you see against these rules:
- You can see the **System** tab: you are logged in as an administrator. On Noiz shared and reseller hosting this applies to Noiz staff only, so you will normally only see this on a self-managed server.
- You can see the **Client** tab but not the **System** tab: you are a reseller. You can create and manage your own clients.
- You can see neither the **Client** tab nor the **System** tab: you are a client. Your tabs will typically include **Home**, **Sites**, **Email**, and **Tools**, plus **DNS** if it is enabled for your account.
4. For a summary of what your account may create, open the **Home** tab. Home holds the panel dashboard, and it is where you land after logging in unless the **Startmodule** setting under **Tools** > **Interface** has been pointed at a different module. It lists your account limits, for example the number of websites, mailboxes, and databases allowed, alongside how many you have already used. A limit set to zero is left out of the list altogether, which is another reason a function you expected may be missing.
Your Noiz plan is also a strong clue: standard hosting plans are provisioned as client accounts, and reseller hosting plans are provisioned as reseller accounts.
## Troubleshooting
- **A tab or button described in another guide is missing from your panel**: your user level or account configuration does not include that module. This is normal, not a fault. If you believe your plan should include the missing function, open a support ticket with the Noiz support team, or contact your reseller if you bought your hosting through one.
- **A tab is visible but you cannot add a new item**: you have most likely reached a limit on your account, such as the maximum number of websites or mailboxes. Check the limits summary on the **Home** tab to confirm, then contact Noiz or your reseller about raising the limit.
- **You manage hosting for other people but cannot find the Client tab**: your account is client level, not reseller level. Client accounts cannot create sub-accounts. If you need to manage separate customers, ask Noiz about a reseller plan.
- **Your ISPConfig password does not work for FTP, email, or SSH**: an ISPConfig login only opens the control panel. FTP users, mailboxes, and shell users each have their own separate usernames and passwords, which are created inside the panel.
- **You expected full admin access**: on Noiz shared and reseller hosting, the admin level is reserved for Noiz so that server configuration stays consistent and secure for everyone on the server. Admin access is only available on a self-managed server product.
If you get stuck at any point, open a support ticket with the Noiz support team and include your ISPConfig username and a list of the tabs you can see across the top of the panel.
# What to Do If Your IP Address Is Blocked by an ISPConfig Server
Source: https://docs.noiz.ie/ispconfig/what-to-do-if-your-ip-address-is-blocked-by-an-ispconfig-server/
This guide explains what to do if the server that hosts your Noiz services suddenly stops responding for you, while it keeps working normally for everyone else. The usual cause is an automatic security block, sometimes called an IP ban, a firewall block or a fail2ban block, placed on your internet connection's IP address after repeated failed logins. It is written for Noiz clients whose hosting runs on an ISPConfig server. You will learn how to recognise a block, how to confirm it, how to find the IP address that Noiz support needs in order to unblock you, and how to stop the block from coming back.
**Last reviewed:** 27 July 2026, against ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against ISPConfig. It complements, and does not replace, the official ISPConfig documentation linked below.
### Official Documentation Reference
- [ISPConfig 3 User Manual](https://www.ispconfig.org/documentation/user-manual/): the official manual; fail2ban blocking is covered in section 4.10.5.10 (Show fail2ban-Log) and section 5.16 (How Do I Unblock An IP Address That Got Blocked By fail2ban?).
- [Fail2ban project page](https://github.com/fail2ban/fail2ban): the official page of the security tool that performs the blocking, describing how it scans logs and bans IP addresses that make too many failed login attempts.
- [HowtoForge forum: how to manually unban an IP blocked by fail2ban](https://forum.howtoforge.com/threads/how-to-manually-unban-ip-blocked-by-fail2ban.51366/): community reference confirming that removing a block requires administrator access to the server, which is why Noiz support handles it for you.
## Prerequisites
- You know how to [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/). During a block the panel may not load for you at all; knowing what the login page normally looks like helps you confirm that.
- Access to a second internet connection for testing, most easily a mobile phone with Wi-Fi switched off so it uses mobile data.
- No technical knowledge is required. You will not need to run any commands; the unblocking itself is done by Noiz support.
## Why a Server Blocks Your IP Address
ISPConfig servers run a security tool called fail2ban. It watches the server's log files for login attempts to services such as email (IMAP, POP3 and SMTP), FTP, SSH and the web server. If it sees repeated failed logins from the same IP address within a short time, it treats them as a possible break-in attempt and tells the server firewall to stop accepting connections from that address. The block is automatic, applies day and night, and does not distinguish between a genuine attacker and a legitimate client whose device keeps sending an old password.
That last point is the most common real-world cause. Typical triggers include:
- A phone, tablet or computer with an email account still saved under an old password, silently retrying every few minutes after you changed the mailbox password.
- An FTP program or backup tool with outdated saved credentials that reconnects automatically.
- Someone in your home or office repeatedly mistyping a password.
- A genuine attacker guessing passwords from your network, for example malware on a computer that shares your connection.
The ISPConfig control panel is a special case. It guards its own login page separately, counting failed attempts per IP address rather than adding a firewall rule, so a panel lockout and a firewall block look quite different on screen. The section below shows how to tell them apart.
Two important consequences follow from how the block works:
- **The whole connection is blocked, not just one device.** Everyone sharing your internet connection, such as an entire office or household, is affected at the same time, because they all share one public IP address.
- **Only your connection is blocked.** Your website stays online and your email keeps flowing for the rest of the world. Visitors, customers and colleagues on other connections notice nothing. A block is inconvenient, but it is not an outage.
Blocks are normally temporary and expire on their own after a set period, but if the underlying cause is still active, for example a device still retrying a wrong password, the block simply comes back.
## How to Recognise an IP Block
A firewall block silently discards your connection attempts, so the tell-tale sign is **timeouts** rather than error messages. Depending on which service triggered the block, one service or several may be affected. Typical symptoms:
- Your website will not load from your location and the browser eventually shows a message like `connection timed out`, while the same site loads fine on mobile data.
- Your email program reports that it cannot connect to the server, or messages sit in the outbox, on every device in the office at once.
- Your FTP program hangs on `connecting` and then times out.
- The ISPConfig control panel login page will not load at all.
Just as useful are the signs that it is **not** an IP block:
- The site loads but shows an error page, such as a `404`, `500` or a database error. The server answered you, so you are not blocked; that is a website problem.
- You reach the login screen but your password is rejected. The server answered you; that is a credentials problem, although repeated wrong attempts can turn it into a block, so stop retrying and reset the password instead.
- The ISPConfig login page loads but reports `Too many failed login attempts. Please retry after 15 minutes`. That is the panel's own protection rather than a firewall block: ISPConfig counts failed logins per IP address and stops accepting them after more than five in quick succession. Nothing needs unblocking, and the count clears once a login succeeds, so stop retrying and make sure you have the correct password before trying again.
- The service is also unreachable from mobile data and other connections. That points to a wider problem rather than a block on your address.
## Step 1: Confirm the Block from a Second Connection
1. Take a mobile phone and switch **Wi-Fi off**, so that it connects over mobile data. Mobile data uses a different public IP address from your fibre, DSL or office connection.
2. In the phone's browser, open your website, for example `https://yourdomain.com`, and if you use it, the ISPConfig panel address.
3. Compare the results:
- **Works on mobile data, times out on your normal connection**: this strongly suggests your connection's IP address is blocked. Continue to Step 2.
- **Fails on both**: this is probably not an IP block. Skip to the Troubleshooting section below.
If you do not have mobile data available, asking a friend or colleague on a different connection to try the site gives you the same comparison.
## Step 2: Find Your Public IP Address
To remove a block, Noiz support needs the public IP address of the affected connection. This is the address your whole network presents to the internet; it is not the internal address of your computer, which usually starts with `192.168.` or `10.`.
1. On a device connected to the **affected** connection (not on mobile data), open a browser.
2. Search the web for `what is my IP`. Most search engines display your public IP address at the top of the results, and many websites offer the same lookup.
3. Note the address exactly as shown. An IPv4 address looks like `198.51.100.24` (an example value); you may also see a much longer IPv6 address containing colons. Copy whatever is displayed.
Two things worth knowing about public IP addresses in South Africa: many home fibre and LTE connections use dynamic addresses that change from time to time, and some mobile and LTE providers share one public address between many customers. This is why the lookup must be done from the affected connection at the time of the problem; an address you noted last month may no longer be yours.
## Step 3: Contact Noiz Support to Remove the Block
Removing a fail2ban block requires administrator access to the server's firewall, so it is not something you can do from the ISPConfig panel or from your own account. Open a support ticket with the Noiz support team and include:
- Your public IP address from Step 2, for example `198.51.100.24`.
- Your domain name, for example `yourdomain.com`.
- Which services are failing for you: website, email, FTP or the panel.
- Roughly when the problem started.
- Anything that changed shortly before, such as a password change on a mailbox or FTP account. This helps support identify the cause as well as lift the block.
If your usual route to support runs through the blocked server, submit the ticket from a device on mobile data instead. Support can confirm from the server's fail2ban log which service triggered the block and remove it. That log view shows only the most recent activity, so reporting the problem promptly makes the triggering service far easier to pin down.
Because blocks are temporary by default, you may find that access returns by itself after a while. Do not treat that as the end of the matter: if a device is still sending wrong credentials, the next block is only minutes away. Move straight on to Step 4.
## Step 4: Stop the Block from Coming Back
A repeat block almost always means something on your network is still retrying a wrong password. Track it down before it triggers fail2ban again.
### Check every device with a saved email password
1. List every phone, tablet and computer that has the affected email account set up, including old devices in a drawer that are still switched on and connected to Wi-Fi.
2. If a mailbox password was changed recently, update the saved password in the email app on **every one** of those devices. One forgotten phone is enough to keep triggering blocks.
3. Remove email accounts that are no longer used from old devices entirely.
### Check FTP programs, backup tools and scripts
1. Open any FTP program you use and check the saved credentials for your site. Update or delete entries that hold old passwords.
2. Think about anything automated: backup utilities, deployment scripts, website plugins that connect over FTP or SMTP. Automated tools retry far faster than a human and can trigger a block within minutes.
### Adopt habits that avoid future blocks
- When you change any hosting password, change it everywhere it is saved in the same sitting.
- If a login is rejected more than twice, stop and reset the password rather than guessing repeatedly.
- Use a password manager so each device uses the current, correct password.
- Run up-to-date antivirus checks if blocks recur with no obvious cause, since malware on one computer can attack the server from your connection without your knowledge.
## Troubleshooting
- **Access came back on its own after a short while**: the temporary ban expired. The cause is still out there, so work through Step 4, otherwise the cycle repeats.
- **You get blocked again soon after support unblocks you**: a device or program on your network is still using wrong credentials. Switch off suspect devices one at a time, or temporarily disable the email account on each device, to isolate the culprit, then correct its saved password.
- **Only email fails, the website loads fine**: a block can cover only the service that triggered it. It is still the same problem; include this detail in your ticket because it tells support which log to check.
- **The site is down on mobile data too**: this is not an IP block on your address. Check for a domain or server-wide issue and contact Noiz support describing what you see.
- **The site loads but shows an error page**: the server is answering you, so you are not blocked. Troubleshoot the website itself instead.
- **Your public IP address keeps changing**: dynamic addresses are normal on many South African connections. Always look the address up at the moment of the problem, from the affected connection, and send support the current value.
If you get stuck at any point, open a support ticket with the Noiz support team and include your public IP address, your domain name, which services are failing, when the problem started and whether any passwords were changed recently. Never include the passwords themselves in the ticket.
# How to Access Your VPS via the VNC Console in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/
The VNC console in SolusVM gives you a screen and a keyboard wired directly to your VPS, in the same way a monitor and keyboard are wired to a physical machine. It is variously called the console, the VNC console, the virtual console, or out-of-band access. This guide shows you how to open it from the SolusVM control panel, what it can and cannot do once it is open, and how to use it to recover a server you have locked yourself out of. It is written for anyone who administers a VPS through a SolusVM control panel.
The reason VNC matters is what it does *not* depend on. The session is served by the host node that runs your VPS, not by the VPS's own operating system or network stack. It therefore keeps working when the VPS has no network, when a firewall rule has blocked your IP address, when the SSH service has been misconfigured or has failed to start, when a filesystem check is waiting for an answer at boot, and during an operating system installation before any networking exists at all. When SSH is available, SSH is the better tool in almost every respect. VNC is what you reach for when SSH is not an option.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide documents the SolusVM control panel itself and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM 1 Documentation](https://docs.solusvm.com/en/solusvm1/), the panel generation whose client area presents the **HTML5 VNC Client SSL** and **Java VNC Client** buttons shown in the screenshots below.
- [SolusVM 2 Quick Start Guide: Customers](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/), which covers connecting to a server with the VNC console or SSH in the newer panel.
- [The noVNC project](https://novnc.com/info.html), background on how a browser is able to speak VNC at all without any plugin installed.
- [RFC 6143: The Remote Framebuffer Protocol](https://datatracker.ietf.org/doc/html/rfc6143), the specification behind VNC, including the limits of its built-in authentication.
## Prerequisites
- The SolusVM control panel address, your username, and your password. These are in the welcome email sent when the VPS was provisioned. See [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
- A VPS running full virtualisation. VNC needs an emulated graphics adapter, which KVM and Xen HVM provide and container virtualisation does not. See [How to Check the RAM of VPS, IP, Disk Capacity and Virtualization Details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
- VNC switched on for that VPS. See [How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/).
- The VNC password, if the console prompts for one. It is a separate credential from both the panel password and the operating system root password. See [How to Change the VNC Password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/).
- A current desktop browser. The HTML5 client needs nothing installed on your computer.
## How to Open the VNC Console
1. Log in to the SolusVM control panel.
2. If the account holds more than one VPS, select the one you want to work on. 
3. Click **VNC**. 
4. A VNC page opens with the available client options. Click **HTML5 VNC Client SSL**. This is the option to use: it runs entirely in the browser and carries the session over an encrypted connection. 
5. The console appears in a new window or tab. If it asks for a password, that is the VNC password, not the operating system root password.
6. Click once inside the console area to give it keyboard focus, then press **Enter**. A running server answers with a fresh login prompt or a new shell line. That single keypress is the quickest way to confirm the console is genuinely attached to a live machine rather than showing a stale image.
If pressing Enter changes nothing at all, the VPS is probably not running. Check its power state before assuming the console is broken: see [How to Check Whether the VPS Status is "online" or "offline" in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/) and, if needed, [How to Start/Boot Your VPS in SolusVM](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/).
## Working Inside the Console
The console is a live attachment to a running machine. Every keystroke goes straight to the server, with no shell history, no undo, and no confirmation prompt beyond whatever the operating system itself asks. Treat it as though you were standing at the machine with a keyboard in your hands.
### The Keyboard Layout Is the Guest's, Not Yours
VNC sends raw key events. The operating system running on the VPS decides which character each event produces, using its own console keymap. A freshly installed Linux system usually defaults to a US layout, so on a UK or Irish keyboard the characters `@`, `"`, `#`, `\`, and `|` commonly come out as something else. Passwords fail silently as a result, because nothing is echoed while you type them.
The reliable trick is to type the password into the *username* field first, where the characters are visible, confirm each symbol arrives as expected, then clear the field and log in properly. If symbols are being mangled, log in with an alphanumeric account or set a temporary alphanumeric password, then fix the keymap from inside the system.
### Key Combinations Your Own Computer Steals
Some combinations never reach the browser at all because your own operating system or window manager claims them first. **Ctrl+Alt+Del** is the usual example, and on many desktops so are the Windows or Command key, Alt+Tab, and the function keys. Browser shortcuts such as Ctrl+W and Ctrl+T are also intercepted before the console sees them, so a stray Ctrl+W closes the console rather than the window you meant to close inside it.
If the console toolbar offers a control for sending special key combinations to the guest, use that. Otherwise, do not try to force a restart through the keyboard: use the panel instead, as described in [How to Reboot/Restart VPS in SolusVM](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/).
### A Blank Screen Is Usually Not a Fault
Linux blanks its text console after a period of inactivity, typically ten minutes. A console that opens on solid black is very often a healthy server with a blanked screen. Press **Shift** or **Enter** to wake it. Prefer Shift over a letter key, because a letter key wakes the screen *and* types the letter into whatever shell is sitting there.
### Copy, Paste, and Scrollback Are Limited
Clipboard sharing between your desktop and the console ranges from awkward to absent, so plan on typing commands by hand. Long one-line commands are where mistakes happen, so break the work into short commands. Scrollback is whatever the guest's own console buffer holds, usually reachable with **Shift+Page Up**, and it is cleared when the machine reboots. If you need to read a long log, page through it with `less` or narrow it with `journalctl` filters rather than scrolling.
### Log Out Before You Close the Tab
Closing the browser tab ends your VNC session, but it does not end the login session on the virtual screen. The shell stays logged in on that tty, and the next person to open the console sees it exactly as you left it, root prompt included. Always type `exit` or `logout` at the console before you disconnect. This is the single most commonly missed step in VNC hygiene, and it turns a password-protected console into an open door.
For the same reason, treat the VNC password as a root-equivalent credential. Change it if it has ever been shared, reused, or written into a ticket: see [How to Change the VNC Password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/). It is worth knowing why the SSL option matters here. The classic VNC authentication scheme defined in [RFC 6143](https://datatracker.ietf.org/doc/html/rfc6143) is a DES-based challenge and response that uses at most the first eight characters of the password, and the protocol itself carries no transport encryption. A longer VNC password is not more secure than an eight-character one, and a raw VNC connection across the internet exposes both the session and the keystrokes in it. The **HTML5 VNC Client SSL** option wraps the session in the panel's TLS connection, which is what makes it safe to use from anywhere.
## Recovering a Locked-Out VPS from the Console
This is the situation VNC exists for. You will need the operating system root or administrator password, which is not the panel password and not the VNC password. If you no longer have it, reset it first: see [How to Change the VPS OS Root/Admin Password in SolusVM](/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/).
### Work Out Which Layer Is Broken
Once logged in at the console, establish whether the problem is the network, the firewall, or the SSH service, because the fix differs for each. On a Linux VPS:
```
ip a
ip route
ss -tlnp | grep ':22'
systemctl status sshd
```
Read them in that order. If `ip a` shows no address on the public interface, or `ip route` shows no default route, the problem is networking and nothing else will work until it is fixed. If both look right but `ss` shows nothing listening on port 22, SSH is not running, and `systemctl status sshd` (or `journalctl -u sshd -n 50`) will usually name the reason, most often a syntax error in a config file edited just before the lockout. If SSH *is* listening and the network is up, the block is almost certainly a firewall rule.
### Inspect the Firewall Before Changing It
List the rules that are actually loaded, using whichever tool the system uses:
```
nft list ruleset
iptables -S
firewall-cmd --list-all
ufw status verbose
```
Look for a rule that drops or rejects your own public IP address, or a default deny policy with no matching allow rule for port 22. Removing the single offending rule is far better than flushing everything. A flushed firewall leaves the VPS completely exposed, and on a public IP address that exposure is measured in minutes, not hours. If you do flush as a last resort, restore a working rule set immediately afterwards and do not leave the machine in that state overnight.
### Make Risky Network Changes from the Console, Not over SSH
The console cannot lock you out, so it is the right place to edit interface configuration, change the SSH port, tighten firewall rules, or apply a new network configuration. The classic failure is applying such a change over SSH and losing the connection mid-command, leaving the machine half-configured and unreachable. Doing the same work at the console removes that risk entirely.
### Verify the Fix from Outside
Do not judge success by the absence of errors at the console. From your own machine, prove that the path works end to end:
```
ssh -v root@203.0.113.10
```
Replace `203.0.113.10` with your VPS's own IP address. The `-v` flag shows where a failed attempt stops: no response at all points at the network or a firewall drop, a refused connection points at SSH not listening, and reaching the authentication stage means the network and firewall are fine and the remaining problem is credentials. Only close the console once an outside connection has succeeded.
## Using VNC During an Operating System Installation
An installer has no network configuration and no SSH service, so the console is the only way to interact with it. This is the second main use of VNC, and it applies both to the panel's automated reinstaller and to a manual installation from an ISO image. See [How to Reinstall OS Using SolusVM OS-Reinstaller](/solusvm/how-to-reinstall-the-os-on-a-vps-using-the-solusvm-os-reinstaller/) and [How to Manually Install/Reinstall an OS using SolusVM for a Customized Installation](/solusvm/how-to-manually-install-an-os-from-iso-in-solusvm/).
Two practical points. Choose the installer's text mode where it is offered: graphical installers rely on a mouse, and mouse tracking over VNC is frequently offset or laggy because the emulated pointer is a relative device rather than an absolute one, which makes precise clicking tedious. Second, keep the console open for the whole installation. The installer asks questions at unpredictable points, and an unanswered prompt simply waits indefinitely while the installation appears to have stalled.
## The Java VNC Client Is Legacy
Older SolusVM panels offer a **Java VNC Client** alongside the HTML5 one. It ran as a Java applet inside the browser, and it prompted for confirmation before running:

Once accepted, it presented a console window similar to this:

That path no longer works on any current browser, and no amount of configuration will bring it back. Browsers removed the plugin interface that applets depended on, Chrome ending NPAPI support in 2015 (see [the Chromium NPAPI announcement](https://blog.chromium.org/2014/11/the-final-countdown-for-npapi.html)) and Firefox following in version 52. Java itself deprecated the Applet API in Java 9 under [JEP 289](https://openjdk.org/jeps/289) and removed the browser plugin from the JDK entirely thereafter.
The practical consequence: if you see a **Java Blocked** message, a missing-plugin message, or a downloaded `.jnlp` file that does nothing, stop troubleshooting Java. The historical fix of adding the control panel address to the Java exception site list no longer has anything to apply to. Go back and use **HTML5 VNC Client SSL** instead, which needs nothing installed and is the supported option.
## Troubleshooting
- **There is no VNC button in the panel**: either the VPS uses container virtualisation, which has no emulated display and therefore no VNC console, or VNC has been switched off for that VPS. Check the virtualisation type in [the VPS details](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/), then check the setting itself in [How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/).
- **You enabled VNC but the console still will not connect**: a change to the virtual hardware is read when the virtual machine process starts, so a reboot from inside the guest is not enough. Perform a full power cycle from the panel: [shut the VPS down](/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/), wait for the status to show as offline, then [start it again](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/).
- **The console opens black and stays black**: press **Shift** first, because a blanked screen is the most common cause. If the screen stays black, [check whether the VPS is online](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/). A powered-off machine has nothing to display.
- **The console asks for a password and rejects the one you have**: you are being asked for the VNC password, which is separate from the panel password and the operating system root password. Reset it as described in [How to Change the VNC Password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/), then reconnect. Remember that only the first eight characters of a VNC password are used, so a truncated copy and paste can still succeed while a mistyped fifth character will not.
- **The console connects and then drops within a second or two**: the virtual machine has usually just been stopped, rebuilt, or migrated, which invalidates the session. Refresh the panel, confirm the current power state, and open the console again.
- **The console never loads on one network but works on another**: the HTML5 client keeps the session open with a WebSocket connection, and some corporate proxies, captive portals, and older filtering appliances block the WebSocket upgrade. Test from a different network or a mobile connection to confirm, then ask the network administrator to allow it.
- **Typed characters are wrong or passwords fail silently**: the console keymap on the VPS does not match your physical keyboard. Type the password into a visible field first to see what actually arrives, then correct the keymap inside the operating system.
- **The mouse pointer is offset or unresponsive during a graphical installer**: switch to the installer's text mode. Relative pointer emulation over VNC rarely tracks accurately, and text mode is faster to drive over a console anyway.
- **Ctrl+Alt+Del does nothing**: your own computer intercepted it. Use the console toolbar's send-keys control if there is one, or restart the VPS from the panel instead.
Whoever supplied the VPS controls the host node and the VNC service running on it, so if the console itself will not start after the checks above, raise it with that provider's support desk and quote the exact error the browser shows. Noiz clients can open a support ticket with the Noiz support team at any point if something in this guide is unclear.
# How to Change Your VPS Hostname in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-change-your-vps-hostname-in-solusvm/
This guide explains how to change the hostname of a VPS from the SolusVM control panel, what that field actually controls, and the two steps almost everyone forgets afterwards: setting the name inside the operating system as well, and getting reverse DNS to match. A hostname looks like a cosmetic label, and for a web server it very nearly is. For a mail server it is the opposite: it is the identity your server presents to every other mail server on the internet, and if it does not line up with DNS in both directions, your mail starts landing in spam folders or getting refused outright. This article is for anyone with access to a VPS managed through SolusVM, whether that is an end user working in the client area or an administrator changing a name on a customer's virtual server.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is maintained by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation: Introduction to SolusVM, Common Notation and Glossary](https://docs.solusvm.com/en/solusvm1/introduction/introduction-to-solusvm-and-common-notation-and-glossary/), the entry point for the legacy SolusVM 1 documentation set that the classic client area belongs to
- [SolusVM Documentation: Change Hostname (`vserver-hostname`)](https://docs.solusvm.com/en/solusvm1/api/admin/virtual-server-functions/change-hostname/), the API definition of the same action the panel button performs, useful if you need to rename servers in bulk or from a provisioning script
- [SolusVM Documentation: Improving Deliverability of Users' Emails Using Reverse DNS](https://docs.solusvm.com/en/solusvm2/administrator-guide/improving-deliverability-of-users-emails-using-reverse-dns/), the administrator-side view of how PTR records are managed for virtual servers
- [Linux manual page: `hostnamectl(1)`](https://man7.org/linux/man-pages/man1/hostnamectl.1.html), the supported way to set the hostname on a systemd-based Linux distribution
- [Linux manual page: `hostname(5)`](https://man7.org/linux/man-pages/man5/hostname.5.html), what the `/etc/hostname` file may and may not contain
- [Linux manual page: `hosts(5)`](https://man7.org/linux/man-pages/man5/hosts.5.html), the format of `/etc/hosts`, which is what makes `hostname -f` resolve locally
- [RFC 5321, section 4.1.4: Order of Commands](https://www.rfc-editor.org/rfc/rfc5321#section-4.1.4), the requirement that an SMTP client identifies itself with a fully qualified domain name
- [cloud-init: Module Reference](https://docs.cloud-init.io/en/latest/reference/modules.html), covering the `set_hostname` and `update_hostname` modules that silently overwrite a hostname on cloud images
## Prerequisites
- Access to [log in to the SolusVM control panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/). The address you log in at is given in the welcome email for your VPS.
- Root or `sudo` access on the VPS over SSH, or console access, so you can set the name inside the operating system too.
- A hostname you have actually decided on, and control of the domain it sits under, so you can create the matching DNS record.
- A maintenance window. The change is not complete until the VPS has been restarted, and services that read the hostname at start-up will need restarting with it.
## What the Hostname Field in SolusVM Actually Changes
This is the part that causes most of the confusion, so it is worth being precise before you touch anything.
### It is SolusVM's record of the name
The **Hostname** field stores the name SolusVM holds for that virtual server in its own database. That value is what appears in the panel's server list, what administrators see when they search for the machine, and what gets used in notifications the panel sends out. Changing it always succeeds in that sense: the panel will confirm the hostname was changed even if nothing inside the guest operating system has moved.
### Whether it reaches inside the guest depends on the virtualisation type
On container-based virtualisation such as OpenVZ, the host has direct access to the container's filesystem and configuration, so a hostname set from the panel can be applied to the container itself. On full virtualisation such as KVM or Xen HVM, the guest is an opaque virtual machine with its own kernel and its own configuration files. The host cannot reach in and edit them while the machine is running. In that case the panel value is used when the operating system is next built or reinstalled, and the running system keeps whatever name it already had.
The practical rule is simple, and it holds for every virtualisation type: **set the hostname in the panel and inside the operating system, then verify inside the operating system.** Never assume the panel change propagated. If you are not sure which virtualisation your VPS uses, you can [check the virtualisation type and main IP address in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
### It does not create DNS, and it does not set reverse DNS
Setting a hostname is naming a machine. It does not register a domain, it does not create an A record pointing that name at your IP address, and it does not create the PTR record that maps your IP address back to that name. Those are three separate pieces of work, and the hostname is the only one of them you can do from this screen. If you stop after changing the field, you have a server that calls itself `server1.example.com` while the rest of the internet has never heard of it.
## Choosing a Hostname You Will Not Regret
Renaming a server is cheap on day one and expensive on day four hundred, so spend a minute on the choice.
- **Use a fully qualified domain name, not a bare word.** `server1.example.com`, not `server1`. Mail servers are required to identify themselves with a fully qualified name, and a great deal of other software assumes the hostname is resolvable.
- **Use a subdomain, not the domain itself.** Setting the hostname to `example.com` when `example.com` is also a website you host on the same machine is a classic self-inflicted wound. Some mail software then treats `example.com` as a purely local domain and stops delivering mail for it over the network, so messages to your own domain vanish into a local mailbox instead of leaving the server. Give the machine its own name under the domain: `server1.example.com`, `vps1.example.com`, `mail.example.com`.
- **Use a domain you control.** You will need to create an A record for the hostname, and you will need reverse DNS to match it. Neither is possible with a domain belonging to someone else.
- **Keep it lowercase and boring.** Letters, digits and hyphens only. No underscores, no spaces, no trailing dot. Each label is limited to 63 characters and the whole name to 253, but anything approaching either limit is a sign something has gone wrong.
- **Do not encode information that will change.** A hostname containing a client name, a rack position, a datacentre code, or a plan size becomes a lie the moment any of those change, and by then the name is baked into certificates, monitoring, logs and backups.
Two workable examples, both using a placeholder domain you would replace with your own:
```
server1.example.com
hostingserver.example.com
```
## How to Change the Hostname in the SolusVM Control Panel
1. Log in to your SolusVM control panel using the address in your VPS welcome email.
2. If your account holds more than one virtual server, select the one you want to rename. Confirm the main IP address before going further, because nothing in the next step tells you which machine you are editing. 
3. Scroll down to the **Hostname** section, clear the field, and type the new fully qualified hostname. Then click **Change**. 
4. SolusVM confirms that the virtual server hostname was changed. That message means the panel's record was updated. It is not confirmation that anything inside the operating system changed.
5. [Restart the VPS](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/) so the change takes effect. Use a graceful restart, not a forced reset.
### Why a restart is needed
The hostname is not a live setting that everything picks up automatically. The kernel holds a current hostname, and almost every long-running service reads it once, at start-up, and then caches it for the life of the process. A mail server builds its SMTP banner from the hostname when it starts. A web server may write it into log lines. Monitoring agents register themselves under it. Changing the name underneath those processes leaves you with a machine that reports two different identities depending on which one you ask, which is far more confusing to debug than a straightforward restart. A restart also lets you confirm that the new name actually survives a boot, which, as the next section explains, is not a given.
## How to Set the Hostname Inside the Operating System
This is the step the panel cannot reliably do for you on a running virtual machine, and it is the one that matters to every piece of software on the server.
### On a systemd-based Linux distribution
Almost every current Linux distribution uses systemd, including Debian, Ubuntu, Rocky Linux, AlmaLinux and Fedora. Connect over SSH as root or a user with `sudo` rights, then:
```
hostnamectl set-hostname server1.example.com
```
That writes `/etc/hostname` and sets the running kernel hostname in one step, which is why it is preferable to editing the file by hand. The older `hostname server1.example.com` command changes only the running value and is lost at the next boot.
### Update `/etc/hosts` as well
This is the step people skip, and skipping it causes a genuinely irritating class of problem. Open `/etc/hosts` and make sure a line maps the server's IP address to both the fully qualified name and the short name, in that order:
```
203.0.113.10 server1.example.com server1
```
Replace `203.0.113.10` with your VPS main IP address and the names with your own. Order matters: the first name after the address is the canonical one, and it is what `hostname -f` returns.
The reason this is not optional is that a large amount of software resolves its own hostname during start-up, and if that lookup has to go out to a DNS server it can be slow, and if it fails it can be very slow. The most visible symptom is `sudo` pausing for many seconds before every single command, because it is timing out on a lookup of a name nothing can resolve. A correct `/etc/hosts` line makes that lookup instant and offline.
### The gotcha that undoes all of it: cloud-init
If your VPS was built from a cloud image, cloud-init is probably installed, and by default it re-applies the hostname it was given at every boot. You set the name, restart, and find the old one back, with nothing in your own configuration to explain it. To make your change permanent, tell cloud-init to leave the hostname alone by adding this line to `/etc/cloud/cloud.cfg`:
```
preserve_hostname: true
```
Check whether cloud-init is present at all before worrying about it:
```
command -v cloud-init && cloud-init --version
```
A DHCP client can do the same thing for the same reason. If your VPS gets its address by DHCP rather than a static configuration, the DHCP server can supply a hostname that overwrites yours at lease renewal. Most VPS platforms hand out static addressing, so this is the rarer of the two causes, but it is worth knowing about when a hostname keeps reverting and cloud-init is not installed.
## Hostnames, Mail and Reverse DNS
If the VPS will never send email, you can treat the hostname as a label and move on. If it will send email, even just notifications from a web application, this section is the reason the article exists.
### What receiving mail servers check
When your server connects to another mail server, it introduces itself with an `EHLO` command containing its own name. RFC 5321 requires that name to be a fully qualified domain name. The receiving server then, routinely, checks three things that all need to agree:
1. **The PTR record.** A reverse lookup of your IP address should return your hostname. An IP address with no PTR at all, or with a generic provider-assigned PTR full of the IP address in dotted form, is treated as a strong spam signal by most large mail providers.
2. **The forward record.** An A record for that hostname should resolve back to the same IP address. A PTR pointing at a name that does not resolve, or resolves elsewhere, is worse than no PTR at all. The two matching is called forward-confirmed reverse DNS.
3. **The EHLO name.** The name your server announces should be the same fully qualified name. A server that announces `localhost.localdomain`, or a bare short name, or an IP address, is very likely to be refused.
Get one of those three wrong and you are not blocked outright so much as quietly penalised: mail is accepted but scored into spam folders, and the delivery failures are invisible from your side. That is why this is worth doing before the server starts sending, not after complaints arrive.
### The order to do it in
1. **Create the A record first.** In the DNS for your domain, add an A record for the hostname pointing at the VPS main IP address. Let it propagate before continuing.
2. **Change the hostname** in SolusVM and inside the operating system, as described above.
3. **Request the PTR record.** You cannot set this yourself. Reverse DNS lives in the `in-addr.arpa` zone for the IP block, and that zone is controlled by whoever owns the addresses, which is the provider of the VPS, not you. Some SolusVM installations expose a reverse DNS field to end users; many do not. If yours does not, ask for the PTR through the support channel in your VPS welcome email, quoting the IP address and the exact hostname you want it to return.
4. **Update the mail server's own configuration.** Mail software keeps its own copy of the name and does not follow the system hostname automatically. In Postfix that is `myhostname` and usually `myorigin` in `/etc/postfix/main.cf`; in Exim it is the primary hostname setting. Restart the mail service afterwards.
5. **Reissue any TLS certificate** that covers the old hostname, including the certificate the mail server presents for STARTTLS. A certificate for the old name on a server now calling itself something else will produce trust warnings.
## How to Verify the Change Actually Worked
"The panel shows the new name" is not verification. Once the VPS is back up, check from inside the server:
```
hostnamectl status
hostname -f
```
`hostnamectl status` prints the static hostname, which is the persistent one from `/etc/hostname`, alongside the transient one. Both should be your new name. `hostname -f` should print the full name, `server1.example.com`, not the short `server1`. If it prints the short form, your `/etc/hosts` line has the names in the wrong order.
Then check DNS from anywhere, forward and reverse:
```
dig +short A server1.example.com
dig +short -x 203.0.113.10
```
The first should return your VPS main IP address. The second should return your hostname with a trailing dot. If either is empty, the corresponding record does not exist yet.
If the server sends mail, check the banner it presents. From another machine:
```
openssl s_client -starttls smtp -connect server1.example.com:25 -crlf
```
The `220` greeting line should contain your new hostname, and the certificate presented should be valid for it. If the banner still shows the old name, the mail service was not restarted or still has the old name in its own configuration.
Finally, restart the VPS one more time and re-run `hostname -f`. This catches cloud-init or DHCP quietly reverting the change, which is the failure mode that otherwise surfaces weeks later during an unrelated reboot.
## What a Rename Can Break
Changing a hostname on a server that has been in service for a while is a bigger event than it looks, because a surprising number of things store the name rather than looking it up. Before renaming a production machine, check for these:
- **TLS certificates.** Any certificate issued for the old hostname stops matching. This includes web server certificates, mail certificates and control panel certificates.
- **Software licences.** Some commercial software, including several control panels, ties a licence to the hostname or the IP address. A rename can invalidate the licence until it is reissued.
- **Monitoring, backup and log systems.** Agents commonly register under the hostname. After a rename the old host stops reporting and a new one appears, so alerting rules and retention on the old identity need updating, and you may be left with a permanently "down" ghost host.
- **Database grants.** MySQL and MariaDB privileges are granted to `user@host`. Grants written against the old hostname stop matching, which shows up as an application that suddenly cannot authenticate to a database on the same machine.
- **Clustered services that use node names.** Software that identifies cluster members by hostname, such as message brokers and some database replication setups, can refuse to start or lose its data directory reference after a rename. Check the documentation for anything clustered before renaming.
- **Scripts and configuration that hardcode the name.** Cron jobs, backup destinations, rsync targets and firewall rules written against the old name will silently do the wrong thing.
If the machine is in production and any of the above applies, the safer sequence is to add the new name in DNS first, run both names in parallel where the software allows it, then retire the old name once nothing references it.
## Troubleshooting
- **The panel shows the new hostname but the operating system still reports the old one**: expected behaviour on KVM and Xen HVM. The panel field is SolusVM's record and does not edit a running guest's configuration. Set the name inside the operating system with `hostnamectl set-hostname` as described above.
- **The hostname reverts to the old name after every reboot**: something is re-applying it at boot. Check for cloud-init first and set `preserve_hostname: true` in `/etc/cloud/cloud.cfg`. If cloud-init is not installed, check whether the DHCP client is supplying a hostname.
- **Every `sudo` command pauses for several seconds**: the server cannot resolve its own hostname and is waiting for a DNS timeout. Add the correct line to `/etc/hosts` mapping the IP address to the fully qualified and short names.
- **`hostname -f` returns the short name instead of the full one**: in the `/etc/hosts` entry, the fully qualified name must come immediately after the IP address, with the short name after it.
- **SolusVM refuses the hostname you typed**: the field validates the format. Use lowercase letters, digits, hyphens and dots only, supply a fully qualified name with at least one dot, and remove any trailing dot or whitespace.
- **Mail is being accepted but lands in spam since the rename**: reverse DNS almost certainly no longer matches. Check `dig +short -x` against your IP address and `dig +short A` against your hostname and confirm both point at each other, then confirm the mail server's `EHLO` name matches too.
- **Mail is being rejected outright with a message about the HELO or EHLO name**: the mail service still announces the old or a non-qualified name. Update the mail server's own hostname setting and restart it, rather than relying on the system hostname.
- **The VPS does not come back after the restart**: the hostname change is very unlikely to be the cause, but you will not be able to diagnose it over SSH. Open the [VNC console in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/), which shows the boot messages SSH cannot.
- **A control panel or licensed application stopped working after the rename**: its licence is probably keyed to the old hostname. Reissue the licence against the new name through the vendor, then restart the application.
If the hostname change is not sticking, or reverse DNS for your VPS needs to be updated and the panel gives you no way to do it, contact the team that runs the SolusVM master server for your VPS using the details in your VPS welcome email. Noiz clients can open a support ticket with the Noiz support team; include the main IP address of the VPS, the exact hostname you want, whether you need the PTR record set as well, and the output of `hostname -f` from inside the server.
# How to Change the Disk Driver to Virtio or IDE in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-change-the-disk-driver-to-virtio-or-ide-in-solusvm/
This guide explains what the **Disk Driver** setting in the SolusVM control panel actually controls, why **Virtio** is normally the right answer, when **IDE** is the safer one, and why changing this setting on a server that already has an operating system installed is one of the few clicks in SolusVM that can leave a working VPS unable to boot. SolusVM is a virtualisation management panel used by hosting providers to give VPS customers direct control over their own virtual machines. The same setting is described in several ways depending on where you read about it: disk driver, storage driver, disk bus, block device driver, or simply "the disk controller". They all refer to the same thing, which is the type of virtual disk controller the hypervisor presents to the operating system inside your VPS.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is published by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below. SolusVM's client interface has been reworked between major versions, and the options a provider exposes vary, so the wording and the list of available drivers in your copy may differ; the behaviour described here holds regardless.
### Official Documentation Reference
- [SolusVM Documentation (home)](https://docs.solusvm.com/en/): the vendor's documentation hub. If a control in your panel is worded differently from the one described here, search this site for the current wording.
- [Quick Start Guide: Customers (SolusVM)](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/): the vendor's walkthrough of the customer side of SolusVM, covering sign-in, server selection and the controls available on a server.
- [SolusVM Release Notes](https://docs.solusvm.com/en/release-notes/): the authoritative record of what changed in each release, useful when a setting has moved or been renamed since a screenshot was taken.
- [Virtio (KVM project)](https://www.linux-kvm.org/page/Virtio): the project's own description of what paravirtualised drivers are and why they exist. This is the concept behind the Virtio option in the panel.
- [Virtio driver API (Linux kernel documentation)](https://docs.kernel.org/driver-api/virtio/virtio.html): the kernel-side reference, worth a look if you want to know exactly which module has to be present for a Linux guest to see a Virtio disk.
- [QEMU block device documentation](https://www.qemu.org/docs/master/system/qemu-block-drivers.html): the emulator-side reference for how virtual disks are attached and what features, such as discard, each interface supports.
- [Creating Windows virtual machines using Virtio drivers (Fedora)](https://docs.fedoraproject.org/en-US/quick-docs/creating-windows-virtual-machines-using-virtio-drivers/): the clearest public write-up of how a Windows guest obtains Virtio storage drivers, which is the part that trips people up.
- [virtio-win driver packages](https://github.com/virtio-win/virtio-win-pkg-scripts): where the signed Windows Virtio driver ISO comes from, including the stable and latest builds.
## Prerequisites
- Access to the SolusVM control panel address, username and password issued when the VPS was set up. These arrive in your welcome email; do not guess the panel address. If you are not signed in yet, start with [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
- A VPS running under full virtualisation. This setting exists only where the hypervisor emulates hardware for the guest, such as KVM or Xen HVM. Container-style virtual servers share the host kernel and have no virtual disk controller to choose, so the option is absent or greyed out. Check which type you have with [How to Check the RAM of VPS, IP, Disk Capacity and Virtualization Details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
- A verified, tested backup, or a server with nothing on it yet. Treat this setting as one that can cost you a boot, and act accordingly.
- Working VNC console access, or at least the knowledge of how to reach it. If the guest does not come back, the console is how you find out why. See [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/).
## Read This First: When It Is Safe to Change
There is one rule that matters more than everything else on this page.
**Change the disk driver before the operating system is installed, not after.** The right moments are immediately before an OS reinstall, or on a freshly provisioned VPS you have not built anything on yet. At that point the setting costs you nothing, because the installer will detect whatever controller it is given and configure itself around it.
Changing it on a server that already has an operating system installed is a different proposition entirely. The guest was configured at install time for the controller it was given, and swapping that controller underneath it can leave the operating system unable to find its own disk. When that happens the VPS powers on normally, the panel reports it as `online`, and the machine never reaches a login prompt. Nothing is lost from the disk, but the server is down until you put the setting back or repair the guest. The section on recovery below covers both.
If your VPS is already installed and running perfectly well on IDE, the honest answer is usually to leave it alone unless you have a specific reason to move, and to schedule the change alongside a reinstall rather than on its own.
## What the Disk Driver Setting Actually Does
Your VPS does not have a disk. It has a file or a logical volume on the host machine, which the hypervisor presents to the guest as though it were a disk attached to a disk controller. The Disk Driver setting chooses which kind of controller it pretends to be. That choice is invisible from outside the server and enormously consequential inside it, because the operating system will only see a disk it has a driver for.
### IDE: emulated, universally understood, slow
Choosing IDE tells the hypervisor to emulate a real, decades-old ATA disk controller in software, right down to its register layout. The advantage is compatibility that is as close to guaranteed as anything gets: every operating system worth installing has supported IDE since long before virtualisation was common, so it works with no drivers, no preparation and no thought. That is exactly why it is the safe fallback.
The cost is performance. Every read and write the guest issues is a sequence of operations against emulated hardware registers, and each one forces a transition out of the guest into the hypervisor to be handled. The emulated controller is also single-queue and shallow by design, because that is what the real hardware was. On a busy server the result is measurably lower throughput, far lower IOPS under concurrency, and a chunk of CPU spent emulating a disk controller instead of running your workload.
### Virtio: paravirtualised, fast, needs a driver
Virtio takes the opposite approach. Instead of imitating hardware that never existed in this machine, it presents an interface designed for virtual machines, on the understanding that the guest knows it is a guest. The guest and the hypervisor exchange work through shared memory ring buffers, so a batch of requests can be handed over with a single notification rather than a stream of register writes. There is no hardware behaviour to reproduce, so there is far less overhead per operation.
In practice that means materially higher throughput and IOPS, meaningfully lower CPU cost per unit of disk work, and much better behaviour when many requests are in flight at once, which is the normal state of affairs for a database or a busy web server. Virtio also carries capabilities that emulated IDE simply does not expose, the most useful being discard and TRIM support: on thin-provisioned host storage, that is what lets deleted data actually give space back instead of the image growing forever.
The single condition is that the guest must have the Virtio block driver available at boot, before it has mounted anything. On Linux that is the `virtio_blk` and `virtio_pci` modules, and they must be inside the initramfs, not merely installed on the root filesystem, because the kernel needs them in order to reach the root filesystem in the first place. On Windows the driver has to be installed and registered as boot-critical before the switch, not afterwards.
### So which should you pick
Choose **Virtio** in almost every case. Every current mainstream Linux distribution ships the modules and builds them into its initramfs automatically when it detects a Virtio disk during installation, so a normal install onto a Virtio disk simply works and runs faster for it. Windows Server and current Windows desktop releases support Virtio well too, provided the driver is loaded during installation from the driver ISO.
Choose **IDE** when compatibility beats speed:
- You are installing an operating system whose installer cannot see a Virtio disk and offers no way to load a driver. This is the classic reason, and it covers a lot of older or niche images.
- You are installing Windows from an ISO and have no way to supply the Virtio driver at the disk selection screen. Windows will report that it found no drives, and IDE is the pragmatic way past it.
- You are installing something old, unusual or minimal: an ancient kernel, a router or firewall distribution, a rescue image, or a stripped-down appliance that was never built with Virtio in mind.
- You are recovering a server that stopped booting after a switch to Virtio, and you need it back up now.
If your panel offers other options such as SCSI or Virtio SCSI alongside these two, they are further points on the same scale rather than exceptions to it, and the same rule applies: the guest must have a driver for whatever you select, present at boot.
## Step 1: Sign In to SolusVM
Open the SolusVM control panel using the address in your welcome email, and sign in with the panel credentials issued for the VPS. These are the control panel credentials, which are entirely separate from the root or administrator password of the operating system running inside the VPS. Confusing the two is a frequent cause of failed sign-ins.
## Step 2: Select the Correct VPS
If your account holds more than one virtual server, the panel presents a list or a selector so you can choose which one you are working on. Pick the correct server before you change anything. Check the hostname or the primary IP address shown alongside the entry rather than its position in the list, because the ordering changes as servers are added and removed, and this particular setting is not one you want to apply to the wrong machine.

## Step 3: Change the Disk Driver
Scroll down to the **Settings** tab and find the **Disk Driver** option. Select the driver you want from the drop-down menu and save the change.

Nothing happens to the running server at this point. You have edited the virtual machine's definition on the host, not the machine itself. The guest continues running on whatever controller it was given when it was last started, and will keep doing so until it is stopped and started again.
## Step 4: Power Cycle for the Change to Take Effect
The new setting is only read when the virtual machine is created afresh on the host, which means a full stop followed by a start. A `reboot` issued from inside the guest often does not qualify, because on many hypervisors that restarts the operating system without tearing down and rebuilding the virtual machine, so the old controller is still attached afterwards. This catches people out regularly: they change the setting, reboot from the shell, see no difference, and conclude the setting did not save.
Do it from the panel instead. Either use the panel's own restart control, described in [How to Reboot/Restart VPS in SolusVM](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/), or, if you want to be certain, shut the server down cleanly and then start it again, using [How to Forcefully or Gracefully Shut Down the VPS in SolusVM](/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/) followed by [How to Start/Boot Your VPS in SolusVM](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/). Before you do, open the VNC console and leave it open, so that if the server does not come back you are already watching the screen that will tell you why.
## How to Confirm It Actually Took Effect
The panel showing the new value proves only that the setting was saved. To prove the guest is really using it, look from inside the server after the power cycle.
On a Linux guest, the device name is the quickest tell. A Virtio block device appears as `/dev/vda`, with partitions `/dev/vda1` and so on. An emulated IDE disk appears as `/dev/sda` on any modern kernel, or as `/dev/hda` on a very old one. List the block devices:
```
lsblk
```
Then confirm the driver is genuinely loaded and bound, rather than the device merely being present:
```
lsmod | grep virtio
lspci | grep -i virtio
```
On a Windows guest, open Device Manager and look under **Storage controllers**. A VirtIO SCSI or block controller listed there without a warning icon means the driver is installed and working. A yellow exclamation mark against it means Windows can see the device but has no working driver for it, which is the state that produces a failure to boot the next time round.
## If the VPS Will Not Boot After the Change
This is the failure this setting is known for, and it looks alarming without being dangerous. The panel reports the server as `online` because the virtual hardware is powered on, but nothing responds and the VNC console shows the machine stuck early. Your data is untouched. The operating system simply cannot see the disk it lives on.
What you see on the console tells you where it stopped:
- A bootloader that cannot find a bootable device, or a firmware screen offering a network boot, means the disk was not visible before the operating system even started loading.
- A Linux kernel panic along the lines of `Unable to mount root fs on unknown-block(0,0)`, or a dracut or initramfs emergency shell, means the kernel started but its initramfs contains no driver for the new controller.
- A Linux boot that hangs waiting for a device, or drops to a maintenance shell complaining about a filesystem it cannot find, usually means the disk is visible but under a different name, and `/etc/fstab` or the bootloader configuration is still referring to the old one.
- A Windows `INACCESSIBLE_BOOT_DEVICE` stop error means the same thing in Windows terms: the boot-critical storage driver for the new controller is not registered to start at boot.
**The fix, in every case, is to put the setting back to what it was and power cycle again.** Change Disk Driver to its previous value, stop the server, start it, and it will come up exactly as before. Do that first and troubleshoot afterwards, from a running server, rather than experimenting on a machine that is down.
### Preparing the guest so the switch does work
Once you are back up, you have three ways forward, in descending order of how much you should like them.
**The reliable option is to reinstall on Virtio.** Set the disk driver first, then reinstall, and the installer configures the guest for Virtio from the outset with nothing left to go wrong. This is the approach worth taking whenever the server is new, rebuildable, or due a rebuild anyway. See [How to Reinstall OS Using SolusVM OS-Reinstaller](/solusvm/how-to-reinstall-the-os-on-a-vps-using-the-solusvm-os-reinstaller/), or, if you need control over partitioning or a specific image, [How to Manually Install/Reinstall an OS using SolusVM for a Customized Installation](/solusvm/how-to-manually-install-an-os-from-iso-in-solusvm/). Reinstalling destroys everything on the disk, so confirm your backups before you start.
**The workable option on Linux is to prepare the running guest first, while it is still on IDE and still bootable.** Two things have to be true before you switch. First, the Virtio modules must be inside the initramfs rather than only on disk, which means adding `virtio_blk`, `virtio_pci` and, if your panel offers a SCSI variant, `virtio_scsi` to the initramfs configuration and rebuilding it for every installed kernel. The mechanics differ by distribution: consult [the dracut manual](https://man7.org/linux/man-pages/man8/dracut.8.html) on distributions that use dracut, or [the mkinitcpio documentation](https://wiki.archlinux.org/title/Mkinitcpio) where that is the tool, and check your distribution's own guidance if it uses neither. Second, nothing in the boot path may refer to the disk by name, because the name is about to change from `/dev/sda` to `/dev/vda`. Convert every entry in `/etc/fstab` and every root device reference in the bootloader configuration to a UUID, which does not change when the controller does. You can list the UUIDs with:
```
blkid
```
Reboot once on IDE after making those changes, to prove the server still boots with the new initramfs and the UUID-based configuration. Only then change the disk driver and power cycle. That intermediate reboot is the step people skip and then regret, because it separates "the initramfs rebuild broke something" from "the driver switch broke something", and finding out which is far easier before both have happened at once.
**On Windows, the equivalent preparation is to get the driver installed and marked boot-critical before the switch.** The usual approach is to attach a second, small Virtio disk to the running machine so that Windows detects the new controller and installs the driver for it normally, at which point the boot-start registration is in place and the system disk can be switched safely. Doing this on a hosted VPS generally needs your provider's involvement, since attaching an extra disk is not something the client panel exposes. The [Fedora guide to Virtio drivers on Windows](https://docs.fedoraproject.org/en-US/quick-docs/creating-windows-virtual-machines-using-virtio-drivers/) covers the underlying mechanics, and the drivers themselves come from the [virtio-win packages](https://github.com/virtio-win/virtio-win-pkg-scripts). If the Windows install is not precious, reinstalling with the driver loaded at the disk selection screen is considerably less work.
## Troubleshooting
- **Symptom**: the setting saves but nothing changes inside the guest. The virtual machine has not been recreated on the host. A reboot issued from inside the operating system is not enough on many hypervisors. Shut the VPS down from the panel, then start it again, and check `lsblk` once it is up.
- **Symptom**: the VPS shows `online` in the panel but never becomes reachable after the change. The operating system cannot see its disk. Set the disk driver back to its previous value and power cycle. Then read the section above on preparing the guest before trying again.
- **Symptom**: the console shows a dracut or initramfs emergency shell. The kernel booted but has no driver for the new controller in its initramfs. Revert the setting, boot on the old driver, add the Virtio modules to the initramfs, rebuild it for every installed kernel, reboot once to prove it still works, and only then switch.
- **Symptom**: Linux boots but drops to a maintenance shell over a filesystem it cannot find. The disk is visible under a new name. Revert, convert `/etc/fstab` and the bootloader's root device reference to UUIDs, verify with a reboot, then switch again.
- **Symptom**: Windows stops with `INACCESSIBLE_BOOT_DEVICE`. The Virtio storage driver is not registered as boot-critical. Revert the setting to restore the server, then install and register the driver from within the running system before trying again.
- **Symptom**: the operating system installer reports that it cannot find any disks. The installer has no driver for the controller you selected. Either supply the driver during installation, which is what the driver ISO exists for on Windows, or set the disk driver to IDE, complete the installation, and treat moving to Virtio as a separate exercise afterwards.
- **Symptom**: there is no Disk Driver option in your panel at all. Either the VPS is container-based and has no virtual disk controller to configure, or your provider has not exposed the setting to client accounts. Confirm the virtualisation type first with [How to Check the RAM of VPS, IP, Disk Capacity and Virtualization Details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
- **Symptom**: disk performance is no better after switching to Virtio. Confirm the guest is genuinely on Virtio by checking for `/dev/vda` rather than `/dev/sda`. If it is, the limit is elsewhere: host storage contention, an I/O-bound workload that was never controller-limited, or a filesystem or database configuration issue inside the guest. Virtio removes emulation overhead; it does not make the underlying storage faster.
- **Symptom**: everything works but you cannot reach the network after also changing the network card. That is a separate setting with the same failure mode, and it is covered in [How to Change the Network Card to Virtio, Intel PRO, or Realtek in SolusVM](/solusvm/how-to-change-the-network-card-to-virtio-intel-pro-or-realtek-in-solusvm/). Change one hardware setting at a time so you always know which one caused the problem.
## Related Settings Worth Knowing About
The disk driver sits alongside several other virtual hardware options in the same part of the panel, and they share a characteristic: each is a change to the machine the operating system was installed on, so each can produce a server that powers on and then does nothing useful. The network card driver is the closest relative, covered in [How to Change the Network Card to Virtio, Intel PRO, or Realtek in SolusVM](/solusvm/how-to-change-the-network-card-to-virtio-intel-pro-or-realtek-in-solusvm/). The APIC, ACPI and PAE toggles are the other set, described in [How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/), and they can stop an older or 32-bit guest from starting for much the same reason.
The habit that keeps this straightforward is to change one of them at a time, power cycle, confirm the server comes back, and only then move on to the next. It takes a few minutes longer and it removes all the guesswork from the moment something breaks.
If a VPS does not come back after a disk driver change, revert the setting first and investigate second; the server being up is worth more than knowing immediately why it went down. If you are a Noiz client and you are unsure what the VNC console is telling you, open a support ticket with the Noiz support team, including the exact error text on the console, the driver you changed from and to, and the time of the change. Those three details are usually enough to identify the cause without further back and forth.
# How to Change the Network Card to Virtio, Intel PRO, or Realtek in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-change-the-network-card-to-virtio-intel-pro-or-realtek-in-solusvm/
This guide explains how to change the network card a VPS presents to its operating system from the SolusVM control panel, and, more usefully, how to decide which of the options to pick. The setting is often labelled **Network Card**, **NIC**, or **NIC driver**, and the choices are normally **Virtio**, **Intel PRO**, and **Realtek**. Those are not three brands of hardware, because there is no hardware involved. They are three different ways the hypervisor can pretend to be a network adapter, and the difference between them is worth roughly an order of magnitude in throughput and CPU cost. This article is for anyone with access to a VPS managed through SolusVM, whether that is an end user in the client area or an administrator working on a customer's virtual server.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is maintained by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation: Introduction to SolusVM, Common Notation and Glossary](https://docs.solusvm.com/en/solusvm1/introduction/introduction-to-solusvm-and-common-notation-and-glossary/), the entry point for the legacy SolusVM 1 documentation set that the classic client area belongs to
- [SolusVM Documentation: Customers Quick Start Guide](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/), the customer-side workflow in the newer SolusVM interface
- [QEMU Documentation: Network Emulation](https://www.qemu.org/docs/master/system/devices/net.html), the authoritative list of the emulated adapter models behind the panel's friendly names, including `virtio-net-pci`, `e1000`, and `rtl8139`
- [KVM Project: Virtio](https://www.linux-kvm.org/page/Virtio), a plain explanation of what paravirtualised devices are and why they exist
- [Linux Kernel Documentation: Virtio on Linux](https://docs.kernel.org/driver-api/virtio/virtio.html), the guest-side driver model that the `virtio_net` driver is built on
- [virtio-win: KVM Guest Drivers for Windows](https://github.com/virtio-win/kvm-guest-drivers-windows), the source project for the NetKVM adapter driver that Windows guests need before Virtio will work
- [Linux manual page: `ethtool(8)`](https://man7.org/linux/man-pages/man8/ethtool.8.html), used below to confirm which driver a Linux guest actually loaded
## Prerequisites
- Access to [log in to the SolusVM control panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/). The address you log in at is given in the welcome email for your VPS.
- A hardware-virtualised VPS. The network card selector belongs to full virtualisation, where a virtual machine has its own emulated PCI bus. Container-based virtual servers share the host kernel and its networking stack, so they have no adapter model to choose and the option is simply absent. If you are not sure which type you have, [check the virtualisation details for the VPS in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
- Console access you have tested at least once. Changing the network card is one of the few settings that can cost you SSH access to your own server, so know how to reach the [VNC console in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/) before you change anything, not after.
- A maintenance window. The change only takes effect on a full power cycle, so the VPS will be offline for a short period.
## What the Network Card Setting Actually Changes
A virtual machine has no network chip in it. The hypervisor runs a device model in software that behaves, from the guest operating system's point of view, like a specific piece of silicon on a PCI bus. The **Network Card** setting selects which device model gets attached. The guest then probes the PCI bus at boot, sees a particular vendor and device ID, and loads whichever of its own drivers claims that ID.
That is why the setting is effectively a driver choice, and why it can only change while the machine is being built rather than while it is running. It is also why the guest has to already own a driver for whatever you pick, which is the single fact that determines whether the change succeeds or leaves you with no network at all.
### Virtio
Virtio is not an emulation of any real network card. It is a paravirtualised interface: the guest knows perfectly well that it is a virtual machine, and instead of pretending otherwise it talks to the host through shared ring buffers in memory. Packets are handed over in batches, and the expensive part of device emulation, trapping out to the host on every register access, largely disappears.
In Linux the driver is `virtio_net` and it has shipped in the mainline kernel since version 2.6.24, released in January 2008, so every current distribution has it and most build it into the installer image. In Windows it is called NetKVM and it is not part of Windows at all, so it must be installed from the virtio-win driver package before the adapter will work.
### Intel PRO/1000
This option emulates an Intel gigabit-class controller, presented to QEMU as the `e1000` family. It is the most widely recognised virtual network card in existence: almost every operating system released this century, including Windows installers running from unmodified media, has a driver for it already. That universality is the whole point of it. The cost is that every packet passes through a full register-level emulation of a physical chip, which burns host CPU that Virtio does not.
### Realtek RTL8139
This emulates a Realtek Fast Ethernet controller, the `rtl8139` model in QEMU. It is a 100 Mbit part, and the emulation is honest about that, so the link tops out around 100 Mbit no matter how much bandwidth the host has available. It exists for compatibility with genuinely old guests that predate reliable gigabit drivers. On anything modern it is the worst of the three: slowest link, heaviest emulation overhead per byte moved. Treat it as a last resort rather than a middle option.
## Why Virtio Is Normally the Right Choice
For any current Linux distribution, and for any Windows guest with the virtio-win drivers installed, Virtio is the correct setting and the others are compromises. The reasons are concrete rather than theoretical:
- **Throughput is not capped by an imaginary chip.** Emulated cards inherit the limits of the hardware they imitate. Virtio has no fixed line rate, so the ceiling is what the host and the network can actually deliver.
- **CPU cost per packet is far lower.** Emulating a real controller means intercepting the guest's reads and writes to device registers, and each interception is a transition out of the guest. Virtio moves descriptors through a shared queue, so a burst of packets costs a fraction of the transitions. On a small VPS, where CPU is the resource you are most likely to run short of, that difference shows up as headroom for your application rather than as a benchmark number.
- **Modern offloads work properly.** Checksum offload and segmentation offload let the guest hand over one large buffer instead of many small packets. Virtio supports these cleanly, which is a large part of why bulk transfers such as backups and database replication improve so noticeably.
- **It is the path everything else is tested against.** Virtio is the default for virtually all KVM-based platforms, so it receives the most testing in both the host stack and the guest kernels.
If the VPS is running a current Linux distribution and the network card is currently set to Realtek, you are leaving a large amount of performance unclaimed for no benefit at all.
## When Virtio Is Not the Right Choice
There are real cases where one of the emulated cards is the correct answer. Recognising them beforehand saves an hour on the console:
- **The guest has no Virtio driver yet.** This is by far the most common failure. A Windows Server installation that has never had virtio-win installed will boot with Virtio selected, find an unknown PCI device, and have no network. Install NetKVM first, while the adapter is still Intel PRO and the machine is still reachable, then switch.
- **You are installing an operating system from an ISO.** Installers boot with whatever drivers are on the media. Windows installation media does not include NetKVM, so a Virtio adapter is invisible during setup. Install with Intel PRO, add the drivers inside the installed system, then change the adapter. The same caution applies when doing a [manual OS installation in SolusVM](/solusvm/how-to-manually-install-an-os-from-iso-in-solusvm/).
- **The guest is old, unusual, or an appliance.** Very old Linux kernels, older BSD releases, and firewall or router appliances built on cut-down operating systems may have no Virtio support compiled in. Appliance images in particular are often built for a fixed hardware profile, and Intel PRO is the profile they expect.
- **You need to network boot.** Booting from the network depends on an option ROM in the adapter's firmware. Support for that is far more consistent on the emulated Intel card than on Virtio, so if PXE is part of your workflow, test before committing.
- **You are diagnosing a network fault.** Temporarily switching to Intel PRO is a genuinely useful test. If packet loss, stalls, or odd MTU behaviour disappear when the adapter changes, the problem is in the driver or offload path rather than in the network. Switch back afterwards.
Realtek is left over from an era of guests that most people no longer run. Choose it only when a specific operating system refuses to work with the other two.
## How to Change the Network Card in SolusVM
Before you start, note which adapter is currently selected and what the working network configuration inside the guest looks like. If the change goes badly, the fastest recovery is putting the old value back, and that only works if you wrote it down.
1. Log in to your SolusVM control panel using the address in your VPS welcome email.
2. If your account holds more than one virtual server, select the one you want to change. Check the hostname and main IP address before going any further, because nothing later in the process tells you which server you picked. 
3. Scroll down to the **Settings** tab and find the **Network Card** option. Select the adapter you want from the drop-down menu. The list is drawn from what the virtualisation type supports, so you may see fewer than three options. 
4. Save the change. SolusVM records it against the virtual server's configuration on the host node. Nothing happens to the running machine at this point, and the guest still has the old adapter.
5. Power cycle the VPS so the virtual machine is rebuilt with the new device. The reliable way to do this is a [graceful shutdown from the panel](/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/) followed by a [boot of the VPS](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/). A [panel reboot](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/) usually achieves the same thing, but a `reboot` issued inside the guest operating system will not: that restarts the operating system without ever tearing down the virtual machine, so the old adapter is still there when it comes back.
Two things about this that catch people out. First, the setting may be greyed out or rejected while the VPS is running, because some configurations only accept hardware changes against a stopped machine. If the panel refuses the change, shut the VPS down first, change the setting, then boot it. Second, the option can be hidden by whoever operates the SolusVM master server. If the **Network Card** option is not on the **Settings** tab at all, it has been disabled for your account or your virtualisation type, and it will need to be changed for you.
Your IP addresses are not affected by any of this. They are assigned by SolusVM to the virtual server rather than to the adapter model, and the MAC address is normally carried across unchanged. Normally is not always, though, and a changed MAC is the root cause of most of the problems in the troubleshooting section below, so confirm it rather than assume it.
## How to Confirm the Change Took Effect
"The site still loads" is not confirmation. The guest may have quietly fallen back, or it may be running on a different interface name than your configuration expects. Check the driver directly.
On a Linux guest, look at what is on the PCI bus and which driver claimed it:
```
lspci | grep -i ethernet
ip -br link
ethtool -i eth0
```
Substitute your own interface name in the last command. What you are looking for is:
- **Virtio**: `lspci` reports a `Virtio network device`, and `ethtool -i` reports `driver: virtio_net`. Do not be alarmed that `ethtool eth0` reports the speed as unknown. Virtio has no emulated line rate to report, and that is the expected result rather than a fault.
- **Intel PRO**: `lspci` reports an Intel gigabit controller, and `ethtool -i` reports `driver: e1000`, with a link speed of 1000 Mb/s.
- **Realtek**: `lspci` reports an RTL-8139 controller, and the driver is one of the `8139` variants, with a link speed of 100 Mb/s.
On a Windows guest, open Device Manager and expand **Network adapters**. A working Virtio adapter appears as `Red Hat VirtIO Ethernet Adapter`. A yellow warning icon on an **Ethernet Controller** under **Other devices** means the opposite: the adapter is present but Windows has no driver for it, and NetKVM needs installing from the virtio-win package.
Finally, confirm the network itself, not just the driver. Check that the interface has its address, that the default route is present, and that name resolution works:
```
ip -4 addr show
ip route show default
ping -c 3 1.1.1.1
```
An interface with a driver loaded but no IP address is the classic symptom of the rename problem described below.
## Troubleshooting
- **The VPS boots but has no network at all after the change**: the guest almost certainly has no driver for the adapter you selected. Open the VNC console, log in locally, and put the old adapter back from the panel. Then install the correct driver while the machine is reachable, and change the adapter afterwards. On Windows this means installing NetKVM from virtio-win before selecting Virtio.
- **The adapter is there, the driver loaded, but the interface has no IP address**: the interface has been renamed and your configuration is still referring to the old name. On systems using predictable interface names, the name is derived from the adapter's position and identity, so a driver change can turn `eth0` into `ens3` or similar. Run `ip -br link` at the console to see the real name, then update the network configuration to match, whether that is a netplan file, an `ifcfg` file, or a NetworkManager connection profile.
- **The interface came back as `eth1` instead of `eth0`**: this is the older udev persistent naming rule, which binds a name to a MAC address it has seen before. If the MAC changed with the adapter, the old rule keeps `eth0` reserved and the new card is given the next free number. On distributions that still use it, remove `/etc/udev/rules.d/70-persistent-net.rules` and reboot so the rule is regenerated.
- **The old network settings vanished on Windows**: Windows binds TCP/IP settings to a specific adapter instance, so a new adapter model appears as a brand new connection with default settings, and the previous one becomes a hidden device that is still holding the static IP. Set the address again on the new adapter. If Windows warns that the address is already assigned to another adapter, show hidden devices in Device Manager and remove the old one.
- **The change appears to save but the guest still shows the old card**: the virtual machine was never actually rebuilt. An in-guest `reboot` does not do it. Shut the VPS down from the panel, confirm it reports as [offline in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/), then boot it again.
- **Throughput did not improve after switching to Virtio**: confirm the driver first with `ethtool -i`, because a guest that silently fell back to the old configuration will look fine until you check. If `virtio_net` is loaded and throughput is still poor, the bottleneck is elsewhere: the host node, the upstream link, a bandwidth limit applied to the virtual server, or the application itself. Test with something that is not your web stack before drawing conclusions.
- **The connection is fast but unstable, with stalls on large transfers**: suspect offload or MTU behaviour rather than the panel setting. Temporarily selecting Intel PRO is a valid diagnostic. If the instability follows the adapter, the driver or its offload settings are involved; if it does not, look at the path outside the VPS.
- **You changed both the network card and the disk driver at once and the VPS will not boot**: change one thing at a time. A disk driver the guest cannot use will stop the machine booting entirely, which looks identical to a network problem from the outside. Put the [disk driver](/solusvm/how-to-change-the-disk-driver-to-virtio-or-ide-in-solusvm/) back first, then deal with the network separately.
If a network card change leaves your VPS unreachable and the console does not get you back in, escalate to the team that runs the SolusVM master server for your VPS, whose contact details are in your VPS welcome email. Noiz clients can open a support ticket with the Noiz support team; include the VPS hostname and main IP address, which adapter you changed from and to, whether the guest is Linux or Windows, and the output of `ip -br link` from the console.
# How to Change the SolusVM Account Email Address
Source: https://docs.noiz.ie/solusvm/how-to-change-the-solusvm-account-email-address/
Your SolusVM control panel account carries its own email address, stored in the panel and independent of every other address attached to your service. This guide shows you how to change that address from inside the SolusVM client area, what the address is actually used for, and what it deliberately does not affect.
The distinction matters more than it first appears. The address you change here belongs to the **panel account**: the identity that signs in to SolusVM and receives the panel's own notifications. It is not a mailbox on your VPS, it is not the address your server sends outbound mail from, and it is not the contact address held on your hosting or billing account. Changing it in SolusVM changes it in SolusVM, and nowhere else.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is maintained by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM 1 documentation](https://docs.solusvm.com/en/solusvm1/) (the vendor publishes this set as legacy documentation)
- [Two-factor authentication in the SolusVM 1 client area](https://docs.solusvm.com/en/solusvm1/advanced-configuration/client-area/enabling-two-factor-authentication/)
- [SolusVM 2 quick start guide: customers](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/)
## Which SolusVM are you looking at?
The procedure below describes the SolusVM 1 client area, the one with a **My Account** item in the top navigation bar and an **Account Settings** block on the page it opens. SolusVM 2 ships a rebuilt customer panel with different navigation, so if your panel looks nothing like the screenshots here, work from the SolusVM 2 customer documentation linked above instead. There the equivalent item is labelled **Account** rather than **My Account**, and the email address doubles as the login itself, so changing it also changes what you sign in with.
## Prerequisites
- You can [log in to the SolusVM control panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/). The panel address and your username come from the welcome email sent when the service was set up.
- You can already read mail at the new address. Confirm that before you save, not after.
- If two-factor authentication is enabled on the account, have your authenticator app or an unused recovery code to hand.
## What the SolusVM account email address is used for
Knowing what depends on this field tells you how much care the change deserves:
- **Password recovery.** A reset link for the panel account goes to this address. If it is wrong, you cannot recover the account yourself and have to ask the panel's administrator to correct it.
- **Panel notifications.** Alerts generated by SolusVM about your account and your servers are delivered here, including the [VPS login alert](/solusvm/how-to-enable-or-disable-the-solusvm-vps-login-alert/) if you have it switched on.
- **Two-factor enrolment identity.** When you enrol an authenticator app, SolusVM uses this address as the account label written into the app, and as the identifier in the manual enrolment step for anyone who types the secret key by hand instead of scanning the QR code.
## What changing it does not do
This is where most support tickets on the subject actually start. Updating the panel account address does **not**:
- Create, rename or redirect any mailbox on the VPS. Mail hosted on the server is configured on the server, by whatever mail software you installed there.
- Change how the VPS identifies itself when it sends mail. That follows the server's [hostname](/solusvm/how-to-change-your-vps-hostname-in-solusvm/) and its own mail configuration, not the panel profile.
- Change the root or administrator password of the operating system inside the VPS. That is a separate credential entirely.
- Change your [SolusVM control panel password](/solusvm/how-to-change-the-solusvm-control-panel-password/), or your username.
- Update the contact address held on your hosting or billing account. Where a provider's billing system provisioned the SolusVM account, the two records are created together but maintained separately from then on, so an address updated in one is not reflected in the other. Update both if you want invoices and panel alerts to reach the same inbox.
## Change the account email address
### Step 1: Open My Account
1. Log in to the SolusVM control panel.
2. In the top navigation bar, click **My Account**.

### Step 2: Enter the new address and save
1. Find the **Account Settings** block on the page.
2. Replace the contents of the email field with the new address. Type it rather than pasting a fragment on top of the old value, so no stray characters survive at either end.
3. If the same form also offers password fields, leave them empty. They are only there for people who want to change the password at the same time, and a blank entry leaves the existing password untouched.
4. Click **Update Settings**. A success message confirms the change.

## Confirm it worked
The success banner tells you the form submitted, not that the value stored is the one you meant. Two quick checks settle it:
1. Reload **My Account**. The email field should redisplay the new address, character for character. Read it back rather than glancing at it, because a transposed letter in a familiar-looking domain is exactly the failure that survives a glance.
2. Log out and log back in, then reload **My Account** once more. This proves the value was written to the account record rather than only echoed back into the form.
If you want proof that mail actually arrives at the new address, the cleanest trigger is to switch the VPS login alert on, log in once, and check the new mailbox including its spam folder. Avoid using a password reset as your test, because it invalidates the credential you are currently signed in with.
## Things that catch people out
### There is no confirmation email, so a typo is silent
SolusVM applies the change the moment you click **Update Settings**. It does not send a verification link to the new address first and wait for you to click it. A mistyped address therefore looks like a complete success while quietly sending every future reset link and alert somewhere you cannot read. This is the single reason to read the value back after saving.
### Browser autofill on a form that also holds password fields
Password managers happily fill any password box they find on a settings page, including one you intended to leave alone. If your browser has populated those fields, clear them before saving. Submitting the form with an autofilled value can change the panel password to something you are not tracking, at which point you need the reset link that has just moved to a new address.
### Your authenticator app keeps showing the old address
An authenticator entry stores the label it was given at enrolment, so the app carries on displaying the previous email address after you change it. That is cosmetic. The shared secret behind the six-digit codes has not changed, so the codes keep working and no re-enrolment is needed. Only remove and re-add the entry if the stale label genuinely confuses you, and if you do, save the fresh recovery codes SolusVM issues, since generating a new set invalidates any unused older codes.
### Personal addresses on shared services
Where more than one person looks after the server, point the panel account at a shared or role address rather than an individual's mailbox. Panel alerts and reset links are worth very little if the only person who can read them has left, changed role or is on leave when something breaks.
## Troubleshooting
**Symptom**: the form reports an invalid email address. Fix: the field accepts a single, complete address only. Remove any display name, angle brackets, trailing full stop, comma-separated second address or leading and trailing whitespace, then save again.
**Symptom**: the success message appears but the old address is back after a reload. Fix: your session may have expired between loading the page and submitting it, so the request was discarded. Log in again, go straight to **My Account**, make the change and save without leaving the page idle in between.
**Symptom**: nothing ever arrives at the new address. Fix: check the spam and quarantine folders first, then confirm the stored address on **My Account** letter by letter. If both look right, the receiving mail service may be rejecting or filtering the panel's mail, so try an address on a different provider to isolate which side is dropping it.
**Symptom**: you saved a wrong address and can no longer receive a reset link. Fix: as long as you are still logged in, correct the address immediately and verify it before logging out. If you have already been logged out, the account record can only be corrected by the administrator of the SolusVM installation.
**Symptom**: **My Account** is missing from the navigation bar, or the email field is present but read-only. Fix: the panel administrator can restrict what customers may edit, and some installations deliberately keep the address in sync with an upstream billing record. In that case the change has to be made in the upstream system, and the panel picks it up from there.
If you cannot log in at all, only the administrator of the SolusVM installation can update the address for you, so that request goes to whoever operates the panel for your service. Where that is a Noiz service, open a support ticket with the Noiz support team and include your SolusVM username and the address you want set. Never put a password in a support ticket.
# How to Change the SolusVM Control Panel Password
Source: https://docs.noiz.ie/solusvm/how-to-change-the-solusvm-control-panel-password/
This guide shows you how to change the password on your **SolusVM control panel account**: the credential that signs you in to the panel itself. SolusVM is a VPS control panel, meaning it is the web interface that issues reboot, shutdown, reinstall and console commands to a virtual server. The password covered here is the one that gets you into that interface, and nothing else.
**Read this part first, because the distinction catches people out.** A VPS normally carries three separate passwords, and changing one has no effect on the other two:
- **The SolusVM control panel password** (this article). Authenticates you to the panel. No service inside the operating system uses it.
- **The VPS root or administrator password.** Authenticates you to the operating system itself, over SSH or RDP. See [How to Change the VPS OS Root/Admin Password in SolusVM](/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/).
- **The VNC console password.** Authenticates the browser console session that draws the server's screen. See [How to Change the VNC Password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/).
Changing the panel password locks nobody out of SSH, and resetting root does not change how you sign in to the panel. Treat them as three unrelated credentials, and never set one to the value of another.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is published by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation](https://docs.solusvm.com/en/): the vendor documentation set, covering both SolusVM 1 and SolusVM 2.
- [Introduction to SolusVM and common notation and glossary](https://docs.solusvm.com/en/solusvm1/introduction/introduction-to-solusvm-and-common-notation-and-glossary/): the SolusVM 1 terminology, including what the vendor means by Client, Master Node and Slave Node.
- [Two-factor authentication in the Client Area](https://docs.solusvm.com/en/solusvm1/advanced-configuration/client-area/enabling-two-factor-authentication/): the second factor you should add once the password is changed.
- [SolusVM 2 Quick Start Guide: Customers](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/): the newer customer interface, which is laid out differently from the client area described here.
- [NIST SP 800-63B, Digital Identity Guidelines: Authentication and Authenticator Management](https://pages.nist.gov/800-63-4/sp800-63b.html): the current public standard behind the password advice further down this page.
## Prerequisites
- You can already sign in to the panel. The form asks for your current password, so it is a change tool, not a recovery tool. If you cannot sign in at all, skip to [Troubleshooting](#troubleshooting).
- The panel address and the username or email address on the account. These are in the welcome email sent when the service was set up. If you are not sure how to reach the login screen, see [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
- The new password chosen and saved before you start, not invented in the form. See the next section for why.
## Choose the New Password Before You Open the Form
The panel account is a higher-value credential than most people assume. Whoever holds it can reinstall the operating system, which wipes the disk, and can open a console session onto the running machine. None of that requires knowing the root password. So the panel login is, in practice, a route to full control of the server and to destroying its data.
Two consequences worth acting on:
- **Make it long rather than clever.** [NIST SP 800-63B](https://pages.nist.gov/800-63-4/sp800-63b.html) sets a minimum of 15 characters for a password used on its own as a single factor. A generated passphrase or a random string from a password manager clears that comfortably. Forced character-class rules (one capital, one symbol) add far less than length does.
- **Make it unique to this panel.** The panel account can be reset by the administrator who runs the SolusVM installation, so it is not a secret that only you can ever hold. Reusing it as the root password, or as a mail or billing password, spreads that exposure to systems that had nothing to do with it.
Generate and store the new password first, then paste it in. Typing an improvised password straight into a change form is how people end up locked out of a panel five minutes later.
## Change the Password in the SolusVM Client Area
### Step 1: Sign in and open My Account
Sign in to the SolusVM control panel, then click **My Account** on the top navigation bar. This is the single page that holds the account-level settings: the password, the account email address and, on current versions, the two-factor authentication setting.

### Step 2: Complete the Change Account Password fields
Find the **Change Account Password** section and fill in all three fields:
- **Current Password**: the password you signed in with just now.
- **New Password**: the password you prepared.
- **Repeat New Password**: the same value again.

Paste into all three fields rather than typing, and paste the new password into both new-password boxes from the same source. Retyping the confirmation by hand is the most common cause of a rejected change, and a mismatch you cannot see is worse than one you can.
### Step 3: Click Update Password
Click **Update Password**. The change applies to the panel account immediately. Nothing inside the virtual server is touched, no service restarts, and the server keeps running exactly as it was.
## Verify That It Actually Worked
Do not take the on-screen confirmation as the end of it. Confirm the change the only way that proves anything:
1. Save the new password in your password manager, replacing the old entry rather than adding a second one.
2. Sign out of the panel completely.
3. Sign back in with the new password. If that succeeds, the change is real.
4. Sign out on any other browser or device where the panel was left signed in. Do not assume a password change ends sessions that are already open elsewhere. If your reason for changing the password was that someone else may have had access, closing those sessions is the part that matters.
If your browser offers to save the password, accept it only if the browser is the password manager you actually use. Two stores holding two different values for the same login is a problem you will meet again at the worst moment.
## Harden the Account While You Are on the Page
A password change on its own does very little against a determined attacker, and nothing at all if the old password is already in someone else's hands along with a live session. The settings that genuinely raise the bar are on the same **My Account** page:
- **Two-factor authentication.** Available to any client account on SolusVM 1 version 1.30.01 and higher, and disabled by default. Enabling it means a stolen password alone is no longer enough. The panel shows eight one-time recovery codes once, and once only, so save them somewhere you can reach without the panel. One caveat the vendor documents: two-factor authentication does not survive an account being imported into SolusVM 2, so if that migration happens you have to enable it again on the new side. Full steps are in the [vendor guide](https://docs.solusvm.com/en/solusvm1/advanced-configuration/client-area/enabling-two-factor-authentication/).
- **A correct account email address.** Password reset and alert mail goes to whatever address is on the account, so a stale address quietly breaks your recovery path. See [How to Change the SolusVM Account Email Address](/solusvm/how-to-change-the-solusvm-account-email-address/).
- **Login alerts.** These tell you when the account is used, which is how you find out about an unwanted sign-in rather than guessing. See [How to Enable or Disable the SolusVM VPS Login Alert](/solusvm/how-to-enable-or-disable-the-solusvm-vps-login-alert/).
## How Often Should You Change It?
Older guidance, including earlier versions of this article, recommended rotating the panel password every ninety days. That advice has since been withdrawn by the standards bodies that issued it. [NIST SP 800-63B](https://pages.nist.gov/800-63-4/sp800-63b.html) now states that subscribers shall not be required to change passwords periodically, and that a change shall be forced only where there is evidence the credential has been compromised. Calendar-driven rotation reliably pushes people towards shorter, patterned passwords that they can increment, which is a net loss.
Change the panel password when there is a reason to, for example:
- You shared it with someone, including a developer or contractor who no longer needs it.
- Somebody who had it has left the business.
- You typed it on a machine you do not trust, or on a machine later found to be infected.
- It appears in a breach dataset, or your password manager flags it as reused or exposed.
- You see a sign-in you cannot account for.
Otherwise, a long unique password plus two-factor authentication beats any rotation schedule.
## If the Panel Does Not Look Like the Screenshots
The **My Account** layout above is the SolusVM 1 client area. SolusVM 2 gives customers a different interface, built around projects and servers rather than a single account tab, and its account settings are not in the same place. If what you see does not match, check the [SolusVM 2 customer documentation](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/) instead. The three-passwords distinction at the top of this page still holds in either version.
## Troubleshooting
**Symptom: the form rejects your current password, but you are certain it is right.** You are signed in, so the password does work. The usual causes are a stale value pasted in by browser autofill, a trailing space picked up when copying, Caps Lock, or a different keyboard layout on the machine you are using. Clear the field completely and type the current password by hand once, as a test.
**Symptom: the change fails on a mismatch you cannot see.** Clear both new-password fields and paste the same value into each from your password manager. Do not retype the second one.
**Symptom: you cannot sign in at all, so you cannot reach this form.** This page requires the current password and cannot help you. Use the password reset link on the panel login screen if the operator of that installation has enabled it. If there is no reset link, or the reset mail never arrives, contact whoever issued the panel account: an administrator can reset a client password from the administrator side. The support contact for the service is in your welcome email.
**Symptom: the panel password changed, but SSH still rejects the new password.** Expected. SSH authenticates against the operating system, which never sees the panel password. Change the root or administrator password instead, using [How to Change the VPS OS Root/Admin Password in SolusVM](/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/).
**Symptom: the panel signs you in, but the VNC console then asks for a password you do not recognise.** Also expected. The console has its own credential. See [How to Change the VNC Password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/).
**Symptom: you changed the password because you think someone else had access.** The new password is the smallest part of the response. Anyone who reached the panel could have opened a console session or reinstalled the operating system, so treat the server itself as suspect: enable two-factor authentication, sign out every other session, change the root password, review the accounts and SSH keys on the server, and check what has been running on it.
## Getting Help
If you are unsure which of the three passwords you actually need to change, work through the list at the top of this page first, since that settles most cases. If you are locked out of the panel altogether, the reset has to come from the administrator of the SolusVM installation, using the support contact in your welcome email. For anything to do with your Noiz hosting account, the Noiz support team is available through the client area at [www.noiz.co.za](https://www.noiz.co.za).
# How to Change the VNC Password in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-change-the-vnc-password-in-solusvm/
This guide shows you how to change the **VNC password** on a VPS from the SolusVM control panel. The VNC password is the credential that guards the browser console: the virtual screen and keyboard attached directly to your server. It is also the password most often confused with the other two a VPS carries, so the first job is making sure you are about to change the right one.
**A VPS normally has three separate passwords, and changing one does nothing to the other two:**
- **The SolusVM control panel password.** Signs you in to the panel itself. See [How to Change the SolusVM Control Panel Password](/solusvm/how-to-change-the-solusvm-control-panel-password/).
- **The VPS root or administrator password.** Authenticates you to the operating system over SSH or RDP, and at the console login prompt. See [How to Change the VPS OS Root/Admin Password in SolusVM](/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/).
- **The VNC password** (this article). Authenticates the console *connection*, before the operating system has shown you anything at all.
The clearest way to tell which one you need: if you are being asked for a password by a login screen that is drawing your server's own boot messages behind it, that is the operating system, so you need the root password. If you are asked for a password *before* any server screen appears, while the console is still connecting, that is the VNC password and this is the right page.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide documents the SolusVM control panel itself and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation](https://docs.solusvm.com/en/): the vendor documentation set, covering both SolusVM 1 and SolusVM 2.
- [SolusVM 1 Client Area](https://docs.solusvm.com/en/solusvm1/advanced-configuration/client-area/): the panel generation whose virtual server page carries the **VNC Password** section shown in the screenshots below.
- [SolusVM 2 Quick Start Guide: Customers](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/): the newer customer interface, which is laid out differently from the client area described here.
- [RFC 6143 section 7.2.2, VNC Authentication](https://datatracker.ietf.org/doc/html/rfc6143#section-7.2.2): the specification that defines what a VNC password actually is, and the limits this article explains.
- [NIST SP 800-63B, Digital Identity Guidelines](https://pages.nist.gov/800-63-4/sp800-63b.html): the current public standard behind the advice on choosing and rotating passwords.
## Prerequisites
- Access to the SolusVM control panel. The panel address, username and password are in the welcome email sent when the VPS was provisioned. If you cannot reach the login screen, see [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
- A VPS that has a VNC console at all. VNC needs an emulated display adapter, which full virtualisation provides and container virtualisation does not. Check which type you have in [How to Check the RAM of VPS, IP, Disk Capacity and Virtualization Details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
- A window in which the VPS can be restarted. The new password does not apply to a running machine, for reasons explained below.
- The new password decided and saved before you open the form, not invented in the field.
## What a VNC Password Actually Is, and Why It Is Unusual
This is worth two minutes, because a VNC password does not behave like the other passwords you manage, and the differences change how you should choose and handle it.
### Only the First Eight Characters Are Used
VNC authentication is defined in [RFC 6143 section 7.2.2](https://datatracker.ietf.org/doc/html/rfc6143#section-7.2.2). The server sends a random challenge, and the client encrypts it with DES using the password as the key. In the words of the specification, "the password is truncated to eight characters, or padded with null bytes on the right".
The consequences are practical, not academic:
- A twenty-character VNC password is **no stronger** than its first eight characters. Everything after character eight is discarded.
- Two passwords that share their first eight characters are the same password as far as the console is concerned. `Correct1horsebattery` and `Correct1staple` both authenticate against a server expecting either.
- If the field lets you paste in something longer, do not assume the extra length is protecting anything. Equally, a copy and paste that silently truncated at eight characters will still work, which can leave you believing a longer password is in place when it is not.
This puts a VNC password permanently below the fifteen-character single-factor minimum that [NIST SP 800-63B](https://pages.nist.gov/800-63-4/sp800-63b.html) now sets. You cannot fix that by choosing a better password, because the protocol will not carry one. The right response is to stop treating the VNC password as the thing keeping people out, and to lean on the controls that genuinely do: a strong panel login with two-factor authentication in front of it, and an encrypted console session rather than a raw VNC port.
### There Is No Username
VNC authentication has no username field. The password is the entire credential, so anyone who has the string has the console, with no second thing to guess. That is why it should never be shared in a chat message, pasted into a ticket, or reused anywhere else.
### The Console Is Root-Equivalent Regardless of the Operating System Password
People often reason that a leaked VNC password is survivable because the attacker still faces the operating system login. On a typical Linux VPS that reasoning does not hold. Someone at the console can interrupt the bootloader during startup and boot the machine to a root shell without any operating system password at all. This is standard, documented behaviour on physical machines, and the VNC console is the virtual equivalent of standing in front of one.
Treat the VNC password as a root-equivalent credential. If it has ever been shared, reused, written into a ticket or sent over an unencrypted channel, change it, and change the root password too.
### The Session Itself Is Not Encrypted by This Password
The specification is blunt about the scheme: "This type of authentication is known to be cryptographically weak and is not intended for use on untrusted networks." The password authenticates the connection but encrypts nothing afterwards. Screen content and every keystroke, including the root password you type at the login prompt, cross a raw VNC connection in the clear.
This is why the console option to use is the one that wraps the session in TLS, presented in older panels as **HTML5 VNC Client SSL**. Opening the console the right way is covered in [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/).
## Choose the Password Before You Open the Form
Given the eight-character ceiling, the useful rules are narrow but they matter:
- **Use eight random characters.** Generate them with a password manager rather than inventing them. Eight random characters is the most this credential can hold, so there is nothing to gain from a memorable phrase and a great deal to lose.
- **Keep to plain ASCII letters and digits.** Accented characters, symbols outside the basic set, and anything non-Latin can be encoded differently by different VNC clients, which produces an authentication failure that looks exactly like a wrong password. Restricting yourself to `A` to `Z`, `a` to `z` and `0` to `9` removes an entire category of failure for a trivial loss of entropy.
- **Never reuse the panel password or the root password here.** They protect different things and they leak in different ways. Setting all three to the same value means one exposure hands over everything.
- **Store it in your password manager as a distinct entry**, labelled so nobody in your team mistakes it for the root password later. Naming it after the VPS and the word "VNC" is enough.
## Change the VNC Password
### Step 1: Sign in and select the VPS
Log in to the SolusVM control panel. If the account holds more than one VPS, select the one you want to work on. The VNC password is per virtual server, not per account, so changing it on one VPS leaves every other VPS on the account untouched.

### Step 2: Find the VNC Password section
Scroll down the virtual server management page to the **VNC Password** section. It sits alongside the other per-server settings rather than under the account settings, which is the usual reason people cannot find it: they look under **My Account**, where the panel password lives, and conclude the option is missing.
### Step 3: Enter the new password and click Change
Enter the new password in the field and click **Change**. There is no "current password" field to complete, because the panel is setting the value rather than verifying you know the old one. That is another reason panel access is the real security boundary here.

### Step 4: Confirm
Click **Yes** to confirm. The panel reports the change immediately. At this point the new password is recorded in the VPS configuration, but it is **not yet in force**, which is the subject of the next section and the single most common reason people think this procedure has failed.
## Restart the VPS, or the Change Does Nothing
The VNC password is a property of the virtual machine's emulated display, and that display is configured at the moment the virtual machine process starts on the host node. Saving a new password writes it to the configuration for next time. It does not reach into a virtual machine that is already running.
Two things follow, and the second one catches out experienced administrators:
- Until the VPS is restarted, the console continues to accept the **old** password. If you changed it because it may have been exposed, the exposure is still live until the restart happens. Do not close the ticket at step 4.
- **A reboot issued from inside the operating system is not sufficient.** Typing `reboot` over SSH restarts the guest, but the virtual machine process on the host node keeps running throughout, and it keeps the display configuration it started with. The restart has to be issued at the virtualisation layer.
The reliable method is a full power cycle from the panel: [shut the VPS down](/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/), wait until [the status actually reads offline](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/), then [start it again](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/). The panel's [reboot option](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/) is usually enough as well, but a stop followed by a start is the one that always works, and it is worth the extra thirty seconds when the whole point of the exercise is that the old password must stop working.
Shut the operating system down cleanly first if you can. A forced power cycle is the equivalent of pulling the plug, and it risks the same filesystem damage.
## Verify That It Actually Worked
The panel's confirmation message tells you the value was saved, not that it is in effect. Prove it:
1. After the VPS has restarted and shows as online, open the console. See [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/).
2. Enter the **new** password when prompted. The console should connect.
3. Now do the test most people skip. Disconnect, open the console again, and try the **old** password. It must be rejected. If the old password still connects, the virtual machine process was never restarted, and everything you did at step 4 is still pending.
4. Click once inside the console and press **Enter** to confirm you have reached a live machine rather than a stale image.
5. Type `exit` or `logout` before closing the tab if you logged in to the operating system. Closing the browser tab ends the VNC session but leaves the shell logged in on the virtual screen, waiting for whoever opens the console next.
Step 3 is the one that separates a completed change from a change you only believe you made.
## When to Change the VNC Password
[NIST SP 800-63B](https://pages.nist.gov/800-63-4/sp800-63b.html) withdrew the old advice to rotate passwords on a calendar. Change this one when there is a reason, and the reasons are more common than for most credentials because of how consoles get used:
- You gave it to a support engineer, contractor or developer to fix something, and the work is finished.
- It was pasted into a ticket, a chat channel, an email or a shared document, all of which retain it long after the incident.
- Somebody who had it has left the business.
- You connected with a plain VNC client over the internet rather than the encrypted console option.
- You inherited the VPS from someone else and do not know who else holds the password. Change it as part of taking over, along with the panel password and the root password.
Because a VNC password is one of the routine credentials handed out during troubleshooting, rotating it after any support engagement that touched the console is a sensible habit rather than an overreaction.
## If the Panel Does Not Look Like the Screenshots
The layout above is the SolusVM 1 client area. SolusVM 2 presents customers with a different interface, organised around projects and servers, and its console settings are not in the same place. If what you see does not match, work from the [SolusVM 2 customer documentation](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/) instead. Everything on this page about what a VNC password is, the eight-character limit and the restart requirement applies to either version, because those come from the protocol and the virtualisation layer rather than from the panel.
## Troubleshooting
**Symptom: there is no VNC Password section on the page.** Either the VPS uses container virtualisation, which has no emulated display and therefore no VNC console, or VNC is switched off for that server. Check the virtualisation type in [the VPS details](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/), then check the setting itself in [How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/). Some installations also hide the option from client accounts, in which case the administrator who issued the account has to make the change.
**Symptom: the old password still works after the change.** The virtual machine process has not been restarted. A guest reboot does not do it. Perform a full stop and start from the panel, wait for the status to read offline in between, and test again.
**Symptom: the new password is rejected.** Check the obvious first: the console is asking for the VNC password, not the root password, and not the panel password. After that, suspect truncation. If you set a password longer than eight characters, try just its first eight. If it contains symbols or accented characters, set a fresh eight-character alphanumeric password and try again, since character encoding differences between VNC clients produce failures that are indistinguishable from a wrong password.
**Symptom: the console asks for a password you never set.** A VNC password may have been set when the VPS was provisioned, or by whoever administered it before you. You do not need to recover it. Set a new one with the procedure above and restart the VPS.
**Symptom: the console connects without asking for any password.** That is normal in installations where the console is reached through an authenticated panel session, so the panel login is doing the authenticating. It also means your panel password and its second factor are the only things standing between the internet and a console on your server. If two-factor authentication is available on the account, this is the reason to switch it on: see [How to Change the SolusVM Control Panel Password](/solusvm/how-to-change-the-solusvm-control-panel-password/).
**Symptom: the password field will not accept the length you want.** Expected behaviour rather than a fault. Panels commonly cap the field at eight characters to match what the protocol uses. Use eight random alphanumeric characters.
**Symptom: you changed the VNC password because you think someone had console access.** The password is the smallest part of the response. Anyone with console access could have booted the machine to a root shell, added an account or installed an SSH key, none of which a new VNC password removes. Change the [root password](/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/) and the [panel password](/solusvm/how-to-change-the-solusvm-control-panel-password/) as well, then review the user accounts, the authorised SSH keys and the services running on the server.
## Getting Help
If you are unsure which of the three passwords you need, work back through the list at the top of this page, which settles most cases. For anything to do with your Noiz hosting account, the Noiz support team is available through the client area at [www.noiz.co.za](https://www.noiz.co.za). For a control panel issued by another provider, the host node and the console service belong to that provider, so use the support contact given in the welcome email for that service and quote the exact message the console shows.
# How to Change the VPS OS Root/Admin Password in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/
This guide shows you how to change the **root or administrator password of the operating system running inside your VPS**, using the SolusVM control panel. This is the credential that SSH, RDP and the console ask for. It is set from outside the server, through the host, which is why it works even when you have lost access to the machine entirely.
**Read this before you touch the form, because this is where most of the confusion lives.** A VPS managed through SolusVM carries three separate passwords, and changing one has no effect on the other two:
- **The VPS root or administrator password** (this article). Authenticates you to the operating system itself: SSH on Linux, RDP or the console sign-in on Windows. Nothing in the panel uses it.
- **The SolusVM control panel password.** Authenticates you to the panel web interface only. See [How to Change the SolusVM Control Panel Password](/solusvm/how-to-change-the-solusvm-control-panel-password/).
- **The VNC console password.** Authenticates the browser console session that draws the server's screen. See [How to Change the VNC Password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/).
If you are here because you cannot sign in to the panel, this page is the wrong one: you need [the panel password article](/solusvm/how-to-change-the-solusvm-control-panel-password/) instead. If you are here because SSH is rejecting your password, you are in the right place. Never set any two of these three passwords to the same value.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is published by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation](https://docs.solusvm.com/en/): the vendor documentation set, covering both SolusVM 1 and SolusVM 2.
- [Introduction to SolusVM and common notation and glossary](https://docs.solusvm.com/en/solusvm1/introduction/introduction-to-solusvm-and-common-notation-and-glossary/): the vendor's own terminology, including what Master Node, Slave Node and Client actually mean.
- [Change Root Password (SolusVM 1 API reference)](https://docs.solusvm.com/en/solusvm1/api/admin/virtual-server-functions/change-root-password/): the `vserver-rootpassword` action, which is the same operation the button in the client area performs.
- [SolusVM 2 Quick Start Guide: Customers](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/): the newer customer interface, which is laid out differently from the client area shown in the screenshots below.
- [OpenSSH `sshd_config` manual page](https://man.openbsd.org/sshd_config): the authority on `PermitRootLogin` and `PasswordAuthentication`, the two settings that decide whether your new root password is usable over SSH at all.
- [Microsoft `net user` command reference](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/net-user): for changing the Administrator password from inside a Windows VPS once you are back in.
- [NIST SP 800-63B, Digital Identity Guidelines](https://pages.nist.gov/800-63-4/sp800-63b.html): the current public standard behind the password advice on this page.
## Prerequisites
- Access to the SolusVM control panel for the VPS. The panel address and your sign-in details are in the welcome email issued when the service was set up. If you are not sure how to reach the login screen, see [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
- The VPS online, or at least in a state where the panel can reach it. Check first with [How to Check Whether the VPS Status is "online" or "offline" in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/).
- The new password generated and saved *before* you open the form, not invented in the field. The next section explains why that ordering matters more here than it looks.
- A way back in once the password is changed: an SSH client, an RDP client, or the browser console. See [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/) if SSH is not an option.
## What This Password Change Actually Does
The panel does not log in to your server to make this change. It instructs the host that runs your virtual machine to write a new password into the guest operating system's own account database, from the outside. Two things follow from that, and both matter:
- **It works when you are locked out.** You do not need the old password, and you do not need a working SSH service. This is the standard recovery route when the root password has been lost, and it is usually faster and far less destructive than reinstalling the operating system.
- **It is a privileged operation that leaves a trail.** The new value passes through the panel to reach the guest. Treat any password you type into a hosting panel as a password the panel operator could in principle see. That is not a reason to avoid it, but it is a good reason to follow the next section.
Because of the second point, the strongest habit is to use the panel to regain access, then change the password again from inside the operating system with `passwd` on Linux or `net user` on Windows. The panel is your way back in; the in-server change is what sets the password you actually keep.
### Choose the password before you open the form
Root is the account that can do anything on the server, and unlike the panel account there is no second factor protecting it. Two rules cover almost all of the risk:
- **Make it long rather than clever.** [NIST SP 800-63B](https://pages.nist.gov/800-63-4/sp800-63b.html) sets a minimum of 15 characters for a password used on its own as a single factor. A generated passphrase or a random string from a password manager clears that easily, and length beats forced character-class rules by a wide margin.
- **Keep it plain.** This one is specific to control panels. The password travels from the panel through the host to the guest, and passwords containing quotes, backslashes, backticks, semicolons or dollar signs have a long history of being mangled somewhere along that path. The change then reports success while the password that landed on the server is not the one you typed. Stick to letters and digits, and get your strength from length instead. If you want symbols, add them later with `passwd` inside the server, where nothing is relaying the value on your behalf.
Generate it and save it in your password manager *first*, then paste it into the panel. Improvising a password into a form that is about to become the only credential for your server is how people lock themselves out.
## Change the Root/Admin Password in SolusVM
### Step 1: Sign in and select the VPS
Sign in to the SolusVM control panel. If your account holds more than one virtual server, select the correct one first. The panel acts on whichever server is currently selected, and the pages look identical from one server to the next, so this is a genuinely easy mistake to make.

Confirm the hostname or IP address shown on the page matches the server you intend to change before you go any further. If more than one of your servers shares a similar hostname, check the details page first: see [How to Check the RAM of VPS, IP, Disk Capacity and Virtualization Details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
### Step 2: Open the Root/Admin Password tab and enter the new password
Scroll down the server management page to the **Root/Admin Password** tab. The tab carries both names because the same field covers the Linux `root` account and the Windows `Administrator` account, depending on what the server runs.
If a password field is shown, enter the password you prepared and click **Change**. If no field appears, the option is not available for this server, and the section [If the Password Field Is Not There](#no-field) further down explains what to do instead.

### Step 3: Confirm the change
Click **Yes** to confirm. This prompt exists because the operation is not reversible: the panel cannot show you the old password, and it cannot put it back. Once you confirm, the previous root password is gone.

### Step 4: Wait for the success message
The change is not instant. The panel has to pass the instruction to the host and wait for it to be applied inside the guest, so give it a few moments before assuming something has gone wrong. A success message appears when it completes.

Save the new password in your password manager now, replacing the old entry rather than adding a second one. Do not leave it sitting in a text editor, and do not rely on the panel to remember it for you, because it will not show it to you again.
## Verify That It Actually Worked
The success message means the panel accepted the request. It does not prove the password works. Confirm it the only way that settles the question, and do it now while you still have the panel and the console available as a fallback:
1. Open a *new* session: SSH on Linux, RDP on Windows, or the browser console. Do not test in a session that is already open, because an existing session is already authenticated and will keep working regardless.
2. Sign in as `root` or `Administrator` with the new password.
3. On Linux, run `id` and confirm it returns `uid=0(root)`. That tells you both that the password worked and that you are the account you expected to be.
4. If SSH refuses the password, do not assume the change failed. Read the next section first: on a default Linux configuration it is supposed to refuse.
## Why SSH May Still Reject Your New Root Password
This is the single most common outcome that gets reported as a broken password change, and it is not a fault. OpenSSH's own manual page states that the default for `PermitRootLogin` is `prohibit-password`, which disables password and keyboard-interactive authentication for root specifically. Most current Linux images ship with that default in place. The password change worked; SSH is simply declining to accept a password for root, exactly as configured.
You have three ways forward, in order of preference:
- **Use the console instead.** The VNC console attaches to the server's virtual screen rather than to SSH, so it is not bound by `sshd_config` at all. Sign in there as root with the new password, then fix whatever locked you out. See [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/).
- **Sign in as your normal user and escalate.** If the server has an ordinary account with `sudo`, SSH in as that account and use `sudo -i`. This is the intended path on most modern distributions, and it is why root password logins are disabled by default.
- **Change the setting deliberately, if you must.** Setting `PermitRootLogin yes` re-enables password logins for root. It also puts the account every automated scanner on the internet tries first behind a single password. If you do it to recover access, undo it once you are back in and move to key-based authentication instead.
A related trap: if `PasswordAuthentication no` is set, SSH will not accept a password for *any* account, no matter what you change it to. In that configuration the server is key-only, and resetting root's password does nothing for SSH access. Use the console.
## What Else Breaks When Root Changes
Changing the root password is a small action with a long tail. Before you close the panel, think about what else was holding the old value:
- **Anything that logs in as root with a stored password.** Backup jobs, monitoring agents, deployment scripts, file transfer clients with a saved profile, and any control panel installed *inside* the VPS that ties its own root login to the system account. These fail silently and you find out days later.
- **Existing sessions stay open.** A password change does not disconnect anyone who is already signed in. If your reason for changing the password was that someone else may have had access, the change alone achieves very little until those sessions are gone.
- **SSH keys are completely unaffected.** This is the one that matters most in a suspected compromise. Anyone whose public key is in `/root/.ssh/authorized_keys` can still log in as root without a password, before and after your change. Review that file, and the equivalent for every other account on the server, or the password change is theatre.
If the server has been accessed by someone who should not have had access, treat the whole machine as suspect rather than treating the password as the problem. Anyone holding the panel account could also have opened a console session or reinstalled the operating system without ever knowing the root password.
## Harden the Account Once You Are Back In
A recovered root password is a starting position, not a finished job. While you have a working session:
- **Set the password again from inside the server.** Run `passwd` on Linux, or `net user Administrator *` on Windows, so the value you keep is one that never travelled through a panel.
- **Move to SSH keys and turn password authentication off.** Once key access is proven working, set `PasswordAuthentication no` in `sshd_config`. Test the key login in a second terminal *before* you close the first one. Locking yourself out at this step is common, and the console is what saves you when it happens.
- **Secure the panel account too.** The panel can reinstall the operating system, which wipes the disk, without ever needing the root password. A strong panel password and two-factor authentication are therefore part of protecting the server, not a separate concern. See [How to Change the SolusVM Control Panel Password](/solusvm/how-to-change-the-solusvm-control-panel-password/) and [How to Enable or Disable the SolusVM VPS Login Alert](/solusvm/how-to-enable-or-disable-the-solusvm-vps-login-alert/).
- **Do not put the change on a calendar.** [NIST SP 800-63B](https://pages.nist.gov/800-63-4/sp800-63b.html) now states that passwords shall not be required to change periodically, and that a forced change belongs only where there is evidence of compromise. Scheduled rotation pushes people towards shorter, incrementable passwords. Change root when there is a reason: someone left, a device was compromised, the value was shared, or you see a sign-in you cannot account for.
## If the Password Field Is Not There
The **Root/Admin Password** tab does not offer a password field on every server. Whether it appears depends on the virtualisation type your VPS runs on and on how the SolusVM installation has been configured by whoever operates it, because setting a password inside a running guest from the host is not possible in every combination. Check what your server runs using [How to Check the RAM of VPS, IP, Disk Capacity and Virtualization Details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
When the field is absent and you still need to regain access, the options are:
- **The console.** If you can still sign in with any account, or the server offers single-user or recovery boot, the console is the least destructive route. See [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/).
- **A reinstall, which sets a fresh root password as part of the build.** This erases everything on the disk. Take a backup you have verified you can restore before you start. See [How to Reinstall OS Using SolusVM OS-Reinstaller](/solusvm/how-to-reinstall-the-os-on-a-vps-using-the-solusvm-os-reinstaller/), or [How to Manually Install/Reinstall an OS using SolusVM for a Customized Installation](/solusvm/how-to-manually-install-an-os-from-iso-in-solusvm/) if you need control over the installation.
- **Ask the provider who issued the server.** An administrator on the SolusVM installation can reset a root password from the administrator side using the same underlying operation, which the vendor documents as the [`vserver-rootpassword` action](https://docs.solusvm.com/en/solusvm1/api/admin/virtual-server-functions/change-root-password/). The support contact for your service is in your welcome email.
## Troubleshooting
**Symptom: the change reports success, but the new password does not work anywhere, including the console.** Suspect the characters before you suspect the panel. Set it again using letters and digits only, at least 15 characters, with no quotes, backslashes, backticks, semicolons or dollar signs. If a plain password works and a complex one did not, the value was being mangled in transit, not rejected.
**Symptom: SSH rejects the new root password, but the console accepts it.** Working as designed. `PermitRootLogin` defaults to `prohibit-password`, so root cannot authenticate with a password over SSH. See [Why SSH May Still Reject Your New Root Password](#ssh-rejects) above, and prefer signing in as a normal user with `sudo`.
**Symptom: the change fails, times out, or the page returns an error.** Check the server's state first. The panel applies the change through the host, and the request can fail if the server is not in a condition to accept it. Confirm the status with [How to Check Whether the VPS Status is "online" or "offline" in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/), and if it is stuck, a reboot often clears it: see [How to Reboot/Restart VPS in SolusVM](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/). Retry the password change once the server is back online.
**Symptom: the panel password stopped working after you changed root.** These are unrelated credentials and one cannot affect the other. You are almost certainly reaching for the wrong saved entry. See [How to Change the SolusVM Control Panel Password](/solusvm/how-to-change-the-solusvm-control-panel-password/).
**Symptom: the console asks for a password you do not recognise before you even reach the login prompt.** That is the VNC password, which sits in front of the console session and is separate again from both the panel and root passwords. See [How to Change the VNC Password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/).
**Symptom: services on the server started failing shortly after the change.** Something was authenticating as root with the old password. Work through backup jobs, monitoring agents, scheduled scripts and any panel installed inside the VPS, and update the stored credential in each.
**Symptom: the panel does not look like the screenshots at all.** The layout above is the SolusVM 1 client area. SolusVM 2 presents customers with a different interface, organised around projects and servers, and its controls are not in the same places. Check the [SolusVM 2 customer documentation](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/) instead. The three-passwords distinction at the top of this page holds in either version.
## Getting Help
If you are not certain which of the three passwords you need to change, work through the list at the top of this page first, because that resolves most cases before any password is touched. For anything relating to your Noiz hosting account, the Noiz support team is available through the client area at [www.noiz.co.za](https://www.noiz.co.za). For a control panel issued by another provider, use the support contact given in the welcome email for that service.
# How to Check VPS RAM, IP, Disk Capacity, and Virtualization Type in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/
This guide shows you how to read the specifications of a virtual private server from the SolusVM control panel: the memory (RAM) assigned to it, its IP addresses, how much disk capacity it has, and which virtualisation type it runs on. It is written for anyone who has been given a client login to a SolusVM panel and needs to know exactly what their VPS is, either to size a workload, to answer a support question, or to work out why a feature they expected is missing from the menu.
The last of those figures, the virtualisation type, is the one people skip and the one that matters most. It is not a trivia field. It decides whether you can boot an ISO, open a VNC console, load a kernel module, run a custom kernel, or change a disk driver. A great many "this option is not in my panel" questions are answered by that single line, so this guide explains what each type actually means for you rather than just telling you where to find it.
A note on wording, because SolusVM and its documentation use several names for the same things. A **VPS** is called a **virtual server**, a **virtual machine** or a **VS** depending on which screen you are looking at. **Memory** and **RAM** are the same field. **Virtualization** (SolusVM spells it with a z) is the same thing as the virtualisation type or the hypervisor type. Treat these as interchangeable throughout.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is maintained by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [Introduction to SolusVM (SolusVM 1)](https://docs.solusvm.com/en/solusvm1/introduction/): the vendor's own overview and glossary for the SolusVM 1 generation, which is the generation the classic client area belongs to.
- [SolusVM 2 Overview](https://docs.solusvm.com/en/solusvm2/quick-start-guide/overview/): states which virtualisation technologies the current generation supports, namely KVM virtualisation and Virtuozzo or OpenVZ containers.
- [SolusVM 2 Glossary](https://docs.solusvm.com/en/solusvm2/glossary/): the vendor's definitions of compute resource, virtual server, plan and the other terms that appear on the specification screen.
- [Customising the SolusVM Client Area](https://docs.solusvm.com/en/solusvm1/advanced-configuration/client-area/customizing-the-client-area/): confirms that the client area is themeable, which is why the exact position and labelling of the fields below varies from one provider to another.
- [KVM Project FAQ](https://www.linux-kvm.org/page/FAQ): authoritative background on what KVM is, for the virtualisation section below.
- [`systemd-detect-virt` manual page](https://www.freedesktop.org/software/systemd/man/latest/systemd-detect-virt.html): the command used later in this guide to confirm the virtualisation type from inside the VPS.
## Prerequisites
- You can [log in to the SolusVM control panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/). The panel address, your username and your password are in the welcome email you were sent when the VPS was set up; SolusVM is installed per provider, so there is no single universal login URL.
- You know which VPS you are looking at, by hostname or by primary IP address, if more than one is attached to your account.
- Optionally, SSH or console access to the VPS itself. You do not need it to read the panel, but the cross-checking section below uses it, and cross-checking is what turns a number on a screen into something you can trust.
## Open the Right VPS First
SolusVM shows specifications per virtual server, so the first job is making sure you are looking at the one you mean. If your account holds only one VPS, the client area opens straight onto it and there is nothing to choose. If it holds several, pick the one you want from the selector at the top of the client area.

Identify the VPS by its primary IP address rather than by its hostname where you can. The hostname field in SolusVM is a label held in the panel's own database, and it does not have to match the hostname configured inside the operating system, so two VPS entries can easily carry similar or stale names. The primary IP is unique and is what the host node actually routes.
## Read the Specification Panel
Once the correct VPS is selected, its specifications appear underneath the hostname on the main client area screen. This block is generated from the host node, not from anything running inside your VPS, so it reflects what has been allocated to the virtual server rather than what the operating system inside currently believes.

The fields you will normally see, and what each one is really telling you:
### Hostname
The name the panel holds for this VPS. It is used in notification emails, in reverse DNS requests, and as the label in lists. It is not automatically the same as the output of `hostname` inside the server. If the two differ, neither is wrong; they are two separate records. See [changing the hostname in SolusVM](/solusvm/how-to-change-your-vps-hostname-in-solusvm/) for how the panel field is edited, and remember that mail servers and TLS certificates care about the name inside the operating system and about DNS, not about the panel label.
### Main IP address and additional IPs
The main IP address is the one SolusVM treats as the identity of this virtual server. Reverse DNS, console access and the panel's own health checks hang off it. Any further addresses assigned to you are listed separately, often with their netmask and gateway.
The gotcha here catches people every time: on a full virtualisation type such as KVM, an address listed in SolusVM is *allocated* to you, not necessarily *configured* inside the guest. Additional IPv4 and IPv6 addresses usually have to be added to the operating system's own network configuration before anything responds on them. Container types behave differently, because the host injects addresses into the container directly. So if an address appears in the panel but does not answer, the panel is not lying; the guest has simply never been told about it.
### Operating system template
The template the VPS was built or last rebuilt from. Treat it as a record of origin rather than a live reading. If you upgraded the distribution in place, or installed an operating system yourself from an ISO, the panel will still show the template it started from until the VPS is rebuilt through SolusVM. Check the operating system inside the server with `cat /etc/os-release` when it matters.
### Disk capacity
The disk allocation for this virtual server, usually shown as an amount used against a total. On KVM and other full virtualisation types this is the size of the virtual block device presented to the guest. On container types it is a quota applied by the host.
Expect the total here to be slightly larger than what `df -h` reports inside the server, and do not treat that as an error. A virtual disk of a given size loses a little to the partition table, to filesystem metadata, and, on ext4, to the five percent of blocks reserved for the root user by default. A difference of a few percent between the panel and the filesystem is normal and expected.
The real trap is a resize. If the disk allocation is increased, the guest sees a bigger block device but the partition and the filesystem inside it stay exactly the size they were. The extra space does not appear in `df -h` until the partition is grown and the filesystem is extended onto it. That is the single most common "my disk did not grow" report, and the panel figure being right while `df` is unchanged is the clue that it is what happened.
### Memory (RAM)
The memory assigned to the virtual server, again usually shown as used against total. On a full virtualisation type this is a hard allocation: the virtual machine cannot exceed it, and processes are killed by the kernel's out-of-memory handler when it runs out. On a container type your provider may have configured a guaranteed amount plus a burst or vSwap allowance, in which case the panel may show more than one memory figure and the larger one is not a number you should plan capacity against.
Two things surprise people. First, `free -h` inside a KVM guest reports a *total* slightly below the panel figure, because the guest kernel and its virtual firmware reserve some memory before user space ever sees it. Again, a small shortfall is expected, not a fault. Second, a memory change made in the panel is defined when the virtual hardware is created, so it typically needs a full stop and start rather than a reboot issued from inside the operating system. A `reboot` from the shell keeps the same virtual machine running and will not pick up a new memory size; a [reboot performed from the panel](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/) is the safer way to make a hardware change take effect.
### Bandwidth
Traffic used against your allowance for the current period, counted by the host node at the virtual network interface. It will not match an in-guest counter such as `vnstat`, because the host counts traffic that reaches your virtual interface even when the guest firewall drops it. If you are close to an allowance, trust the panel figure, since that is the one your provider bills and shapes against.
### Virtualisation type
Usually a short label such as `KVM`, `OpenVZ`, `Virtuozzo`, `Xen HVM` or `Xen PV`. What it means for you is covered in full in the next section, and it is worth reading before you plan anything on the server.
### Status and node
Some client areas also show whether the VPS is running and, occasionally, which host node it lives on. If the specification block will not load at all, check the running state first: see [checking whether the VPS status is online or offline](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/).
## What the Virtualisation Type Actually Means for You
SolusVM presents every virtual server through the same client area, but the technology underneath differs, and it changes what you are allowed to do. The current SolusVM generation supports KVM virtualisation and Virtuozzo or OpenVZ containers; older SolusVM 1 deployments may additionally be running Xen. The practical split is between *full virtualisation*, where you get your own kernel and virtual hardware, and *containers*, where you share the host's kernel.
| Shown as | What it is | Own kernel? | What that gets you |
| --- | --- | --- | --- |
| `KVM` | Full hardware virtualisation. Your VPS is a virtual machine with virtual firmware, a virtual disk and a virtual network card. | Yes | Boot an ISO, use the VNC console, load kernel modules, run a custom or newer kernel, run non-Linux operating systems, choose disk and network drivers. |
| `OpenVZ` or `Virtuozzo` | Operating-system-level virtualisation. Your VPS is an isolated container running on the host's kernel. | No | Fast, efficient and quick to provision, but no custom kernel, no kernel module loading, no ISO boot and no real VNC console. |
| `Xen HVM` | Full virtualisation on the older Xen hypervisor. Behaves much like KVM. | Yes | Broadly the same freedoms as KVM, with a different set of virtual hardware. |
| `Xen PV` | Paravirtualised Xen. Runs a kernel supplied by the host side rather than a full virtual firmware stack. | Partly | Lighter than HVM, but no ISO boot and limited control over the kernel. |
### If it says KVM (or Xen HVM)
You have the most freedom, and most of the interesting controls in the SolusVM client area exist only for you. That includes the [VNC console](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/), which is a genuine virtual screen and keyboard and therefore works even when networking inside the guest is broken; [installing an operating system yourself from an ISO](/solusvm/how-to-manually-install-an-os-from-iso-in-solusvm/); the [APIC, ACPI, VNC and PAE toggles](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/); and the driver choices for the [network card](/solusvm/how-to-change-the-network-card-to-virtio-intel-pro-or-realtek-in-solusvm/) and the [disk](/solusvm/how-to-change-the-disk-driver-to-virtio-or-ide-in-solusvm/). Because you run your own kernel, you can also load modules, which is what things like WireGuard, TUN/TAP devices, custom netfilter modules and some container runtimes need.
The cost is that memory and disk are hard allocations and there is a small amount of virtualisation overhead. If you change the virtual hardware, including its drivers, the guest has to be fully stopped and started for the change to be applied, and a driver change is one of the few settings that can leave a server unbootable if the guest kernel lacks the driver you switched to. Read the linked driver articles before changing either one on a production server.
### If it says OpenVZ or Virtuozzo
You are in a container, sharing the host's kernel with other containers. It is efficient and it starts and stops almost instantly, but the shared kernel is a hard boundary:
- **You cannot load kernel modules or run your own kernel.** Anything that needs a module the host has not enabled will simply fail, no matter what you install. This is the usual reason a VPN, a firewall feature or a container runtime that works elsewhere refuses to start here.
- **There is no ISO boot and no real console.** A container has no virtual screen, so the VNC and manual installation options either will not appear or will not do anything useful. Reinstalling is done from templates instead, through the [operating system reinstaller](/solusvm/how-to-reinstall-the-os-on-a-vps-using-the-solusvm-os-reinstaller/).
- **Driver and firmware settings do not apply.** There is no virtual network card or virtual disk controller to choose, so those menu entries are absent by design rather than broken.
- **Resource reporting can be odd.** Older container platforms let host-wide values leak into `/proc`, so tools inside the container occasionally report the host's CPU count or memory rather than your limit. Where a container exposes `/proc/user_beancounters`, that file is the authoritative view of your limits and, importantly, of how many times you have hit them.
In exchange, container resources can be more elastic. Disk quota increases usually take effect immediately without you touching the partition table, and burst memory can absorb short spikes. Do not plan capacity against burst figures; plan against the guaranteed amount.
### Why it is worth checking before you buy or build
If a piece of software you intend to run states that it needs a specific kernel version, a kernel module, `/dev/net/tun`, nested virtualisation, or a non-Linux operating system, the virtualisation type is the first thing to check. Finding out after deployment that the server is a container costs a rebuild. Checking one line in the panel costs ten seconds.
## Cross-Check the Figures From Inside the VPS
The panel tells you what has been allocated. These commands tell you what the operating system can actually see. Running both is how you tell a real problem apart from a misunderstanding, and it is the first thing any support engineer will ask you for.
```
# Which virtualisation type does the OS think it is on?
systemd-detect-virt
# Same question, from the CPU's point of view
lscpu | grep -i hypervisor
# Memory the guest kernel can see
free -h
# Disk: allocation, partitions and filesystem usage
lsblk
df -h /
# Addresses actually configured on the interfaces
ip -brief address
```
How to read the results:
- `systemd-detect-virt` prints a single word such as `kvm`, `xen`, `openvz` or `lxc`. If it prints `none` on a machine you know is virtual, you are almost certainly on a container type that hides it, or on a system without systemd; fall back to checking whether `/proc/vz` or `/proc/user_beancounters` exists, which indicates an OpenVZ or Virtuozzo container.
- `lscpu` showing a **Hypervisor vendor** line of `KVM` confirms full virtualisation. Containers show no hypervisor line at all, because there is no hypervisor between you and the host kernel.
- `free -h` should be a little under the panel's memory figure on KVM. Substantially *more* than the panel figure on a container is the host's memory leaking through, not a bonus.
- `lsblk` against `df -h` is the disk resize test. If `lsblk` shows a device larger than the partition and filesystem on it, the allocation grew and the filesystem has not been extended yet.
- `ip -brief address` lists only what is configured. An address present in SolusVM but missing here has not been added to the guest's network configuration.
Record the output alongside a screenshot of the specification block if you are opening a support ticket about a mismatch. The two views together identify the problem immediately; either one on its own rarely does.
## Troubleshooting
- **Symptom: the specification block is empty, stuck loading, or showing zeroes.** The client area pulls these figures live from the host node. If the node cannot be reached, or the VPS record is mid-operation such as a rebuild or a migration, the fields do not populate. Check the running state first, wait for any operation in progress to finish, then reload. If it persists, it is a host-side condition rather than something inside your server.
- **Symptom: the disk was increased but `df -h` shows the old size.** Expected on full virtualisation types. The virtual disk grew; the partition and the filesystem did not. Confirm with `lsblk`, then grow the partition and extend the filesystem, and take a backup before you touch a partition table on a live server.
- **Symptom: the panel shows more memory than `free -h`.** Normal on KVM. The guest kernel and virtual firmware reserve a slice before user space sees it. A gap of a few percent needs no action. A gap of half the allocation does, and usually means the memory change has not been applied yet because the VPS was rebooted from inside instead of being stopped and started from the panel.
- **Symptom: an additional IP address is listed in the panel but does not respond.** On KVM and Xen HVM, allocated is not configured. Add the address, netmask and gateway shown in the panel to the guest's network configuration, then confirm with `ip -brief address`. If the address is configured and still silent, the problem is routing or firewalling rather than allocation.
- **Symptom: VNC, ISO installation or driver options are missing from the client area.** Check the virtualisation type. Those features exist only for full virtualisation. On a container they are absent by design. If the type does say KVM and the options are still missing, your provider has disabled them for client accounts.
- **Symptom: the operating system shown does not match what is installed.** The template field records what the VPS was built from, not what is running now. An in-place distribution upgrade or a manual installation does not update it. `cat /etc/os-release` is authoritative.
- **Symptom: the figures do not match the plan you were quoted.** The panel shows what is assigned to this virtual server right now, which reflects any add-ons, configurable options or later resizes. Compare it against the specification on your invoice rather than against the marketing page, and query the difference with whoever provides the VPS.
- **Symptom: the fields are laid out differently from the screenshots above.** The SolusVM client area is themeable and providers customise it, so labels move and some fields are hidden. The underlying values are the same; look for the memory, disk, bandwidth and virtualisation labels wherever the theme has placed them.
## Getting Help From Noiz
Reading the specification block takes seconds and answers most questions about what a VPS actually is before anyone needs to open a ticket. Where it does not, a little preparation makes the ticket quick to resolve.
If a figure looks wrong, if a resize has not taken effect, or if you are weighing up whether the resources shown are enough for a website, mail service or application you are planning to run, the Noiz support team can go through the numbers with you. Include the memory, disk and virtualisation type from the specification block, plus the output of `free -h`, `df -h /` and `systemd-detect-virt` from inside the server. Those five values together are usually enough to settle it on the first reply. Keep the welcome email for the account to hand as well, since it identifies which panel and which virtual server the figures belong to.
# How to Check Whether Your VPS Is Online or Offline in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/
This guide explains how to find the power status of a VPS in the SolusVM control panel, what an **online** or **offline** status actually tells you, and what to check first when the status is not what you expected. The status field is sometimes called the power state, and some interfaces label the same two values *running* and *stopped*. It is the single most useful piece of information on the panel when a server stops responding, and it is also the most commonly misread, because an online status is not a promise that anything inside the server is working.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation: Quick Start Guide Overview](https://docs.solusvm.com/en/solusvm2/quick-start-guide/overview/), the vendor's description of what SolusVM manages and how virtual servers sit on compute resources
- [SolusVM Documentation: Customers](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/), covering the customer-facing side of the panel, including deploying servers and connecting over the VNC console or SSH
- [SolusVM Documentation: Recovering Inaccessible Servers with Rescue Mode](https://docs.solusvm.com/en/solusvm2/administrator-guide/recovering-inaccessible-servers-with-rescue-mode/), useful background on what happens when a server boots but stays unreachable
## Prerequisites
- Access to the SolusVM control panel. If you are not sure where to sign in, see [how to log in to the SolusVM control panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/), and use the panel address given in the welcome email for the service.
- The hostname or IP address of the VPS you want to check, so that you pick the right one if the account holds more than one server.
## Where the Status Is Shown
The status appears on the main server view of the SolusVM control panel, alongside the other headline details for the server.
1. Log in to the SolusVM control panel.
2. If the account has more than one VPS, select the one you want to check. Match on hostname or IP address rather than position in the list, because the order can change. 
3. Read the **Status** field shown under the VPS hostname, together with the other summary details such as bandwidth usage. A status of **offline** means the virtual machine is powered off. 
The same status is normally mirrored in the billing client area for the service, which is convenient if you do not want to open the panel itself. The panel is the authoritative source: the client area displays a copy of what SolusVM last reported.
## What Online and Offline Actually Mean
SolusVM reports what the host machine sees, not what the operating system inside the VPS is doing. Think of it as the switch on the wall rather than the light bulb.
- **online**: the virtual machine is powered on and the host is running it. CPU time is being scheduled and memory is allocated. That is the whole claim. The status does not know whether the operating system finished booting, whether SSH is listening, whether the web server is up, or whether the disk is full.
- **offline**: the virtual machine is powered off. Nothing inside it is running, no memory is allocated to it, and it will not answer on any port or protocol. A server in this state cannot fix itself, because there is no operating system running to act.
The exact mechanism behind the status depends on the virtualisation type of the server, which you can see alongside the other details covered in [how to check the RAM, IP, disk capacity and virtualisation details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/). On full virtualisation such as KVM the status tracks the virtual machine process on the host. On container virtualisation it tracks whether the container is running. The practical meaning to you is the same in both cases.
Two states are easy to confuse with a simple power-off:
- **Suspended**: a server suspended for a billing or abuse reason will usually read as offline, and attempts to start it will either be refused or the server will stop again straight away. If a server refuses to stay on and nothing has changed inside it, check the account standing before hunting for a technical fault.
- **Stale status**: SolusVM polls the host rather than watching it continuously, so the value on screen can be a short way behind reality, particularly during a reboot. Reload the page before drawing conclusions from a status that has just changed.
## The First Thing to Check
There are only two situations worth separating, and the useful next step is different for each.
### The Status Is Offline
1. **Reload the panel.** If the server was rebooted moments ago, an offline reading may simply be the gap between power off and power on.
2. **Ask whether it was shut down on purpose.** A `shutdown`, `poweroff`, or `halt` command run inside the VPS powers the virtual machine off exactly as intended, and the operating system cannot switch itself back on afterwards. This surprises people who expect a reboot and get a shutdown. Only the panel can start it again. See [how to forcefully or gracefully shut down the VPS in SolusVM](/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/) for how the two shutdown types differ.
3. **Start it.** Follow [how to start or boot your VPS in SolusVM](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/). If it comes online and stays online, the cause was a clean shutdown and there is nothing further to fix.
4. **If it goes offline again within a minute or two**, the server is stopping itself or the host is stopping it. Common causes are a kernel panic during boot, a bootloader broken by a failed kernel update, a filesystem that fails its check and drops to an emergency prompt, or a suspension. This is where you stop guessing and watch the boot.
5. **Watch it boot over the console.** The VNC console attaches to the server's virtual screen, so it shows boot messages, panics, and emergency prompts even when networking never comes up. See [how to access a VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/). Start the server and watch from the first moment: the message that matters usually scrolls past in the first few seconds.
### The Status Is Online but the Server Is Unreachable
This is the more common of the two, and the status has already told you something valuable: the host is fine and the virtual machine is powered on, so the fault is inside the server or in the network path to it. Work through it in this order.
1. **Confirm the address.** Check that the IP address you are connecting to is the one the panel shows for that server. An IP change after a reinstall or a migration is a quiet cause of a server that looks dead from your desk and healthy in the panel.
2. **Do not judge it by ping.** ICMP is routinely blocked by server firewalls and by networks in between, so silence from `ping` is not evidence that a server is down. Test the port you actually need instead: `nc -vz 203.0.113.10 22 curl -I -m 10 http://203.0.113.10/` Replace `203.0.113.10` with the IP address of your own server. A *connection refused* means the server is reachable and something answered to say the port is closed, which is a very different diagnosis from a timeout, where nothing answered at all.
3. **Log in over the VNC console.** VNC does not depend on SSH, on the firewall, or on the server having a working network configuration, so it is the escape hatch that still works when everything else has locked you out.
4. **Check the three things that account for most cases**, once you are on the console: `df -h free -m systemctl status ssh` A full disk is the single most frequent cause of a server that reads online and behaves as though it is dead: services cannot write logs or temporary files, stop accepting connections, and in some cases fail to restart, while the virtual machine itself stays happily powered on. Exhausted memory is the next most frequent, with the kernel out-of-memory killer removing whichever process was largest, often the database or the web server.
5. **Consider a firewall lockout.** If the server became unreachable immediately after a firewall or SSH configuration change, that is almost certainly the cause. Fix it from the console rather than rebooting, because a reboot will not undo a saved rule set.
6. **Check whether your own address has been blocked** by brute-force protection running inside the server. That produces a server which is reachable from everywhere except your office or home connection.
A reboot is a reasonable step once you have looked, and a poor first step before you have looked, because it destroys the evidence of what was wrong. See [how to reboot or restart a VPS in SolusVM](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/) when you are ready to use it.
## How to Verify a Status Change Really Took Effect
Watching only the status field will mislead you after a power action, because the panel and the operating system move at different speeds.
- After a start or a reboot, the status flips to **online** almost at once. That is the host confirming it has powered the virtual machine on. The operating system inside still has to boot, which typically takes anywhere from a few seconds to a couple of minutes depending on the system and its filesystem checks.
- Treat the status as the first checkpoint and a real service test as the second. The server is genuinely back when the port you care about answers, not when the panel turns green.
- Use the bandwidth figure shown next to the status as a corroborating signal. Even an idle server generates a trickle of traffic. If usage has been flat since a particular point in time, that timestamp is a good estimate of when the server actually stopped doing useful work, which is often earlier than when anyone noticed.
## Troubleshooting
- **Symptom: the status says online but nothing responds.** The virtual machine is running, so the problem is inside it. Open the VNC console and check disk space, memory, and whether the service you need is running. Do not reboot before looking.
- **Symptom: the status says offline and starting it does nothing.** Either the start action is failing at the host, or the server powers on and immediately stops again. Watch the attempt on the VNC console to tell the two apart, then contact the support desk for the service with what you saw.
- **Symptom: the server starts, runs for a while, then goes offline on its own.** Something is shutting it down. Look for a scheduled task or an automation running `shutdown`, for a thermal or resource action taken by the host, or for an account suspension that took effect.
- **Symptom: the panel and the client area disagree about the status.** The client area shows a cached copy. Trust the panel, and reload it once before acting.
- **Symptom: the status changed but the server behaves the same as before.** You may be looking at the wrong server. Confirm the hostname and IP address on screen match the machine you are testing, particularly on an account with several servers.
- **Symptom: ping fails but SSH works, or the reverse.** That is normal and expected. ICMP and TCP services are filtered independently, so each protocol has to be tested on its own.
If you need to escalate, gather this first: the exact status shown in SolusVM and the time you read it, the hostname and IP address of the server, what you tried from the console, and the exact error text from your connection attempt. A ticket built from that detail gets a useful answer on the first reply, where "my VPS is down" does not.
# How to Enable or Disable the SolusVM VPS Login Alert
Source: https://docs.noiz.ie/solusvm/how-to-enable-or-disable-the-solusvm-vps-login-alert/
The SolusVM client area can send you an email every time somebody signs in to your account. SolusVM calls this the **Login Alert**, and it is a single checkbox under **My Account**. This guide shows you where that checkbox lives, explains exactly what the alert does and does not cover, and gives you a way to confirm the change actually saved.
You may see the same feature referred to as a login notification, a sign-in alert or an email alert on login. Inside SolusVM the label is **Login Alert**.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is published by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Client Area documentation](https://docs.solusvm.com/en/solusvm1/advanced-configuration/client-area/)
- [Two-factor authentication in the SolusVM Client Area](https://docs.solusvm.com/en/solusvm1/advanced-configuration/client-area/enabling-two-factor-authentication/)
- [SolusVM Client API overview](https://docs.solusvm.com/en/solusvm1/api/client/client-overview/)
- [Introduction to SolusVM, notation and glossary](https://docs.solusvm.com/en/solusvm1/introduction/introduction-to-solusvm-and-common-notation-and-glossary/)
## Prerequisites
- A working sign-in to the SolusVM control panel. See [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
- A mailbox you actually read on the address held against the SolusVM account. If it is stale, fix it first: [How to Change the SolusVM Account Email Address](/solusvm/how-to-change-the-solusvm-account-email-address/).
## Turn the Login Alert On or Off
### Step 1: Sign in to SolusVM
Open your SolusVM control panel address in a browser and sign in with your panel username and password.
### Step 2: Open My Account
In the top navigation bar, click **My Account**.

### Step 3: Toggle the Login Alert checkbox
Under **Account Settings** you will find **Login Alert**. Tick it to receive an email on every sign-in, or clear it to stop those emails. Save the page if SolusVM presents a save or update button, then reload **My Account** and confirm the checkbox is in the state you left it. A setting that silently reverts on reload has not saved.

## What the Login Alert Actually Covers
This is the part that catches people out, so it is worth being precise.
- **It covers the SolusVM panel, not the server.** The alert fires when somebody authenticates to your SolusVM client area account. It has no visibility into the operating system running inside your VPS, so an SSH or RDP session straight into the guest will never generate one of these emails. If you want alerting on operating system logins, that is configured inside the guest itself.
- **It is a detection control, not a prevention control.** The alert does not challenge, delay or block anything. By the time the message lands in your inbox, the session already exists and whoever opened it can act on it.
- **It goes to the SolusVM account address only.** That address is a property of the SolusVM account and is not necessarily the same address as your billing or hosting account. Changing one does not change the other.
- **It is set per account, not per VPS.** If one SolusVM account holds several virtual servers, the alert is about the account sign-in, not about any individual server.
## Why the Alert Is Worth Keeping On
The value of the alert is proportional to what panel access lets somebody do, and in SolusVM that is a lot. A signed-in session can reboot or forcibly shut down the machine, open a VNC console, change the root password, and reinstall the operating system, which destroys the contents of the disk. None of those actions need the guest password.
In other words, the SolusVM panel is a route around every control you configured inside the server. The Login Alert is the tripwire on that route, and it costs you nothing but one email per sign-in.
## When Turning It Off Is Reasonable
There are only two situations where clearing the checkbox is a sensible engineering decision rather than a shortcut:
- **Automation is signing in on a schedule.** A monitoring script that logs into the client area every few minutes will generate an alert every few minutes, and you will stop reading them within a day. Fix the cause rather than the symptom: SolusVM exposes a client API with its own key, and moving the automation onto the API means it is no longer performing interactive sign-ins at all. See the [SolusVM Client API overview](https://docs.solusvm.com/en/solusvm1/api/client/client-overview/).
- **Several people share one login.** Shared credentials make the alert useless, because every message is ambiguous and you can never tell a colleague from an intruder. Again, the right fix is separate accounts rather than a silenced alert.
If neither of those applies, alert fatigue is not a real reason. Once the alert is off you have no way of learning that your panel credentials have been used until something visible breaks, and by then the reinstall may already have run.
## Verify That It Worked
1. Sign out of SolusVM properly using the sign-out control rather than just closing the tab, so the session is genuinely ended.
2. Sign back in.
3. Check the mailbox on the SolusVM account address within a few minutes.
If you enabled the alert, a message should arrive. If you disabled it, nothing should arrive. If the message includes a source IP address, compare it with your own connection so you know what a legitimate alert looks like before you ever have to judge a suspicious one.
## Pair It With Controls That Actually Stop a Login
The alert tells you afterwards. These stop the sign-in in the first place, and are worth doing in this order:
- **Enable two-factor authentication** on the SolusVM account. Even a leaked password is then not enough on its own. SolusVM documents the client-side procedure in [Two-factor authentication in the Client Area](https://docs.solusvm.com/en/solusvm1/advanced-configuration/client-area/enabling-two-factor-authentication/), including the one-time recovery codes, which are shown once and must be stored somewhere you will still be able to reach if your phone is lost.
- **Use a unique panel password** that is not reused anywhere else. See [How to Change the SolusVM Control Panel Password](/solusvm/how-to-change-the-solusvm-control-panel-password/).
- **Treat the VNC password as separate.** It is a distinct credential with distinct reach: see [How to Change the VNC Password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/).
## Troubleshooting
**Symptom: the alert is enabled but no email arrives.** Check the address held against the SolusVM account first, since a typo there sends every alert into nothing. Then check the junk or quarantine folder, because automated notifications from an unfamiliar sender are a classic false positive. Finally check for a mailbox rule or forwarder that is filing or discarding the messages before you see them. Add the sender address to your allowed senders once you have identified it.
**Symptom: alerts keep arriving after you cleared the checkbox.** Reload **My Account** and confirm the checkbox is genuinely clear rather than showing a cached page state. If it has reverted, the save did not take, and a different browser or a fresh session usually settles it.
**Symptom: an alert arrives that you cannot account for.** Treat it as a compromise until proven otherwise, and work in this order so you close the panel route first. Change the SolusVM panel password ([guide](/solusvm/how-to-change-the-solusvm-control-panel-password/)), then the VPS root or administrator password ([guide](/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/)), then the VNC password ([guide](/solusvm/how-to-change-the-vnc-password-in-solusvm/)). After that, review the authentication logs inside the guest operating system, because the panel cannot tell you what happened at that level. Only consider an operating system reinstall ([guide](/solusvm/how-to-reinstall-the-os-on-a-vps-using-the-solusvm-os-reinstaller/)) once you have a verified backup, since the reinstall wipes the disk.
**Symptom: an alert every few minutes.** Something is signing in on a timer. Look for monitoring, uptime checks or a saved browser session refreshing itself, and move that workload onto the client API rather than interactive sign-ins.
**Symptom: there is no Login Alert option under My Account.** The SolusVM client area is customisable by whoever operates the panel, and account settings can be hidden or restyled, so a missing option is usually presentation rather than a missing feature. Confirm you are on the account settings page itself rather than a customised dashboard view, and raise a support ticket if the option is still absent.
## Getting Help
Noiz publishes this guide as part of its VPS and server administration documentation. If you have a question about a service you hold with Noiz, open a ticket from the Noiz client area and the support team will pick it up. Include the SolusVM account address and the approximate time of the sign-in you are asking about, so the request can be actioned without a round trip.
# How to Force or Gracefully Shut Down a VPS in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/
This guide covers stopping a virtual private server (VPS) from the SolusVM control panel, and choosing correctly between the two ways SolusVM can do it: a graceful **Shutdown**, which asks the operating system to close down in an orderly way, and a forced **Power Off**, which stops the virtual machine dead. It is written for anyone holding client-level access to a SolusVM panel. SolusVM refers to a VPS as a *virtual server*; the two terms mean the same thing here.
**Warning:** a forced **Power Off** can corrupt data and, in the worst case, leave the VPS unbootable. Always try **Shutdown** first, and keep **Power Off** for a server that has genuinely stopped responding.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is maintained by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation](https://docs.solusvm.com/), the vendor documentation home.
- [Legacy SolusVM 1 documentation and glossary](https://docs.solusvm.com/en/solusvm1/introduction/), which covers the older client area whose **Shutdown** and **Power Off** controls are shown below.
- [How to configure guest VM shutdown behaviour](https://docs.solusvm.com/en/solusvm2/administrator-guide/how-to-configure-guest-vm-shutdown-behavior/), the administrator-side settings (`ON_SHUTDOWN`, `SHUTDOWN_TIMEOUT`) that decide how long a guest gets to close down when the host itself is shutting down.
- [systemd `systemctl(1)` manual page](https://man7.org/linux/man-pages/man1/systemctl.1.html), the authority on what `poweroff` and its `--force` variants actually do inside a Linux guest.
- [libvirt `virsh` manual](https://libvirt.org/manpages/virsh.html), which documents the underlying distinction between a graceful `shutdown` and a hard `destroy` on KVM hosts.
## Prerequisites
- Client-level access to the SolusVM control panel. The panel address and your login details are in your welcome email. See [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
- A way to start the server again afterwards. Once a VPS is off, SSH is gone, so the SolusVM panel is your only route back in. See [How to Start/Boot Your VPS in SolusVM](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/).
- Optional but strongly advised for a forced power off: console access, so you can watch the server come back up. See [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/).
## Graceful Shutdown and Forced Power Off: What Actually Happens
The two buttons sit next to each other in the panel and look almost identical. They are not. Knowing which one you are about to click is the whole of this article.
### Shutdown, the graceful option
On a KVM virtual server, **Shutdown** sends an ACPI power button event into the guest. It is a polite request, not an instruction. Inside the guest, an ACPI handler catches the event and starts the operating system's normal shutdown sequence: services stop in dependency order, databases flush their buffers and close their files, filesystem journals are committed, the filesystems are unmounted cleanly, and only then does the guest ask the hypervisor to cut the power. On a healthy server this takes somewhere between five seconds and a minute.
The important consequence is that the request can be ignored. If the guest has no ACPI handler running, or a service refuses to stop, the panel will happily report that the request was sent while the VPS carries on running. On container-based virtualisation such as OpenVZ there is no ACPI layer at all; the platform stops the container's processes directly, which is why container shutdowns tend to be faster and more reliable than KVM ones.
### Power Off, the forced option
**Power Off** is the virtual equivalent of pulling the plug out of the wall. The hypervisor terminates the virtual machine immediately. Everything still held in RAM is discarded, and that includes the guest's dirty filesystem cache: writes your applications believe succeeded, but which the kernel had not yet committed to disk.
Journalling filesystems such as ext4 and XFS will normally replay their journal on the next boot and recover without help. That protects the *filesystem's* internal bookkeeping. It does not protect *your* data. A database table halfway through an update, a file halfway through an upload, or a package install halfway through unpacking is still halfway through, and no journal replay will finish the job for you. Databases that were not shut down cleanly may also need to run their own crash recovery on the next start, which can take a long time on a large data set.
**Warning:** use **Power Off** only when the server is genuinely unresponsive and a graceful **Shutdown** has already been tried and has failed. It is a recovery tool, not a faster shutdown.
## Before You Shut Down
- **Confirm you have the right server selected.** SolusVM lists every VPS on the account, and the panel does not ask twice. The hostname beside the selector is usually the only thing distinguishing one from another.
- **Tell anyone who depends on it.** A shutdown drops every connection at once: web, mail, database, SSH and any control panel running on the VPS.
- **Take a backup or snapshot first** if the server holds anything you cannot rebuild, particularly before a forced power off.
- **Know that shutting down is not cancelling.** A powered-off VPS keeps its plan resources, its disk contents and its IP addresses reserved, and it stays billable. Shutting a server down to save money does not work.
- **If you only want the server to come straight back up, reboot instead.** A reboot is a single, supervised operation and avoids the window in which you have a powered-off server and no plan for starting it. See [How to Reboot/Restart VPS in SolusVM](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/).
## How to Gracefully Shut Down a VPS in SolusVM
1. Log in to your SolusVM control panel using the address and credentials from your welcome email.
2. If more than one VPS is attached to the account, select the one you intend to stop. 
3. Click **Shutdown**. 
4. Click **Yes** to confirm. 
5. Wait, then check the status. The panel confirms that the request has been *sent*, which is not the same as the server being off. Refresh the page after thirty seconds or so and confirm the status has changed to `offline`.
If the status is still `online` after two or three minutes, the guest is not acting on the request. Go to the troubleshooting section below rather than clicking **Shutdown** repeatedly, which achieves nothing: each click sends another power button event to an operating system that is already ignoring the first one.
## How to Force a Shutdown with Power Off
Use this only after a graceful shutdown has failed, or when the VPS is unresponsive to the point that waiting has no value.
1. Select the correct VPS, exactly as above. This step matters more here than anywhere else in the panel, because there is no undo and no grace period.
2. Click **Power Off** and confirm. 
3. The status changes to `offline` almost immediately, because nothing inside the guest is being waited for.
When you start the server again, watch the boot over the VNC console rather than assuming it came back. A forced power off is exactly the situation in which a filesystem check runs on boot, and a server sitting at an `fsck` prompt looks identical from outside to a server that is simply slow to come up.
## How to Shut Down from Inside the VPS over SSH
You can also shut the server down from within the guest operating system, which is often cleaner than the panel because you can see what is happening as it happens.
On any modern systemd-based Linux distribution, `poweroff` is an alias for `systemctl poweroff`. It is a **graceful** shutdown, not the equivalent of pulling the power cord, and it is the safest way to stop a server you can still log in to:
```
sudo poweroff
```
Your SSH session will drop partway through as networking stops. A sudden `Connection closed by remote host` is the expected outcome, not an error.
The forced equivalent from inside the guest is `--force` given twice, which tells systemd to power the machine off immediately without stopping any services or unmounting any filesystems:
```
sudo systemctl poweroff --force --force
```
That carries the same corruption risk as the panel's **Power Off**, and there is rarely a good reason to prefer it over simply using the panel. A single `--force` is the middle ground: it skips the normal service shutdown but still syncs and unmounts filesystems.
**Gotcha:** once the server is off, SSH is gone with it. Nothing inside a powered-off VPS runs, so there is no command that will bring it back. Starting it again is a control panel operation, and the SolusVM panel is the only place to do it.
## How to Confirm the VPS Really Powered Off
- **The panel status is the authority.** Refresh the server page and confirm it reads `offline`. See [How to Check Whether the VPS Status is "online" or "offline" in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/).
- **Do not rely on ping.** A server that stops answering ICMP might be off, or might simply be filtering ICMP, or might have lost networking while still running. It tells you nothing definitive.
- **Check the console if in doubt.** Opening the VNC console of a powered-off server shows a blank, unresponsive screen rather than a login prompt. On a server that is merely hung, the console will usually still show its last output.
## Troubleshooting
**Symptom**: you clicked **Shutdown**, the panel confirmed the request, and the status stays `online`. The guest is not acting on the ACPI power button event. On minimal Linux images this is usually because no handler is listening: systemd distributions rely on `systemd-logind`, while older or heavily stripped images need `acpid` installed and enabled. Windows guests can also stall on a prompt asking whether to force running applications to close. Fix: open the VNC console and shut the server down from inside, and install or enable an ACPI handler so the panel button works next time.
**Symptom**: the shutdown eventually completes, but takes several minutes. A service is refusing to stop and systemd is sitting out that unit's stop timeout, ninety seconds each by default, before killing it. Watch the console during shutdown to see which unit is named in the "A stop job is running for..." message, then fix that service rather than reaching for **Power Off**.
**Symptom**: **Shutdown** never works on this server, no matter what is running inside it. ACPI may be switched off for the virtual server itself. On KVM servers SolusVM exposes ACPI as a per-server setting, and with it disabled the graceful shutdown button has nothing to talk to. See [How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/). Changing that setting requires the server to be fully powered off and then started again; it will not take effect on a running server.
**Symptom**: after a forced power off, the server boots into a filesystem check or comes up with a read-only root filesystem. The journal replay found damage it could not repair unattended. Connect over VNC, because SSH will usually be unavailable in this state, and run the check the console prompts for. Do not force another reboot out of it, which tends to make matters worse.
**Symptom**: a database or application will not start after a forced power off, and its log mentions recovery, a corrupt table or a stale lock file. This is the expected consequence of the write cache being discarded. Let any automatic crash recovery finish before intervening, and restore from backup if it cannot complete.
**Symptom**: the VPS shut down on its own, without anyone clicking anything. If the host itself was being shut down or rebooted for maintenance, the platform asks every guest on it to shut down gracefully and waits only a fixed period before stopping them regardless. That window is an administrator setting, not a client one, and is documented as `SHUTDOWN_TIMEOUT` in the guest shutdown behaviour reference linked above. A guest that is slow to close down can therefore be cut off mid-shutdown during host maintenance.
## Related SolusVM Guides
- [How to Start/Boot Your VPS in SolusVM](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/), the other half of this operation and the only way back from a powered-off server.
- [How to Reboot/Restart VPS in SolusVM](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/), for when the server should come straight back up.
- [How to Check Whether the VPS Status is "online" or "offline" in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/).
- [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/), for watching a boot or rescuing a server with no working SSH.
- [How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/), if graceful shutdowns never work on a KVM server.
- [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
Noiz maintains this guide as part of its hosting knowledgebase. If you are a Noiz client and a server is not behaving the way this article describes, open a ticket from the Noiz client area with the server name and the time of the shutdown, and the support team will take a look.
# How to Log in to the SolusVM Control Panel
Source: https://docs.noiz.ie/solusvm/how-to-log-in-to-the-solusvm-control-panel/
SolusVM (Solus Virtual Manager) is a browser-based VPS management system that lets the owner of a virtual server start it, stop it, rebuild it and inspect it without any access to the physical host behind it. This guide covers the part every VPS owner meets first: the client area login. It explains where the address, username and password come from, how to sign in, what two-factor authentication changes about the login screen, and how to work out what has gone wrong when the login fails. The client area is also called the SolusVM control panel, the VPS control panel, or simply "the panel", and all of those names refer to the same screen. It is the starting point for every other SolusVM guide in this knowledgebase.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is maintained by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation: Introduction to SolusVM and Common Notation & Glossary](https://docs.solusvm.com/en/solusvm1/introduction/introduction-to-solusvm-and-common-notation-and-glossary/), the vendor's definition of the product and of terms such as master node, slave node and template
- [SolusVM Documentation: Two-Factor Authentication in the Client Area](https://docs.solusvm.com/en/solusvm1/advanced-configuration/client-area/enabling-two-factor-authentication/), the authoritative procedure for enabling, disabling and recovering 2FA on a client account
- [SolusVM Documentation: Quick Start Guide for Customers](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/), the equivalent workflow in SolusVM 2, whose login screen differs from the one described here
- [SolusVM Documentation: clearauthlog.php](https://docs.solusvm.com/en/solusvm1/advanced-configuration/command-line/clearauthlog.php/), for administrators, the utility that clears the record of access attempts held in the authentication log
## Prerequisites
- Your VPS welcome email, which carries the control panel address, your username and your initial password. Nothing on the panel itself will tell you the address if you have lost it.
- A current web browser with cookies and JavaScript enabled.
- Your authenticator app or a saved recovery code, if two-factor authentication has been enabled on the account.
## Where Your Login Details Come From
SolusVM does not send its own welcome message. The control panel address, username and password are issued by whoever provisioned the VPS, normally in the welcome email sent when the server was set up. If that email has been deleted, ask the provider that supplied the VPS to reissue the details; there is no self-service recovery from the login screen for a lost panel address.
A typical set of details looks like the example below. Replace every value with the ones from your own welcome email.
- **Control panel URL**: `https://cp.example.com`, or an address in the form `https://198.51.100.10` if the provider publishes an IP address rather than a hostname.
- **Username**: `vmuser123`, or a name-based login such as `johndoe`.
- **Password**: the value quoted in the welcome email, which should be changed after the first login.
Three separate sets of credentials exist around any VPS, and confusing them is the single most common cause of a failed login:
- **The SolusVM client area login**, described in this guide. It controls the virtual server from the outside: power state, reinstall, console, hardware settings.
- **The VPS operating system login**, normally `root` on Linux or `Administrator` on Windows. This is used over SSH, RDP or the console, and it is never the same credential as the panel login.
- **The billing account login**, held with the company that sold the VPS. Billing systems can be configured to hand off into SolusVM, which is why the two are easily mixed up, but the passwords are stored separately and changing one does not change the other.
## How to Log In to the Client Area
1. Open the control panel URL from your welcome email in a browser. Type or paste the address exactly as given, including `https://`.
2. Enter your SolusVM username and password. The username is a panel username, not an email address, on the classic client area shown below.
3. Click **Login**. You are taken to the SolusVM VPS management area, which lists the virtual servers attached to your account.

If two-factor authentication is enabled on the account, a second screen appears after the password is accepted and asks for a six-digit code. See the section on two-factor authentication below.
Once you are in, the landing screen is a list rather than a single server. An account can hold several virtual servers, so the first click after login is choosing which server to manage.
## Which SolusVM You Are Logging In To
There are two generations of the product in the field, and they do not share a login screen. Identify yours before following any SolusVM guide, because the terminology and menus differ:
- **SolusVM 1 client area**: you log in with a *username* and password at the address the provider published, commonly a `cp.` hostname or an IP address. This is the screen in the screenshot above, and it is the version this guide and its companion articles describe. The vendor now publishes the SolusVM 1 material as legacy documentation.
- **SolusVM 2**: you log in with your *email address* and password at a `/login` path on the management server, in the form `https://cp.example.com/login`. SolusVM 2 organises servers into projects and, where the provider allows it, supports self-registration and an email confirmation link.
If the login form asks for an email address and the interface talks about projects, you are on SolusVM 2 and should follow the vendor's customer quick start guide linked above rather than the SolusVM 1 steps in this knowledgebase.
## Two-Factor Authentication at the Login Screen
Two-factor authentication (2FA) adds a time-based one-time code, generated by a phone app such as Google Authenticator or Microsoft Authenticator, on top of the password. With it enabled, a stolen password on its own is not enough to reach the panel, which matters more than usual here: the SolusVM client area can reinstall the operating system and wipe the disk, so it deserves stronger protection than an ordinary web login.
Points worth knowing before you switch it on:
- 2FA is off by default, and the account holder turns it on from **My Account** inside the client area. It does not need a request to the provider. The vendor documents client area 2FA as available from SolusVM version 1.30.01 upwards, so an older installation may not offer the setting at all.
- Enabling it produces eight one-time recovery codes, shown once. Save them somewhere that is not the phone holding the authenticator app, because that phone is exactly what you will have lost when you need them.
- Each recovery code works once. Generating a fresh set immediately invalidates every unused code from the previous set.
- 2FA settings do not survive an import into SolusVM 2. If the provider migrates the account, enable 2FA again on the new panel.
- If both the app and the recovery codes are gone, only the administrator of the SolusVM installation can clear 2FA from the account. There is no self-service route back in.
## What a SolusVM Login Does Not Give You
The client area is deliberately narrow in scope, and knowing its limits saves a lot of fruitless clicking:
- **It is not a shell on the server.** Logging in to SolusVM does not log you in to the operating system. Managing files, services or websites still needs SSH, RDP or a console session.
- **It is not the administrator panel.** SolusVM's admin interface, which manages nodes, IP blocks and other people's servers, is a separate application on the master node and belongs to the provider. A client area account cannot reach it.
- **It is not a billing panel.** Renewals, invoices and plan changes live in the billing system, not here.
- **Changing your panel password changes nothing inside the VPS.** The client area password and the operating system root password are independent, and each has its own procedure.
## Confirm You Are on the Right Server Before You Act
If the account holds more than one virtual server, the safest habit is to verify the server identity before using any control that interrupts service. Open the server's details and check that the main IP address and hostname match the server you intended to work on, then check its power state. Rebooting or reinstalling the wrong entry in the list is an easy and expensive mistake, and SolusVM asks for very little confirmation before carrying out either instruction.
## Where to Go Next
Once you are logged in, these guides cover the tasks the client area is normally opened for:
- [Check whether the VPS status is online or offline](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/), the first thing to look at when a site or service stops responding.
- [Check the RAM, IP address, disk capacity and virtualisation type](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/), which also confirms you are looking at the right server.
- [Change the SolusVM control panel password](/solusvm/how-to-change-the-solusvm-control-panel-password/), which should be done as soon as you have logged in with the password from the welcome email.
- [Enable or disable the VPS login alert](/solusvm/how-to-enable-or-disable-the-solusvm-vps-login-alert/), so that a successful login sends you a notification.
- [Change the account email address](/solusvm/how-to-change-the-solusvm-account-email-address/), which is where alerts and panel notifications are delivered.
- [Reboot or restart the VPS](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/), and [access the VPS console over VNC](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/) when the network is unreachable but the server is running.
- [Change the VPS operating system root or administrator password](/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/), the credential that the panel password is often mistaken for.
## Troubleshooting
- **The username and password are rejected**: check that you are using the panel credentials from the welcome email rather than the billing account or the server's root password. Type the password by hand once instead of pasting it, since a copied value often carries a trailing space, and confirm Caps Lock is off. On the SolusVM 1 client area the login field takes a username, so an email address will always fail.
- **"Incorrect two-factor authentication code" although the code looks right**: time-based codes fail when clocks drift. Check that automatic time is enabled on the phone, then try the next code rather than the one about to expire. If every code is refused, the clock on the management server itself may be out of sync, which only the administrator can correct, so use a recovery code and report it.
- **The phone is lost and the recovery codes are gone**: contact the administrator of the SolusVM installation. Recovery codes cannot be reissued from the login screen, and support cannot read the existing ones.
- **The browser warns that the connection is not private**: this is common when the panel is reached by IP address, because the certificate is issued for the hostname instead. Use the hostname form of the address from the welcome email. Never enter panel credentials on a page you reached from a link in an unexpected email; open the address from your own records instead.
- **The login page loads but the Login button does nothing**: cookies or JavaScript are blocked. Try a private browsing window with extensions disabled, then re-enable them one at a time to find the offender.
- **The panel address does not load at all**: this is a fault on the management server rather than on the VPS, and the two are separate machines. The virtual server itself can be running perfectly while the panel is unreachable, so test the server's own services before assuming an outage.
- **You cannot tell whether your attempts are arriving**: SolusVM records access attempts in an authentication log on the master node. The administrator can confirm whether the failed logins reached the panel, which quickly separates a wrong password from a network or DNS problem.
- **The bookmark stopped working**: bookmark the login page, not the page you land on afterwards. Internal panel URLs carry session information and expire.
If you are locked out, only the administrator of the SolusVM installation can reset a client area password or clear two-factor authentication, so use the support channel given in your VPS welcome email. If you are not sure who administers your server, open a support ticket with the Noiz support team, quoting the hostname or IP address of the VPS and the exact wording of the error shown at the login screen.
# How to Manually Install an OS from ISO in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-manually-install-an-os-from-iso-in-solusvm/
This guide shows you how to install an operating system on a VPS by hand in SolusVM: mounting an installation ISO to the server's virtual CD-ROM drive, telling the virtual machine to boot from it, and then driving the installer yourself through the VNC console. SolusVM is a virtualisation management panel that gives VPS customers direct control over their own virtual machines, including the virtual hardware settings this procedure depends on. People describe this task in several ways: a manual OS install, a custom install, installing from ISO, mounting a CD-ROM image, or a clean reinstall with custom partitions. They all mean the same thing, and this is the procedure.
The reason to do it this way rather than using the panel's automated reinstaller is control. The automated reinstaller lays a prepared template onto the disk with a partition layout the template author chose. A manual install puts the operating system's own installer in front of you, so you decide the partitioning, the filesystem, the packages and the settings. That control is the whole point, and it is also the whole cost: nothing is done for you, and every mistake is yours to make.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is published by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below. SolusVM's client interface has been reworked between major versions, so a control may be worded or positioned differently in your copy; the sequence and the underlying behaviour described here hold across releases.
### Official Documentation Reference
- [SolusVM Documentation (home)](https://docs.solusvm.com/en/): the vendor's documentation hub. If a control in your panel is worded differently from the one described here, search this site for the current wording.
- [Quick Start Guide: Customers (SolusVM)](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/): the vendor's walkthrough of the customer side of the panel, including the ways you can connect to a server once it is running.
- [Recovering Inaccessible Servers with Rescue Mode (SolusVM)](https://docs.solusvm.com/en/solusvm2/administrator-guide/recovering-inaccessible-servers-with-rescue-mode/): worth reading before you start. If a manual install leaves the server unbootable, rescue mode is the path back in, and it is the route your provider would take.
- [SolusVM Release Notes](https://docs.solusvm.com/en/release-notes/): the authoritative record of what changed in each release, useful when a control has moved or been renamed since a screenshot was taken.
## Warning: This Destroys Everything on the Disk
Installing an operating system from ISO overwrites the VPS disk. Every file, database, mailbox, certificate, configuration file, cron job and log on that server is gone, and there is no undo, no confirmation screen after the fact, and no way to recover from the panel. Treat this as the deliberate destruction of the server's contents, because that is exactly what it is.
Before you go any further:
- **Copy your data off the VPS entirely.** A backup that lives on the same disk is not a backup for this purpose. Move it to your own machine or to separate storage, and confirm the copy is complete and readable there.
- **Record the network settings.** Write down the primary IP address, the netmask or prefix, the gateway and any additional IPs assigned to the server. You will very likely need to type them into the installer by hand, and once the disk is wiped there is nowhere left to look them up except the panel and your welcome email.
- **Record anything else you cannot rebuild from memory.** Firewall rules, DNS records pointing at the server, SSH keys, application licence keys and the exact versions of software you were running.
- **Check you actually need a manual install.** If you simply want a clean, standard operating system, the automated reinstaller is faster, safer and needs no console work. See [How to Reinstall OS Using SolusVM OS-Reinstaller](/solusvm/how-to-reinstall-the-os-on-a-vps-using-the-solusvm-os-reinstaller/).
## Prerequisites
- Access to the SolusVM control panel address, username and password issued when the VPS was set up. These arrive in your welcome email; do not guess the panel address. If you are not signed in yet, start with [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
- A VPS running full virtualisation, such as KVM or Xen HVM. See the section below on why this matters.
- Familiarity with the VNC console, since the entire installation happens there and not over SSH. See [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/).
- A block of uninterrupted time. A manual install over a console is not a two-minute job, and abandoning it half way leaves the server with no working operating system at all.
- Your own copy of the data on that server, verified readable. This bears repeating.
## Manual Install Only Works on Full Virtualisation
This is the first thing to check, and it saves a lot of confusion when the controls described here are simply not present in your panel.
A full virtual machine, such as a KVM or Xen HVM guest, emulates a complete computer: virtual firmware, a boot device order, a virtual CD-ROM drive and a virtual screen. Because all of that exists, you can hand it an ISO image, tell it to boot from the CD-ROM first, and watch the installer on the screen exactly as you would on a physical machine.
A container-style VPS, such as an OpenVZ or LXC guest, has none of that. It shares the host's kernel and has no firmware, no boot order, no CD-ROM and no screen. There is nothing to boot an ISO with, which is why the **Boot Order**, **CDRom** and **VNC** controls either do not appear or do nothing on a container VPS. On that virtualisation type your only option is the panel's template-based reinstaller, and no amount of hunting through the interface will change that.
If you are unsure which type you have, the panel shows the virtualisation alongside the RAM, disk and IP details: see [How to Check the RAM of VPS, IP, Disk Capacity and Virtualization Details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
## Step 1: Sign In and Select the Right VPS
Open the SolusVM control panel using the address in your welcome email and sign in with the panel credentials issued for the VPS. These are the control panel credentials, which are entirely separate from the root or administrator password of the operating system inside the VPS.
If your account holds more than one virtual server, select the one you intend to reinstall. Check the hostname or the primary IP address shown alongside the entry rather than its position in the list, because the ordering changes as servers are added and removed. Selecting the wrong server here means wiping the wrong server later, and nothing in the steps that follow will warn you.

## Step 2: Set the Boot Order to CD-ROM First
Scroll down to the **Settings** tab and change the boot order to **(1) CDROM (2) Hard Disk**.

This tells the virtual firmware which device to try first when the machine powers on. With CD-ROM first, a mounted ISO takes priority and the installer starts; if no ISO is mounted, the firmware falls through to the hard disk and the server boots normally.
Two things about this setting catch people out. It is **persistent, not one-shot**: it stays as you set it until you change it back, so every subsequent reboot will keep trying the CD-ROM first. And it takes effect at the **next power cycle**, not immediately, so changing it while the server is running does nothing until the server reboots.
## Step 3: Mount the Installation ISO
Choose **CDRom**. If an image is already mounted, click **Unmount** first, then select the operating system you want from the list and click **Mount**.

The list contains the ISO images your provider has loaded onto the host machine. You are choosing from that library rather than uploading your own image, so if the operating system or the exact version you want is missing, that is a request to your provider rather than something you can fix in the panel.
Pay attention to which variant you are picking, because it changes how the installation behaves:
- A **minimal** or **netinst** image contains only the installer and downloads the packages it needs during installation. It boots quickly, but it will not get past package selection unless networking is configured correctly inside the installer.
- A **full** or **DVD** image carries the packages with it and can install without any network access at all. It is the safer choice if you are not certain the network settings will work first time.
- A **live** image boots into a working desktop or shell rather than straight into an installer, and you have to start the installer from inside it. On a console-only VPS this is usually the harder path.
- The **architecture** must match the virtual machine. A 64-bit guest runs a 32-bit installer, but a 32-bit guest cannot run a 64-bit one and will simply refuse to boot the image.
## Step 4: Reboot the VPS
Click **Reboot** and confirm with **Yes**. This is the power cycle that makes the new boot order take effect, so the machine comes back up looking at the CD-ROM first and finds your mounted ISO.

If the server is currently powered off rather than running, use **Boot** instead: the effect is the same, and the relevant details are in [How to Start/Boot Your VPS in SolusVM](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/).
## Step 5: Open the VNC Console Immediately
As soon as you have confirmed the reboot, click **VNC** without waiting.

The urgency is not arbitrary. Most installation media show a boot menu or a "press any key to boot from CD" prompt that waits only a few seconds before timing out. Miss that window and the firmware gives up on the CD-ROM, falls through to the hard disk, and either boots the old operating system or stalls on an empty disk. Neither is a failure you need to fix: just reboot again from the panel with the VNC window already open and waiting.
Understand what VNC is here, because it changes how you work. It attaches to the virtual machine's screen and keyboard, in the same way a monitor and keyboard plug into a physical server. It does not depend on the guest having a network connection, an operating system, or anything at all installed, which is precisely why it is the only way to drive an installer. It also means there is no copy and paste and no file transfer in most builds: whatever you need typed, you type.
## Step 6: Connect With the Console Client
The VNC page opens and offers a client. Choose **HTML5 VNC Client SSL**.

The HTML5 client runs in the browser with no plugin and is the option to use. Older SolusVM builds also offer a **Java VNC Client**, which is a Java applet: current browsers removed the plugin support that applets rely on years ago, so on a modern machine it usually will not run at all. If you do end up on a system where it still works, accept the security warnings and click **Run**.

One console habit worth adopting before you start typing anything important: the console sends raw key codes to the virtual machine, and the installer decides what layout those codes mean. If your physical keyboard is not a US layout, symbols such as `@`, `#`, `/` and `"` can arrive as something else entirely. This bites hardest when you set the root password, because the installer hides what you type and you will not discover the problem until the first login fails. Set the keyboard layout early in the installer if it offers one, and if in doubt choose a password of plain letters and digits for now and change it to something stronger over SSH once the server is up.
## Step 7: Start the Installer
Most installation media pause at a boot prompt or a menu. Press any key when prompted, then choose the install entry rather than a media check or a live session, and press **Enter**.

The menu wording varies by operating system, but the pattern is consistent: an install entry, a test or check entry, a rescue or troubleshooting entry, and sometimes a graphical and a text install. On a VPS console the text or basic graphical option is usually the better choice, because it is far more responsive over VNC and never depends on a display driver the virtual hardware does not have. If the graphical installer starts and the screen is unreadable or frozen, reboot and take the text option instead.
## Step 8: Work Through the Installer
From here you are in the operating system's own installer, and its screens are documented by whoever wrote it. What follows is the part specific to doing it on a VPS over a console, which is where the real problems live.
### Partitioning
This is the reason you chose a manual install, so it deserves thought. A few points that matter more on a VPS than on a physical machine:
- **Simple layouts age better.** A single root partition plus a small swap area is the layout that causes the fewest problems later. Elaborate schemes with separate partitions for every directory look tidy on day one and become a nuisance the first time one of them fills up while the others sit empty.
- **Think about growing later.** If you expect the disk to be enlarged in future, LVM makes the in-guest half of that job considerably easier. Note that enlarging a VPS disk is always two jobs: your provider grows the virtual disk, and then you grow the partition and filesystem from inside the guest. Nothing about a disk upgrade happens automatically.
- **Separate `/var` only with a reason.** Logs and databases live there and it is the partition that fills. If you split it off, size it generously, because a full `/var` stops mail, databases and logging.
- **Swap on a VPS is a judgement call.** A small swap area gives the kernel somewhere to go under memory pressure instead of killing processes outright. A large one on slow storage just makes a struggling server unresponsive rather than failed.
- **Disk encryption needs a passphrase at every boot,** typed into the console by hand, every time. On a remote server with no automatic unlock configured, that means the machine will not come back from a reboot on its own. Choose it deliberately or not at all.
### Networking
This is the most common way a manual install goes wrong, and it is entirely avoidable. Many VPS networks do not hand out addresses by DHCP, so an installer that is left on automatic configuration will sit there failing to find a network. Have the IP address, netmask or prefix, gateway and a pair of resolver addresses in front of you, and enter them by hand when the installer asks. The address details are visible in the panel, covered in [How to Check the RAM of VPS, IP, Disk Capacity and Virtualization Details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/), and in the details you were sent when the server was provisioned.
If you are using a minimal or netinst image, getting this right is not optional: the installer cannot fetch its packages without it.
### Passwords and Remote Access
Set a root or administrator password you can actually retype at a console, subject to the keyboard-layout caution above. Then make sure remote access will exist after the reboot: a minimal Linux install does not always include an SSH server, and even when it does the service is not always enabled to start at boot. If the installer offers an SSH server as a package option, take it. Reinstalling because you locked yourself out of a freshly installed server is a particularly annoying way to spend an afternoon, even though the VNC console will still let you back in to fix it.
Note also that after a custom manual install, the panel's own root password reset feature may no longer work on that server. That feature generally relies on the guest matching the layout of a provider template, so an unusual partition scheme, LVM or full-disk encryption can put the disk beyond its reach. Plan on managing the root password from inside the server from now on, and treat [the panel's password reset](/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/) as a convenience that may or may not still apply.
### Hostname
Set the hostname during the install, and keep it consistent with the hostname recorded in the panel. A mismatch is not fatal, but it makes mail delivery, monitoring and log correlation quietly awkward. The panel-side value is covered in [How to Change Hostname in SolusVM](/solusvm/how-to-change-your-vps-hostname-in-solusvm/).
## Step 9: Set the Boot Order Back to Hard Disk First
This is the step people skip, and skipping it produces a server that appears to have failed its installation when in fact it installed perfectly.
When the installer finishes, it reboots the virtual machine. If the boot order is still CD-ROM first and the ISO is still mounted, the machine boots the installer again, and you find yourself staring at the same welcome screen you started from. Nothing is broken; the machine is doing exactly what you told it to do.
So once the installation completes:
1. Return to the **Settings** tab and set the boot order back to **(1) Hard Disk (2) CD Drive**.
2. Go to **CDRom** and click **Unmount** so no image is attached. Setting the boot order back is enough on its own, but unmounting removes any chance of the same trap catching you at the next reboot, months from now, when you have long forgotten this was ever done.
3. Reboot the VPS.
The server should now come up on its newly installed operating system.
## How to Confirm the Install Actually Worked
Check these in order, because each tests something the previous one does not:
1. **The console shows a login prompt.** Watch the reboot in VNC. A login prompt from the new operating system means the bootloader and kernel are working and the machine is booting from disk, not from the ISO.
2. **The panel status reads `online`.** This confirms the virtual hardware is powered on, and nothing more. See [How to Check Whether the VPS Status is "online" or "offline" in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/).
3. **The server answers on the network.** Ping the primary IP from your own machine. A reply proves the kernel is up and the network settings you typed into the installer are correct. Some networks filter ICMP, so silence here is suggestive rather than conclusive.
4. **Remote access works.** Connect over SSH, or RDP for a Windows guest. This is the test that matters, because it proves you no longer depend on the console.
5. **Reboot once, deliberately.** Reboot the VPS from the panel and confirm it comes back on its own without the console. This catches a boot order left on CD-ROM, a bootloader written to the wrong device, and services that were started by hand but never enabled at boot. Finding any of those now is far cheaper than finding them during an unplanned outage six months from now.
## Troubleshooting
- **Symptom**: there is no **CDRom**, **Boot Order** or **VNC** option in the panel. The VPS is almost certainly a container-style guest with no virtual CD-ROM or firmware to boot one from. Use the template-based reinstaller instead: [How to Reinstall OS Using SolusVM OS-Reinstaller](/solusvm/how-to-reinstall-the-os-on-a-vps-using-the-solusvm-os-reinstaller/).
- **Symptom**: the VPS boots the old operating system instead of the installer. Either the ISO is not mounted, the boot order was not changed, or the boot order change was made after the reboot rather than before it. Confirm both settings, then reboot again. Remember that a boot order change only applies from the next power cycle.
- **Symptom**: the boot prompt appears and then vanishes before you can press anything. You reached the console too late. Reboot from the panel with the VNC window already open and focused, and press a key as soon as the prompt appears.
- **Symptom**: the VNC console is black or blank. Give it a few seconds, since the screen only refreshes when the guest draws to it. If it stays black, close and reopen the session. If it still stays black after a reboot, check that VNC is enabled for the server, covered in [How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/), and that the VNC password is what you think it is, per [How to Change the VNC Password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/).
- **Symptom**: the installer starts but reports that it cannot find any disk to install to. The virtual disk is presented with a driver the installation media has no driver for. Virtio is the usual culprit, particularly with older or Windows installation images, which ship no Virtio driver by default. Switch the disk driver to IDE for the installation using [How to Change the Disk Driver to Virtio or IDE in SolusVM](/solusvm/how-to-change-the-disk-driver-to-virtio-or-ide-in-solusvm/), then reboot and start again.
- **Symptom**: the installer finds the disk but no network interface. Same problem, different device. Change the network card model using [How to Change the Network Card to Virtio, Intel PRO, or Realtek in SolusVM](/solusvm/how-to-change-the-network-card-to-virtio-intel-pro-or-realtek-in-solusvm/). Intel PRO or Realtek are recognised by almost every installer without extra drivers, while Virtio needs support that older media may not have.
- **Symptom**: the installer will not boot at all, or panics immediately. Check the image architecture against the guest first. After that, the ACPI, APIC and PAE toggles are the usual cause: older and 32-bit operating systems can refuse to start when these do not match what they expect. They are covered in [How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/).
- **Symptom**: the install finished, but rebooting lands back in the installer. The boot order is still CD-ROM first, the ISO is still mounted, or both. Set it back to hard disk first, unmount the image, and reboot. The install itself is fine.
- **Symptom**: the install finished and the machine now says there is no bootable device. The bootloader was not written, or was written to a device the firmware does not boot from. This happens most often with unusual partition layouts, or when the installer was pointed at a partition rather than the whole disk. Boot the ISO again, choose the installer's rescue or repair mode, and reinstall the bootloader to the disk itself.
- **Symptom**: the operating system installed but nothing responds on the network, while the console shows a healthy login prompt. The network settings entered during installation are wrong, or the interface was not brought up at boot. Log in at the VNC console, since that session does not need the network, and correct the address, netmask, gateway and resolver configuration from there. Compare them against the values shown in the panel.
- **Symptom**: the console keyboard types the wrong characters, or the root password you set will not work. Almost always a keyboard layout mismatch between your machine and the guest. Log in at the console and reset the password using only unambiguous characters, then set the layout inside the operating system before choosing anything more complex.
## After the Install
A freshly installed server has none of the hardening or configuration the previous one accumulated, so treat the first hour as part of the job rather than as optional tidying. Apply all available updates before the server does anything useful, since an image on a host library can be months old and the gap between its packages and current ones is exactly where the known vulnerabilities sit. Configure the firewall before you expose any service. Set up your SSH keys and consider disabling password authentication once key access is proven to work. Enable every service you depend on to start at boot, then reboot once to prove it does. And put a backup routine in place immediately, because the empty state of a fresh install is the one moment when the absence of backups costs nothing and is therefore easiest to overlook.
If a manual install leaves a VPS unbootable and the troubleshooting above has not got you back in, gather the detail before escalating: the exact wording on the console, the ISO you mounted, the boot order and driver settings, and the point in the installation where it went wrong. Those details separate a fault inside the guest from a problem with the virtual hardware underneath it, and they save a round of questions. If you are a Noiz client and you are unsure how to read what the console is telling you, open a support ticket with the Noiz support team and they will help you interpret it.
# How to Reboot or Restart a VPS in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/
This guide explains how to restart a VPS from the SolusVM control panel and from inside the operating system over SSH, and, more importantly, how to choose between the two ways a virtual machine can be restarted. A restart is sometimes called a reboot, a power cycle, or a reset, and those words are not interchangeable: one of them shuts the operating system down properly first, and one of them does not. Getting that choice wrong is the single most common way people turn a slow VPS into a broken one. This article is for anyone with access to a VPS managed through SolusVM, whether that is an end user in the client area or an administrator working on a customer's virtual server.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is maintained by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation: Introduction to SolusVM, Common Notation and Glossary](https://docs.solusvm.com/en/solusvm1/introduction/introduction-to-solusvm-and-common-notation-and-glossary/), the entry point for the legacy SolusVM 1 documentation set that the classic client area belongs to
- [SolusVM Documentation: Customers Quick Start Guide](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/), the customer-side workflow in the newer SolusVM interface, including how servers are created and connected to
- [SolusVM Documentation: Glossary](https://docs.solusvm.com/en/solusvm2/glossary/glossary/), the official definitions of terms such as compute resource, management node, and virtual server
- [SolusVM Documentation: Recovering Inaccessible Servers with Rescue Mode](https://docs.solusvm.com/en/solusvm2/administrator-guide/recovering-inaccessible-servers-with-rescue-mode/), for the administrator-side recovery path when a virtual server will not boot at all
- [Linux manual page: `shutdown(8)`](https://man7.org/linux/man-pages/man8/shutdown.8.html), the authoritative reference for the command-line method described below
- [systemd manual: `systemctl`](https://www.freedesktop.org/software/systemd/man/latest/systemctl.html), covering `systemctl reboot` and the related power state commands on systemd-based Linux distributions
## Prerequisites
- Access to [log in to the SolusVM control panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/). The address you log in at is given in the welcome email for your VPS.
- For the command-line method, an SSH client and root or `sudo` access on the VPS itself.
- A rough idea of what the VPS is currently doing. A restart during a package upgrade, a database import, or an OS reinstall is far riskier than a restart on an idle server.
## Graceful Restart Versus Forced Reset
SolusVM can restart a virtual server in two fundamentally different ways, and the panel does not always make the difference obvious. Understanding what each one does at the hypervisor level is the whole point of this article.
### What a graceful restart actually does
A graceful restart asks the operating system to shut itself down, then brings it back up. On a KVM or Xen HVM virtual server, SolusVM signals the guest with an ACPI power event, which is the virtual equivalent of briefly pressing the power button on a physical machine. The guest sees that event and runs its normal shutdown sequence:
- Running services are told to stop, so databases close their tables, web servers finish or abandon in-flight requests, and mail queues are written to disk rather than left in memory.
- Filesystem write buffers are flushed to disk. Linux does not write every change to disk immediately, so this step is what turns "the application thinks it saved the file" into "the file is actually on the disk".
- Filesystems are unmounted cleanly and marked clean, so the next boot does not need to repair them.
- Only then does the machine reset and boot again.
This is the correct choice in almost every situation, including applying a kernel update, clearing a memory leak, or recovering a server that is sluggish but still responding.
The catch is that a graceful restart depends on the guest actually hearing and acting on the request. It will silently do nothing if ACPI is disabled for the virtual server, if the guest has no software listening for power events, or if the operating system is so badly hung that it cannot respond. Modern Linux distributions using systemd handle ACPI power events natively; older systems rely on the `acpid` daemon being installed and running. If your graceful restarts never take effect, check the [ACPI setting for the virtual server in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/) before assuming the panel is broken.
Container-based virtual servers such as OpenVZ work differently. There is no BIOS or ACPI layer inside a container, so the host stops and restarts the container's init process directly. The practical effect is the same, and it is still the graceful path.
### What a forced reset actually does
A forced reset, also described as a hard reset or a power cycle, cuts virtual power to the machine and starts it again. Nothing inside the guest is consulted. It is the exact equivalent of pulling the plug out of the wall on a physical server. Because none of the shutdown sequence runs, everything that sequence protects is at risk:
- **Unwritten data is lost.** Anything sitting in a write buffer when the power is cut never reaches the disk. Files that an application reported as saved seconds earlier can come back empty or truncated.
- **Filesystems are left dirty.** Journalling filesystems such as ext4 and XFS will usually replay their journal and recover, but a dirty filesystem can also trigger a full `fsck` at the next boot, which on a large disk can take a long time and, on a serious inconsistency, will stop and wait for a human answer at the console.
- **Databases have to run crash recovery.** InnoDB tables in MySQL or MariaDB normally survive this, at the cost of a slower start. MyISAM tables frequently do not and need repairing by hand.
- **Interrupted package operations leave the OS half-configured.** A reset in the middle of an `apt` or `dnf` transaction can leave packages unpacked but not configured, which on Debian and Ubuntu is what produces the familiar `dpkg --configure -a` recovery step.
- **An interrupted OS reinstall is usually unrecoverable.** If SolusVM is part-way through writing a fresh operating system to the disk, a forced reset leaves nothing bootable behind and the reinstall has to be started again from scratch.
A forced reset is a last resort, not a faster alternative. It is justified when the operating system is genuinely hung, ignores a graceful restart, and cannot be reached over SSH or the console. It is not justified because a graceful restart is taking a couple of minutes.
### Choosing between them
Work down this list and stop at the first option that works:
1. Restart from inside the operating system over SSH. This is the most graceful path available, because the OS is running its own shutdown rather than reacting to an external signal.
2. If SSH is unreachable, use **Reboot** in the SolusVM control panel. This is still a graceful restart.
3. If the panel reports the restart as sent but the server never goes down, open the console to see what it is stuck on. The [VNC console in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/) shows boot and shutdown messages that SSH cannot, including a stalled service or an `fsck` prompt waiting for input.
4. Only then force the machine down and start it again. That is a [forced shutdown in SolusVM](/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/) followed by a [boot of the VPS](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/).
If the panel offers snapshots or backups for your virtual server, take one before a forced reset. It costs a few minutes and it is the only thing that makes filesystem damage reversible.
## How to Restart a VPS from the SolusVM Control Panel
Use this method when the operating system is unresponsive over SSH, or when you simply prefer the panel. The classic SolusVM client area labels this control **Reboot**; newer SolusVM interfaces label the same action **Restart** in the server's power controls. Both send a graceful restart request.
1. Log in to your SolusVM control panel using the address in your VPS welcome email.
2. If your account holds more than one virtual server, select the one you want to restart. Check the hostname and main IP address before going any further, because nothing in the confirmation step tells you which server you picked. 
3. Click **Reboot**. 
4. Choose **Yes** to confirm. SolusVM queues the request and passes it to the host node that runs the virtual server. 
5. Wait. The panel confirms that the request was sent, not that the server has finished restarting. A small Linux VPS is typically back within a minute or two; a server with a large filesystem, many services, or a slow-stopping database can take considerably longer.
Two things worth knowing about the panel's behaviour here. First, the status SolusVM reports is the power state of the virtual machine on the host node, not the readiness of the software inside it. A virtual server can show as [online in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/) while the operating system is still working through its boot sequence and refusing SSH connections. Second, every click queues another task. Clicking **Reboot** repeatedly because nothing appears to be happening can interrupt a filesystem check that is part-way through repairing a disk, which turns a recoverable problem into a much worse one.
## How to Restart a VPS from the Command Line
Restarting from inside the operating system is the cleanest option available, because the OS initiates and controls its own shutdown rather than reacting to a signal from outside. Use it whenever SSH still works.
1. Connect to the VPS with your SSH client as root, or as a user with `sudo` rights.
2. Run the restart command: `shutdown -r now` On systemd-based distributions, `systemctl reboot` does the same job and is the more modern form. Both need root privileges, so prefix with `sudo` if you are not logged in as root.
Your SSH session will drop the moment the shutdown starts. That is expected and is not a sign of a problem.
If other people use the server, give them warning rather than restarting underneath them:
```
shutdown -r +5 "Restarting for scheduled maintenance"
```
That schedules the restart five minutes out and broadcasts the message to logged-in users. If you change your mind, cancel it before the timer expires:
```
shutdown -c
```
One caveat that catches people out: a command-line restart is only as graceful as the operating system's ability to complete it. If a service refuses to stop, or a network filesystem mount has hung, the shutdown can stall part-way through and leave the server neither properly up nor properly down. At that point SSH is already gone and the panel is your only remaining route, which is exactly the situation the console is for.
One more thing that is specific to virtualisation. On KVM and Xen HVM virtual servers, a restart loads whatever kernel the guest has installed, so a restart is how a kernel update takes effect. On container-based virtual servers such as OpenVZ, the kernel belongs to the host node and is shared, so restarting the container will never give you a different kernel no matter how many kernel packages you install inside it.
## How to Confirm the Restart Actually Happened
"It seems to be working again" is not confirmation. Once SSH accepts connections, check three things:
1. Confirm the machine really restarted, rather than the network briefly dropping: `uptime -p who -b` `uptime -p` prints how long the system has been running, and `who -b` prints the timestamp of the last boot. Both should reflect the restart you just performed.
2. Confirm nothing failed to start. On systemd distributions: `systemctl list-units --failed` An empty list is what you want.
3. Confirm the services you actually depend on came back, for example your web server, database, and mail service: `systemctl status nginx systemctl status mariadb` Substitute the service names your server uses.
This last check is worth more than it looks. A service that was started by hand and never enabled will run perfectly until the first restart, then quietly fail to come back. That is the real reason a great many sites go down "after a reboot". Where a service should always start at boot, make it explicit:
```
systemctl is-enabled nginx
systemctl enable nginx
```
The first command reports whether the service is set to start automatically; the second sets it. Doing this once, on a working server, saves an outage later.
## Troubleshooting
- **You clicked Reboot and nothing happened at all**: the guest is not acting on the restart request. Check that ACPI is enabled for the virtual server in SolusVM, and, on an older Linux distribution, that `acpid` is installed and running. If both are correct, the operating system is likely hung and will need a forced shutdown followed by a boot.
- **The VPS has not come back after 5 to 10 minutes**: open the VNC console before doing anything else. The console shows the boot messages that SSH cannot, and the cause is usually visible there: a filesystem check in progress, a service blocking the boot, a prompt waiting for input, or a bootloader that cannot find a kernel. Forcing another reset without looking first risks interrupting a repair that would have finished on its own.
- **The panel shows the VPS as online but SSH refuses to connect**: the virtual machine is powered on but the operating system is not finished booting, or the SSH service did not start. Give it a few more minutes, then use the console to log in locally and check `systemctl status sshd`. A full disk is a common cause of services failing to start after a restart, so check with `df -h` while you are there.
- **Everything came back except one website or database**: the service behind it is almost certainly not enabled at boot. Check with `systemctl list-units --failed` and `systemctl is-enabled` for the service in question, then enable it so the next restart is clean.
- **The server boots into a filesystem repair prompt**: this is the normal aftermath of a forced reset. Answer the prompt at the console rather than resetting again. If the repair reports data loss, restore the affected files from your most recent backup.
- **MySQL or MariaDB will not start after a forced reset**: check the database error log for crash recovery messages. InnoDB usually recovers on its own; MyISAM tables often need repairing explicitly. Restore from backup if recovery cannot complete.
- **You restarted while an OS reinstall was running**: the disk is very unlikely to hold a usable system. Start the reinstall again rather than trying to repair the result.
If a restart leaves your VPS unreachable and the panel controls are not recovering it, escalate to the team that runs the SolusVM master server for your VPS, whose contact details are in your VPS welcome email. Noiz clients can open a support ticket with the Noiz support team; include the VPS hostname and main IP address, the time the restart was issued, whether it was a graceful restart or a forced reset, and anything visible on the VNC console.
# How to Reinstall the OS on a VPS Using the SolusVM OS Reinstaller
Source: https://docs.noiz.ie/solusvm/how-to-reinstall-the-os-on-a-vps-using-the-solusvm-os-reinstaller/
This guide explains how to reinstall the operating system on a VPS from the SolusVM control panel, what a reinstall actually does at the disk level, and the checks that separate a clean rebuild from a lost weekend. The same action is described in different places as a reinstall, a rebuild, an OS reinstall, or a reimage, and they all mean the same thing: SolusVM discards what is currently on the virtual server's disk and writes a fresh operating system template in its place. This article is for anyone with access to a VPS managed through SolusVM, whether that is an end user in the client area or an administrator working on a customer's virtual server.
**Warning: a reinstall destroys everything on the virtual server.** Websites, databases, mailboxes and stored mail, user accounts, SSH keys, cron jobs, TLS certificates and their private keys, firewall rules, application data, and any installed software are all erased. Nothing is moved to a recycle bin and there is no undo button in the panel. **Take a full backup, copy it off the virtual server, and confirm you can read it back before you start.** If you cannot answer the question "where exactly is my backup and have I opened it?", you are not ready to reinstall.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is maintained by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation: Customers Quick Start Guide](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/), the customer-side workflow in the newer SolusVM interface, including how servers are created and connected to
- [SolusVM Documentation: Glossary](https://docs.solusvm.com/en/solusvm2/glossary/glossary/), the official definitions of terms such as OS image, compute resource, and virtual server
- [SolusVM Documentation: Custom Templates](https://docs.solusvm.com/en/solusvm1/custom-templates/), what an operating system template is and how the list you choose from is built
- [SolusVM Documentation: Single Partition Templates](https://docs.solusvm.com/en/solusvm1/custom-templates/kvm-templates/single-partition-templates/), the reason a freshly reinstalled disk sometimes appears smaller than the plan allows
- [SolusVM Documentation: Automated Backups for VPS](https://docs.solusvm.com/en/solusvm1/backups/automated-backups-vps/), the provider-side backup mechanism in the classic interface
- [SolusVM Documentation: Backing Up and Restoring Servers](https://docs.solusvm.com/en/solusvm2/administrator-guide/backing-up-and-restoring-servers/), the equivalent in the newer interface, including what a provider-side backup does and does not cover
- [SolusVM Documentation: Rebuild Virtual Server (API)](https://docs.solusvm.com/en/solusvm1/api/admin/virtual-server-functions/rebuild-virtual-server/), the API call behind the panel button, useful if you need to script a rebuild
- [Linux manual page: `ssh-keygen(1)`](https://man7.org/linux/man-pages/man1/ssh-keygen.1.html), the authoritative reference for clearing the stale host key your SSH client will complain about afterwards
## Prerequisites
- Access to [log in to the SolusVM control panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/). The address you log in at is given in the welcome email for your VPS.
- A verified, off-server backup of everything you intend to keep. This is not optional and it is covered in detail below.
- A note of the virtual server's hostname and main IP address, so you can be certain which server you are about to wipe.
- A password manager or other secure place to store the new root password that SolusVM displays once and does not display again.
- A maintenance window. Everything the server hosts is offline from the moment the reinstall starts until you have rebuilt and restored it, which is almost always longer than the reinstall itself.
## What a Reinstall Actually Does
Understanding the mechanism removes most of the surprises. SolusVM does not repair, upgrade, or reset your operating system. It throws the current disk contents away and lays down a prepared operating system template in their place, then generates a new administrator password and hands it to you.
### What is destroyed
Assume the entire filesystem is gone, because it is. In practice the losses people underestimate are:
- **Configuration you forgot you changed.** Web server virtual hosts, PHP settings, mail routing, `sudoers` entries, systemd unit overrides, and everything else under `/etc`.
- **Credentials and keys.** Authorised SSH public keys, private keys used to reach other servers, API tokens in application configuration files, and TLS private keys. A certificate without its private key is useless, so exporting only the certificate is a common and painful mistake.
- **Scheduled work.** User and system crontabs, systemd timers, and the scripts they call.
- **Mail that only exists on the server.** Mailboxes held locally, plus anything sitting in the mail queue.
- **Installed control panel software.** A licence tied to the IP address may well survive, because the IP does not change, but the software and everything it managed is gone and has to be installed again from scratch.
If the virtual server has more than one disk attached, do not assume the extra one is safe. Treat every disk attached to the server as at risk and back it up too.
### What survives
The virtual server itself is not deleted, so the container around the operating system stays intact:
- The virtual server keeps its IP addresses, so your DNS records and reverse DNS remain valid and there is nothing to update at the registrar or DNS provider.
- The plan resources stay the same. CPU, memory, disk allocation, and bandwidth limits are properties of the virtual server, not of the operating system on it. You can confirm them afterwards by [checking the RAM, IP, disk capacity and virtualisation details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
- The hostname recorded in SolusVM is kept, and most templates apply it to the new system during the first boot. Check it once the server is up and [change the hostname in SolusVM](/solusvm/how-to-change-your-vps-hostname-in-solusvm/) if it did not take.
- Your SolusVM login is unaffected. Reinstalling the operating system has nothing to do with the panel account you signed in with.
One important consequence of the IP addresses surviving: if the server had additional IP addresses beyond the main one, the fresh operating system is usually configured with the main IP only. The extra addresses are still assigned to the virtual server in SolusVM, but you will often have to add them to the new system's network configuration by hand before they respond.
### How it differs by virtualisation type
The end result is the same, but the timing and the mechanics are not. On container-based virtual servers such as OpenVZ, the host destroys the container's filesystem and extracts a fresh template into it, which is usually quick because it is a file-level operation. On full virtualisation such as KVM and Xen HVM, the host writes a disk image over the virtual disk, which is a block-level operation and takes longer on larger disks. SolusVM reports that the installation can take up to 10 minutes; a small container is often finished in well under that, and a large virtual disk can take longer.
The rule that matters in both cases is the same: **do not interrupt a reinstall.** A [reboot](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/) or a forced power cycle part-way through leaves a disk that is neither the old system nor the new one, and nothing bootable on it. The recovery from that is to start the reinstall again, so clicking the power controls out of impatience only costs you more time.
## Back Up Before You Start
A reinstall is the one panel action where a missing backup is unrecoverable. Provider-side backups or snapshots may exist for your virtual server, but do not rely on an assumption. Confirm what exists, how old it is, and how it would be restored, before you wipe anything.
### What to capture
Work through this list rather than trusting memory:
- Website files and application code, including anything outside the obvious web root.
- Database dumps, taken with the database's own tooling rather than by copying its data directory while it is running. A file-level copy of a live database is frequently unusable.
- Mail data, if mail is hosted on this server.
- The whole of `/etc`, or at minimum the configuration for every service you run.
- Crontabs for every user, not just root.
- TLS certificates *and* their private keys, along with any certificate authority account data.
- Authorised SSH keys, and a list of which users had access.
- A written note of installed packages and versions, so the rebuilt server can be brought back to a known state.
### Verify the backup before you wipe anything
Copy the backup off the virtual server, to your own machine or to separate storage. A backup stored on the disk you are about to erase is not a backup. Then actually open it: list the contents of the archive, and check that the database dump ends in a complete statement rather than being truncated. Restoring is the only real test, but reading the archive catches the majority of failures, and those failures are common. Backup scripts that have been silently failing for months are one of the most frequent causes of data loss during an otherwise routine reinstall.
One further caution if you are reinstalling because the server was compromised. A clean operating system does not help if you restore the attacker's foothold along with your data. Restore only content you have inspected, rebuild configuration by hand rather than copying it back wholesale, and rotate every credential the server held, including passwords and API keys used by applications on it.
## Choosing an Operating System
The list of operating systems you can pick from is not a list of everything that exists. It is the set of templates or images made available for your virtual server by whoever runs the SolusVM master server, filtered by the virtualisation type. That has two practical consequences.
First, template lists tend to accumulate. Old entries are often left in place long after the distribution behind them has reached end of life, and an end-of-life release receives no security updates at all. CentOS 8, the example used in older versions of this guide, is a case in point: it [reached end of life at the end of 2021](https://www.centos.org/centos-linux-eol/). Check the current support status of a distribution release with its own vendor before selecting it, rather than picking the entry you recognise.
Second, if the operating system or the exact release you need is not in the list, or you need a custom partitioning scheme, encrypted storage, or a specific installer option, a template reinstall cannot give you that. That is what a manual installation is for: see [how to manually install or reinstall an OS using SolusVM for a customised installation](/solusvm/how-to-manually-install-an-os-from-iso-in-solusvm/), which boots the virtual server from installation media and lets you drive the installer yourself over the console.
## How to Reinstall the OS in SolusVM
The classic SolusVM client area presents this as a **Reinstall** control on the virtual server. Newer SolusVM interfaces present the same operation as a reinstall or rebuild in the server's management screen, with an OS image chooser instead of a template list. The sequence below follows the classic client area.
1. Log in to your SolusVM control panel using the address in your VPS welcome email.
2. If your account holds more than one virtual server, select the one you want to reinstall. Check the hostname and main IP address now, and check them carefully. Nothing later in this process tells you which server you picked, and the confirmation prompt looks identical whichever one it is. 
3. Click **Reinstall**. 
4. Select the operating system you want installed. Only the templates available for this virtual server's virtualisation type are shown. 
5. Scroll to the bottom of the page and click **Reinstall**. A confirmation box appears. This is the last point at which stopping costs you nothing. Choose **Yes** to proceed. 
6. SolusVM reports that the installation can take up to 10 minutes and displays the generated administrator or root password for the new system. **Copy that password into a password manager now.** It is shown once. If you lose it you are not locked out permanently, because you can [change the VPS OS root or admin password in SolusVM](/solusvm/how-to-change-the-vps-os-rootadmin-password-in-solusvm/), but that is an avoidable extra step.
7. Wait for the reinstall to finish without touching the power controls. If you want to watch progress, use the [VNC console in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/), which shows the installer and boot output that SSH cannot.
A note on what the panel status means afterwards. Once the virtual server shows as [online in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/), that reports the power state of the machine on the host, not the readiness of the operating system inside it. A freshly installed system commonly spends its first boot generating host keys, expanding filesystems, and starting services, and will refuse SSH connections while it does. Give it a few minutes before concluding something went wrong. If the server never boots at all, it can be [started from the panel](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/).
## After the Reinstall
### Clear the old SSH host key
This trips up almost everyone, and it looks far more alarming than it is. The new operating system generated brand new SSH host keys, but your SSH client still remembers the old ones for that IP address and hostname. On connecting you will get a block of warning text beginning:
```
WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!
```
That warning exists to flag interception, so never dismiss it blindly. In this specific case, immediately after a reinstall you performed yourself, the change is expected. Remove the stale entry from your own machine's known hosts file and connect again:
```
ssh-keygen -R 203.0.113.10
ssh-keygen -R server.yourdomain.com
```
Replace `203.0.113.10` and `server.yourdomain.com` with your own IP address and hostname; both are examples. Run the command for each name you use to reach the server, because the entries are stored per address. If you connect through a jump host or a shared workstation, the same clean-up is needed there too.
### Verify what was actually installed
Do not assume the template gave you what its label promised. Log in over SSH, or over the VNC console if SSH is not answering, and confirm the basics:
```
cat /etc/os-release
df -h
lsblk
ip -4 addr
```
Each of these answers a specific question. `cat /etc/os-release` confirms the distribution and release that actually landed, which occasionally differs from the template name. `df -h` shows whether the root filesystem is the size your plan allows. `lsblk` shows the whole disk, so if `df` reports less space than you pay for, this reveals the unallocated remainder. That mismatch is a known consequence of template partition layout: templates built around a single partition expand to fill the disk cleanly, while multi-partition templates frequently do not, which is why the [single partition template documentation](https://docs.solusvm.com/en/solusvm1/custom-templates/kvm-templates/single-partition-templates/) exists. `ip -4 addr` confirms which IP addresses the new system has configured, and is where you will notice that additional IPs need adding by hand.
### Secure the fresh system before restoring anything
A newly installed server is at its most exposed in its first hour: it is reachable on a public IP, running whatever the template shipped with, with a password that was displayed in a browser window. Work through this before you put data back on it.
1. Change the root password to one of your own, rather than keeping the generated one. You can do this from inside the operating system with `passwd`, or from the panel.
2. Apply all available updates. Templates are built at a point in time and are frequently months behind on security patches: `apt update && apt upgrade` on Debian and Ubuntu, or: `dnf upgrade` on Fedora, Rocky Linux, AlmaLinux, and related distributions.
3. Install your SSH public keys, then disable password authentication for SSH once key access is confirmed working. Confirm it works in a second session before closing the one you already have, so that a mistake does not lock you out.
4. Configure the firewall. The template's default rules are a starting point, not a policy, and they rarely match the services you are about to run.
5. Restore your data and configuration, then enable every service you depend on so that it starts at boot. A service started by hand and never enabled will work perfectly until the first restart, then quietly fail to come back: `systemctl is-enabled nginx systemctl enable nginx` Substitute the service names your server actually uses.
6. Set up backups again. The reinstall removed the backup agent, scripts, and schedules along with everything else, and a server with no backup is exactly how the last emergency started.
## Troubleshooting
- **There is no Reinstall option, or it is greyed out**: client-side reinstall can be disabled for a virtual server by whoever administers the SolusVM master server, and the control is also unavailable while the server is suspended or already running a task. Check with the provider named in your VPS welcome email.
- **The reinstall has been running far longer than 10 minutes**: open the VNC console before doing anything else. The console shows the installer output, and the cause is usually visible there. Do not power cycle the virtual server to "restart" the process, because interrupting a disk write leaves nothing bootable behind.
- **The panel shows the VPS as online but SSH refuses to connect**: first boot tasks may still be running, so wait a few minutes. If it persists, log in over the VNC console and check that the SSH service is running and that the firewall is not blocking your source address.
- **SSH reports that the remote host identification has changed**: this is expected after a reinstall. Clear the stale host key with `ssh-keygen -R` as described above.
- **The root password shown after the reinstall is not accepted**: it was most likely mis-copied, since generated passwords mix similar-looking characters. Reset it from the panel rather than guessing, then log in with the new value.
- **The wrong operating system was installed**: templates are occasionally labelled inaccurately. Confirm with `cat /etc/os-release`, then either reinstall selecting a different template or perform a manual installation from installation media, which puts you in control of exactly what is installed.
- **The disk is smaller than the plan allows**: check `lsblk` against `df -h`. If there is unallocated space, the template's partition layout did not expand to fill the disk. Growing the partition and filesystem is possible, but on a fresh install it is usually simpler and safer to reinstall from a template built for a single partition, if one is offered.
- **Additional IP addresses do not respond**: they are still assigned to the virtual server, but the new operating system was configured with the main IP only. Add them to the network configuration inside the server.
- **Your website and databases are gone and you have no backup**: a template reinstall overwrites the disk, so there is nothing on the virtual server to recover. Ask whoever runs the SolusVM master server whether a provider-side backup or snapshot exists from before the reinstall. That is the only remaining possibility.
If a reinstall leaves your VPS unreachable and the panel controls are not recovering it, escalate to the team that runs the SolusVM master server for your VPS, whose contact details are in your VPS welcome email. Noiz clients can open a support ticket with the Noiz support team; include the VPS hostname and main IP address, the operating system template you selected, the time the reinstall was started, and anything visible on the VNC console.
# How to Start or Boot Your VPS in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-start-or-boot-your-vps-in-solusvm/
This guide shows you how to power a virtual private server back on from the SolusVM control panel, and, just as importantly, how to tell whether the boot actually worked. SolusVM is a virtualisation management panel used by hosting providers to hand VPS customers direct control over their own virtual machines, so that powering a server on does not require a support ticket. People describe this task in several ways: starting the VPS, booting it, powering it on, or bringing it back up after it went offline. In SolusVM they are all the same single action, and the button that performs it is usually labelled **Boot**. Depending on the SolusVM release and the theme your provider uses, the same control may instead read **Start** or appear as a power icon; the behaviour underneath is identical.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is published by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below. SolusVM's client interface has been reworked between major versions, so a label or an icon may sit differently in your copy; the sequence and the underlying behaviour described here hold across releases.
### Official Documentation Reference
- [SolusVM Documentation (home)](https://docs.solusvm.com/en/): the vendor's documentation hub. If a control in your panel is worded differently from the one described here, search this site for the current wording.
- [Quick Start Guide: Customers (SolusVM)](https://docs.solusvm.com/en/solusvm2/quick-start-guide/customers/): the vendor's walkthrough of the customer side of SolusVM, covering logging in, projects, server creation and the ways you can connect to a server once it is running.
- [Recovering Inaccessible Servers with Rescue Mode (SolusVM)](https://docs.solusvm.com/en/solusvm2/administrator-guide/recovering-inaccessible-servers-with-rescue-mode/): written for administrators, but worth reading if a server powers on yet the operating system never comes up. It explains the rescue path your provider would use.
- [SolusVM Release Notes](https://docs.solusvm.com/en/release-notes/): the authoritative record of what changed in each release, useful when a control has moved or been renamed since a screenshot was taken.
## Prerequisites
- Access to the SolusVM control panel address, username and password issued when the VPS was set up. These arrive in your welcome email; do not guess the panel address. If you are not signed in yet, start with [How to Log in to SolusVM Control Panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/).
- Confirmation that the VPS is genuinely powered off rather than merely unreachable. See [How to Check Whether the VPS Status is "online" or "offline" in SolusVM](/solusvm/how-to-check-whether-your-vps-is-online-or-offline-in-solusvm/), and the section below on why this distinction matters.
- If the VPS is already running and you simply want it to come back cleanly, you want a restart instead: see [How to Reboot/Restart VPS in SolusVM](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/).
## What "Boot" Actually Does
It is worth understanding what you are asking for, because this is the difference between a boot that fixes the problem and one that changes nothing at all.
**Boot** is a power-on instruction sent to the host machine that runs your virtual server. The panel asks the hypervisor to switch the virtual hardware on. That is the whole of it. It is the exact equivalent of pressing the power button on a physical machine that is currently switched off, and it carries the same limitation: it starts the hardware, and then whatever is installed on the disk takes over. If the operating system on that disk is broken, a boot will start the machine and the machine will fail in exactly the same way it did before.
What happens next depends on the virtualisation type behind your VPS. A full virtual machine, such as a KVM guest, runs a complete start-up sequence: virtual firmware initialises, a bootloader loads, then the kernel starts and the operating system brings up its services one after another. A container-style VPS has no firmware or bootloader stage and starts far more quickly, often in a couple of seconds. This is why two VPS plans on the same panel can behave so differently after you click the same button, and why "it is taking too long" means different things for each.
The critical point for troubleshooting is this: SolusVM reports the power state of the virtual machine, not the health of the operating system inside it. The panel will happily show `online` for a server whose kernel has panicked, whose disk is full, or whose network configuration is wrong. A power state of `online` is the floor, not the finish line.
## Before You Start: Make Sure It Is Really Off
Check the status in the panel before you do anything. If the status already reads `online`, clicking Boot will not help you, and in many builds the button is greyed out or simply returns an error saying the server is already running. Reaching for Boot when a server is unreachable but powered on is the single most common wasted step, because the fault in that case is inside the operating system or the network, and no amount of powering on will touch it.
So split the problem in two before you act:
- **Status `offline`, server unreachable.** The virtual machine is switched off. Boot is the correct action, and the rest of this guide applies.
- **Status `online`, server unreachable.** The machine is powered on and something inside it, or in front of it, is at fault. Do not boot. Connect to the console over VNC to see what the server is actually doing, using [How to Access VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/), or restart it cleanly using [How to Reboot/Restart VPS in SolusVM](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/).
One further check is worth thirty seconds of your time: think about why the server went off. A VPS that you shut down deliberately will boot straight back up. A VPS that switched itself off, or that was switched off by the provider, usually has a reason behind it, such as an unclean shutdown that left the filesystem dirty, an out-of-memory condition, or an account or resource suspension. Knowing which of these you are dealing with tells you whether to expect a clean start or a repeat of the same failure.
## Step 1: Sign In to SolusVM
Open the SolusVM control panel using the address in your welcome email, and sign in with the panel credentials issued for the VPS. Note that these are the control panel credentials, which are entirely separate from the root or administrator password of the operating system running inside the VPS. Confusing the two is a frequent cause of failed sign-ins.
## Step 2: Select the VPS You Want to Start
If your account holds more than one virtual server, the panel presents a list or a selector so you can choose which one you are working on. Pick the correct server before you touch any power control. This matters more than it sounds: the power buttons act immediately on whichever server is currently selected, and there is nothing in the confirmation prompt that will save you from having selected the wrong one. Check the hostname or the primary IP address shown alongside the entry, not just its position in the list, because the ordering can change as servers are added or removed.

## Step 3: Click Boot
With the correct server selected, click **Boot**. On panels where the control is worded differently, this is the **Start** button or the power icon, and it is the only power control that acts on a server that is currently switched off.

## Step 4: Confirm the Action
SolusVM asks you to confirm before it sends the instruction. Click **Yes**. The confirmation step exists because the power controls sit next to each other and act instantly, so read the prompt and check that it names the action you intended and the server you selected.

Once confirmed, click nothing further. The panel queues the instruction with the host machine and reports back when the state changes, which is not instantaneous. Clicking Boot repeatedly does not make the server start faster, and on a busy host it can leave a queue of conflicting power tasks that take longer to clear than the boot itself would have taken.
## How Long It Should Take
Expect the power state to flip to `online` within a few seconds. That is the fast part, because it only reflects the virtual hardware being switched on.
The operating system inside takes considerably longer to become useful. As a rough guide, a container-style VPS is usually accepting connections within five to fifteen seconds, while a full virtual machine typically needs thirty seconds to two minutes to work through firmware, bootloader, kernel and services. A server carrying databases, mail services or a control panel of its own can easily take longer still, because those services start after the network does. So a VPS that answers a ping but refuses an SSH connection twenty seconds after boot is almost certainly still starting, not broken. Give it a couple of minutes before you conclude anything.
One case genuinely does warrant more patience: a server that was forcibly powered off rather than shut down cleanly may run a filesystem check on the way up. On a large disk that can add several minutes, during which the server appears completely unresponsive from outside. This is normal, it is not a fault, and interrupting it by forcing another power cycle is the one thing that can turn a recoverable situation into a damaged one. If you suspect this, watch the console over VNC rather than guessing.
## How to Confirm the Boot Actually Worked
Do not rely on the panel alone. Work through these in order, because each one tests something the previous one does not:
1. **Panel status.** Refresh the page and confirm the status reads `online`. This proves the virtual hardware is powered on and nothing more.
2. **Network reachability.** Ping the server's primary IP address from your own machine. A reply proves the kernel is up and networking is configured. Note that some providers filter ICMP, so no reply here is suggestive rather than conclusive.
3. **Service reachability.** Connect over SSH, or for a Windows guest over RDP. This proves the operating system reached a usable state and started its remote access service.
4. **Uptime.** Once connected, run `uptime` on a Linux server. A value of a few minutes confirms you are looking at a freshly booted machine rather than a stale session or, worse, the wrong server entirely.
5. **Your own services.** Load the site or application the VPS exists to run. Services set to start automatically will be up; anything that was started by hand before the outage will not be, and will need starting again.
If the panel says `online` but steps 2 and 3 fail, the boot succeeded and the problem is inside the operating system. That is the point to open the VNC console, because VNC attaches to the virtual screen and shows you the boot messages, the login prompt or the error that is stopping it, none of which are visible from the network side.
## Troubleshooting
- **Symptom**: the **Boot** button is greyed out or returns an error saying the server is already running. The server is powered on and the status is `online`, so there is nothing to start. If it is unreachable, use [VNC](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/) to look at the console, or perform a restart rather than a boot.
- **Symptom**: the status flips to `online` and then straight back to `offline`. The virtual machine is starting and then failing or halting immediately. Common causes are a kernel or bootloader that cannot find its root filesystem, a disk that is completely full, or a guest configuration change made since the last successful boot. Open the VNC console and boot again while watching the screen; the failure message on the console is what identifies the cause.
- **Symptom**: it will not boot at all, and the panel reports an error from the host. This usually points at something outside your control, such as the host machine being out of free memory, a storage problem, or the service being suspended. Contact your provider with the exact error text and the time it occurred.
- **Symptom**: the server stopped booting immediately after a hardware setting was changed. Changing the disk driver is the classic case: switching a guest to Virtio when its operating system has no Virtio driver installed leaves it unable to see its own disk, so it powers on and then stalls at the bootloader. Set the driver back to its previous value using [How to Change the Disk Driver to Virtio or IDE in SolusVM](/solusvm/how-to-change-the-disk-driver-to-virtio-or-ide-in-solusvm/), then boot again. The same logic applies to the ACPI, APIC and PAE toggles, covered in [How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM](/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/): an older or 32-bit guest can refuse to start when these do not match what it expects.
- **Symptom**: it boots, but takes far longer than it used to and the console shows a filesystem check. The server was previously powered off without a clean shutdown. Let the check finish. To avoid a repeat, shut down gracefully in future rather than forcing the power off, as explained in [How to Forcefully or Gracefully Shut Down the VPS in SolusVM](/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/).
- **Symptom**: the panel shows `online` but nothing responds on the network, and the VNC console shows a normal login prompt. The operating system is healthy and the fault is in networking: a firewall rule inside the guest, an IP or gateway configuration that was changed and not made permanent, or a network interface that did not come up. Log in at the VNC console and inspect the interface configuration from there, since that session does not depend on the network working.
- **Symptom**: the VPS boots but your website or application does not come back. Powering on starts only the services configured to start at boot. Anything started manually during a previous session is not running. Log in and start those services, then enable them at boot so the next outage recovers on its own.
- **Symptom**: nothing above helps and the operating system is unrecoverable. Reinstalling is the last resort and destroys everything on the disk, so treat it as the end of the road rather than a troubleshooting step, and only after you are certain of your backups. The procedure is in [How to Reinstall OS Using SolusVM OS-Reinstaller](/solusvm/how-to-reinstall-the-os-on-a-vps-using-the-solusvm-os-reinstaller/).
## Good Habits That Prevent the Next Outage
Two things save most of the pain around VPS power states. The first is to shut down gracefully whenever you have the choice, so that the operating system flushes its writes and closes cleanly; a forced power-off is for a server that has already stopped responding, not for routine use. The second is to make sure every service you depend on is enabled to start at boot and tested by actually rebooting once, deliberately, at a quiet time. A server that has never been rebooted since it was configured is a server whose start-up behaviour nobody has verified, and finding out during an unplanned outage is the expensive way to learn.
If a VPS will not start, or it starts and the operating system does not come up, gather the evidence before escalating: the status shown in the panel, the exact error text, the time it happened, and anything you can see on the VNC console. Those details are what separate a fault inside the guest operating system from a fault on the host underneath it, and whoever you raise the ticket with will resolve it far faster for having them. If you are a Noiz client and you are unsure how to read what the console is telling you, open a support ticket with the Noiz support team and they will help you interpret it.
# How to Turn APIC, ACPI, VNC, or PAE On or Off in SolusVM
Source: https://docs.noiz.ie/solusvm/how-to-turn-apic-acpi-vnc-or-pae-on-or-off-in-solusvm/
This guide explains the four virtual hardware toggles that SolusVM exposes for a virtual server, APIC, ACPI, VNC and PAE, what each one actually changes at the hypervisor level, when it is sensible to switch one off, and how to confirm afterwards that the change took effect. These are not cosmetic preferences. Three of them alter the virtual hardware the operating system boots on, and one of them decides whether an out-of-band console exists at all when the network stops answering. Switching the wrong one off is a recognised way to make a working VPS unbootable or unreachable, so the reasoning behind each setting matters more than the click that changes it. This article is for anyone with access to a VPS managed through SolusVM, whether that is an end user in the client area or an administrator working on a customer's virtual server.
**Last reviewed:** 27 July 2026, against the current SolusVM release. This guide is maintained by Noiz and is kept current against SolusVM. It complements, and does not replace, the official SolusVM documentation linked below.
### Official Documentation Reference
- [SolusVM Documentation: Introduction to SolusVM, Common Notation and Glossary](https://docs.solusvm.com/en/solusvm1/introduction/introduction-to-solusvm-and-common-notation-and-glossary/), the entry point for the legacy SolusVM 1 documentation set that the classic client area belongs to
- [SolusVM Documentation: PAE Enable/Disable](https://docs.solusvm.com/en/solusvm1/api/admin/virtual-server-functions/pae-enable_disable/), the documented `vserver-pae` action that the PAE toggle drives behind the scenes
- [SolusVM Documentation: Glossary](https://docs.solusvm.com/en/solusvm2/glossary/glossary/), the official definitions of terms such as compute resource, management node, and virtual server
- [libvirt: Hypervisor Features](https://libvirt.org/formatdomain.html#hypervisor-features), the clearest published description of what the `acpi`, `apic` and `pae` feature flags mean in a virtual machine definition
- [Linux kernel: The Kernel's Command-Line Parameters](https://www.kernel.org/doc/html/latest/admin-guide/kernel-parameters.html), the authoritative reference for `acpi=off`, `noapic`, `nolapic` and the related boot options mentioned below
- [Linux manual page: `logind.conf(5)`](https://man.archlinux.org/man/logind.conf.5), which documents `HandlePowerKey`, the `systemd-logind` setting that makes a modern Linux guest react to a virtual power button press
- [Linux manual page: `acpid(8)`](https://man.archlinux.org/man/acpid.8), the ACPI event daemon that older, non-systemd guests rely on for the same job
- [Linux kernel: High Memory Handling](https://docs.kernel.org/mm/highmem.html), useful background on why 32-bit systems need PAE to address more than 4 GB of RAM
## Prerequisites
- Access to [log in to the SolusVM control panel](/solusvm/how-to-log-in-to-the-solusvm-control-panel/). The address you log in at is given in the welcome email for your VPS.
- A maintenance window. Every one of these settings needs the virtual server to stop and start again before it takes effect, so plan for downtime rather than discovering it.
- Knowing which virtualisation type your VPS uses. These toggles apply to full virtualisation, meaning KVM and Xen HVM. You can check this on the VPS information screen if you are not sure, as described in [how to check the RAM, IP, disk capacity and virtualisation details in SolusVM](/solusvm/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-solusvm/).
- A recent backup or snapshot if you intend to change APIC, ACPI or PAE. Two of these three can stop a guest booting, and the console is your only route back in.
## What Each Toggle Actually Does
SolusVM presents all four as identical On and Off dropdowns, which badly understates how different they are. Three of them, APIC, ACPI and PAE, are virtual hardware features passed to the guest at power-on: they change what the emulated machine looks like to the operating system, in much the same way a BIOS option changes what a physical machine looks like. VNC is not a guest feature at all. It is a service running on the host node that gives you a screen and a keyboard for the virtual machine, and turning it off changes nothing inside the guest.
### ACPI, and why graceful shutdown depends on it
ACPI, the Advanced Configuration and Power Interface, is the standard that lets an operating system discover and control the hardware's power management. In a virtual machine it does two jobs that matter.
The first is the one people notice. ACPI is the mechanism by which a graceful shutdown or restart works. When you click **Shutdown** or **Reboot** in SolusVM, the hypervisor does not reach inside the guest and stop it. It raises an ACPI power button event, which is the virtual equivalent of briefly pressing the power button on a physical server. The operating system sees that event and runs its own shutdown sequence: services stop cleanly, write buffers are flushed to disk, filesystems are unmounted and marked clean. On a systemd-based Linux distribution the event is handled by `systemd-logind` through its `HandlePowerKey` setting; on older or non-systemd systems it is handled by the `acpid` daemon. Either way, if ACPI is switched off in SolusVM, that event has nowhere to land. The panel will report the request as sent, the guest will carry on running as though nothing happened, and the only remaining way to stop the machine is a forced power off, with all the risk that carries. The relationship works in both directions and is worth committing to memory: **no ACPI means no graceful shutdown, which means every stop becomes the equivalent of pulling the plug**. If graceful shutdowns are already failing on your VPS, this setting is the first thing to check, and [the difference between a forced and a graceful shutdown in SolusVM](/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/) explains exactly what you lose when the graceful path is unavailable.
The second job is less obvious and catches people out. On x86 systems, ACPI also publishes the tables that describe the machine's topology, including the MADT table that enumerates the processors. A modern Linux kernel uses those tables to find the CPUs. Disable ACPI on a multi-vCPU virtual server and the guest can come up seeing only one processor, or fail to bring the others online, which looks like a mysterious performance collapse rather than a configuration change. Boot-time thermal, timer and interrupt routing behaviour can shift as well.
ACPI should be left **On** in virtually every case. The only real reason to disable it is a guest operating system so old or so unusual that its ACPI implementation is broken and prevents boot, and that is a diagnosis you reach after seeing the machine hang, not a precaution taken in advance.
### APIC, and what happens to interrupts without it
APIC, the Advanced Programmable Interrupt Controller, is the modern replacement for the original PC interrupt controller, the 8259 PIC. Interrupts are how devices get the processor's attention: a network card announcing a packet, a disk announcing a completed write, the timer announcing a tick. The old PIC design supports only 16 interrupt lines and has no concept of more than one processor. The APIC design removes both limits, which is why it exists.
Turning APIC off tells the hypervisor to present the guest with the legacy controller instead. The consequences follow directly from that:
- **Multiple vCPUs stop being useful.** Without an APIC there is no mechanism for one processor to interrupt another, so symmetric multiprocessing does not work. A guest with several vCPUs will typically boot on one of them or not boot at all.
- **Interrupt lines become scarce.** Devices are forced to share the small pool of legacy interrupt lines, which shows up as poor throughput on disk and network under load rather than as an obvious error.
- **Timer behaviour changes.** The local APIC is a common timer source. Removing it pushes the guest onto older timer hardware, which on some kernels produces clock drift or unusually high timer overhead.
APIC should be left **On**. The genuine exception is a very old guest operating system with a known APIC bug, where the vendor's own advice is to boot with `noapic` or `nolapic`. Note that if the fix you have been given is a kernel command-line parameter, apply it as a kernel parameter inside the guest rather than switching the virtual hardware off in SolusVM. The kernel parameter is reversible from the boot menu; the panel setting is not reachable at all if the machine will not boot.
### VNC, and the console you only miss when you need it
VNC is different in kind from the other three. It does not change the guest's virtual hardware. With VNC on, the host node runs a small server attached to the virtual machine's emulated graphics and keyboard, and the SolusVM client area connects to it to give you a console. That console is out of band, meaning it does not depend on the guest's network stack, its firewall, or its SSH service being alive. It is what shows you a filesystem repair prompt waiting for an answer, a firewall rule that has locked you out, a kernel that panicked during boot, or a network configuration change that took the interface down. [How to access a VPS via VNC in SolusVM](/solusvm/how-to-access-your-vps-via-the-vnc-console-in-solusvm/) covers using it.
The argument for switching VNC off is attack surface. The VNC server listens on the host node, and anyone who reaches it with the right password gets a console session that is equivalent to sitting at the machine, before any of the guest's own authentication applies. The argument against switching it off is that you are removing the one recovery route that works when everything inside the guest has failed, which is precisely the moment you will want it.
In practice the better answer is almost always to leave VNC **On** and treat its password as a root-equivalent credential: set a long, unique one and change it if it has ever been shared. [How to change the VNC password in SolusVM](/solusvm/how-to-change-the-vnc-password-in-solusvm/) covers that. Switch VNC off only if a policy requires it, and only once you are confident of another way in, such as a serial console or a working rescue mode.
One practical detail: turning VNC on or off changes the console service, not the running guest, so nothing inside the operating system notices. It still needs the virtual machine to be stopped and started before the change is live, because the console is attached when the machine is created on the host node.
### PAE, and why it only matters on 32-bit systems
PAE, Physical Address Extension, widens the page table entries a 32-bit x86 processor uses, taking the amount of physical memory the system can address past the 4 GB ceiling that plain 32-bit addressing imposes. It is also the feature that makes the NX no-execute bit available on 32-bit systems, which is a meaningful security property, not just a capacity one.
Everything about PAE follows from one fact: **it is a 32-bit concern only**. A 64-bit guest addresses far more memory natively and does not care about this toggle. If your VPS runs a 64-bit operating system, which almost every current distribution and Windows release is, this setting has no practical effect on it.
Where it does matter, it matters absolutely:
- Most 32-bit Linux distributions ship a PAE-enabled kernel as standard, and a PAE kernel will not boot on a processor that does not advertise the feature. The failure is explicit rather than subtle, along the lines of `This kernel requires the following features not present on the CPU: pae`, followed by a halt. If a 32-bit guest stops dead at that message, this toggle is the cause.
- A handful of very old 32-bit operating systems predate PAE or implement it badly, and need it switched off to install or boot.
- A 32-bit guest with more than 4 GB of RAM assigned cannot use the memory beyond that ceiling without PAE. The RAM is allocated and paid for, and the guest simply will not see it.
Leave PAE **On** unless a specific old operating system tells you otherwise. On the SolusVM side, this toggle corresponds to the documented `vserver-pae` action, linked above, which is worth knowing if you ever automate the change.
### When the settings are not there at all
If you cannot find these controls, the usual reason is virtualisation type. Container-based virtual servers such as OpenVZ share the host node's kernel and have no BIOS, no virtual interrupt controller and no power management layer of their own, so APIC, ACPI and PAE are meaningless for them and are not offered. Xen PV guests are paravirtualised and likewise do not present emulated firmware. Beyond that, the SolusVM client area is configurable, and a provider can choose not to expose these settings to end users, in which case the change has to be made by whoever administers the SolusVM master server for your VPS.
## How to Turn APIC, ACPI, VNC or PAE On or Off
1. Log in to your SolusVM control panel using the address in your VPS welcome email.
2. If your account holds more than one virtual server, select the one you want to change. Check the hostname and main IP address before going any further, because nothing in the confirmation step tells you which server you picked. 
3. Scroll down to the **Settings** tab. The APIC, ACPI, VNC and PAE controls are grouped there, each with its own **On** and **Off** dropdown.
4. Set the dropdown for the feature you want to change. In the example below, VNC is being switched to **Off** by selecting **Off** from the dropdown beneath the VNC label. 
5. Change one setting at a time and apply it before moving on to the next. If two changes are made together and the guest then fails to boot, you have no way of telling which one caused it.
6. Stop and start the virtual server so the new configuration is applied. SolusVM records the change immediately, but the guest keeps the virtual hardware it was given when it was powered on, so nothing is different until the machine is created again on the host node.
### Getting the restart order right
A [reboot from the SolusVM panel](/solusvm/how-to-reboot-or-restart-a-vps-in-solusvm/) is usually enough. If you want certainty, or if the guest comes back visibly unchanged, do a full [shutdown](/solusvm/how-to-force-or-gracefully-shut-down-a-vps-in-solusvm/) followed by a [boot](/solusvm/how-to-start-or-boot-your-vps-in-solusvm/). A full power cycle is the only way to be sure the machine has been rebuilt from the current configuration.
There is one ordering trap that is easy to walk into. If you are switching **ACPI off**, use the graceful shutdown now, while ACPI is still active in the running guest. Once the machine restarts without ACPI, graceful shutdown stops working, and every subsequent stop has to be forced. Doing it in the wrong order means the very first thing you do after the change is exactly the thing this setting has just broken.
A related point applies to **VNC**. If you are turning VNC off, confirm your other access route works before the machine restarts. After the restart there is no console to fall back on, and a mistake in a firewall or network configuration then has no local remedy.
## How to Confirm the Change Actually Took Effect
The panel showing **Off** only tells you SolusVM stored the request. Check inside the guest, over SSH or on the console, once it is back up.
### ACPI
```
ls /sys/firmware/acpi
dmesg | grep -i acpi | head
```
If `/sys/firmware/acpi` exists and is populated, the kernel found and is using ACPI tables. With ACPI disabled, the directory is absent and the boot messages say so. Confirm the handler is running too, since ACPI being present is no use if nothing is listening for the event:
```
systemctl status systemd-logind
systemctl status acpid
```
On a systemd distribution, `systemd-logind` is the one that matters and `acpid` may not be installed at all. On an older system it is the other way round. The real end-to-end test is behavioural: issue a graceful shutdown from the panel and watch the machine actually go down.
### APIC
```
dmesg | grep -iE 'apic|pic' | head
grep -c ^processor /proc/cpuinfo
lscpu | head
```
The boot messages state which interrupt controller was found. The processor count is the practical check: if the VPS was sold with several vCPUs and the guest now reports one, APIC is the first suspect. `cat /proc/interrupts` is also worth a look, since the routing column names the controller in use.
### PAE
```
grep -o -m1 ' pae ' /proc/cpuinfo
uname -m
free -h
```
The first command reports whether the CPU is advertising the PAE flag to the guest. `uname -m` tells you whether this is even relevant: `x86_64` means you are on a 64-bit system and PAE is not your problem. On a 32-bit guest with more than 4 GB assigned, `free -h` is the honest test of whether the extra memory is visible.
### VNC
There is nothing to check inside the guest, because nothing inside the guest changed. Open the console from the SolusVM client area. If it connects and you get a login prompt, VNC is on. If it refuses, it is off, or the console password needs setting.
## Troubleshooting
- **The setting was changed but nothing is different in the guest**: the virtual server has not been rebuilt from the new configuration. A guest-initiated restart from inside the operating system is not always sufficient. Do a full shutdown and boot from the panel.
- **Graceful shutdown and reboot stopped working after a change**: ACPI is off, or the guest has no handler for the power event. Turn ACPI back on, boot the machine, and check that `systemd-logind` is running, or that `acpid` is installed and enabled on an older distribution. Until then, stopping the machine means forcing it, so expect a filesystem check on the next boot.
- **The VPS lost most of its CPUs after a change**: this is the classic signature of APIC or ACPI being off. Without an APIC there is no multiprocessing, and without ACPI the kernel may not enumerate the processors at all. Turn the setting back on and power cycle.
- **A 32-bit guest halts at "This kernel requires the following features not present on the CPU: pae"**: PAE is off and the installed kernel needs it. Turn PAE on and boot again. Nothing inside the guest can be changed to work around this, because the guest never gets far enough to run.
- **The guest will not boot after a change and you have no console**: this is why VNC should be the last thing you ever disable. Set the feature you changed back to its previous value, power cycle, and if that does not recover the machine, ask whoever administers the SolusVM master server to attach a console or start the virtual server in rescue mode.
- **The console connects but shows a blank or frozen screen**: that is usually the guest itself, not the VNC setting. A kernel panic, a boot hang, or a blanked virtual terminal all look like this. Press a key or send **Ctrl+Alt+Del** from the console if the viewer offers it, and read whatever text appears rather than power cycling straight away.
- **The Settings tab does not show these options**: the virtual server is most likely container-based or paravirtualised, where they do not apply, or the client area has been configured not to expose them. Confirm the virtualisation type first, then ask the administrator of the SolusVM master server if it is one that should have them.
- **You want to try a boot-time workaround rather than change the panel**: for interrupt and power management problems, kernel parameters such as `noapic`, `nolapic` and `acpi=off` can be applied from the guest's boot menu for a single boot. That is the safer experiment, because it is undone by rebooting, whereas a panel change persists and may leave a machine that cannot start.
If a change to these settings leaves a VPS unbootable or unreachable and the panel controls are not recovering it, escalate to the team that runs the SolusVM master server for your VPS, whose contact details are in your VPS welcome email. Noiz clients can open a support ticket with the Noiz support team; include the VPS hostname and main IP address, which setting was changed and to what, the time the change was made, and anything visible on the console.
# How to Access Your VPS via the VNC Console in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/
This guide shows you how to open the **VNC console** for a VPS from **Virtualizor**, the panel Noiz VPS clients use to manage their servers. VNC gives you a screen and keyboard attached directly to the virtual machine, exactly as though you had walked up to a physical server and plugged a monitor into it.
That distinction is the whole point of the feature. Every other way of reaching a VPS depends on the server itself co-operating: SSH needs the SSH daemon running, the network configured and the firewall letting you through. VNC needs none of that. It attaches at the hypervisor level, outside the guest operating system, so it keeps working when the server has locked you out of itself.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end-user panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor End User: VNC](https://www.virtualizor.com/docs/enduser/vnc/)
- [Virtualizor End User: VPS Management](https://www.virtualizor.com/docs/enduser/vps-management)
- [Virtualizor FAQ: VNC Issues](https://www.virtualizor.com/docs/faq/vnc-issue/)
## Prerequisites
- Your Virtualizor end-user panel URL and login details, which are in your Noiz VPS welcome email.
- An active Noiz VPS service.
- **The VPS must be powered on.** VNC shows you the virtual machine's screen, and a machine that is switched off has no screen to show. If yours is off, start it first with [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/).
- A current desktop browser. The console runs in the browser itself, so nothing needs installing on your computer.
## When You Actually Need VNC
Most of the time SSH is the better tool, and it is faster, supports copy and paste properly and lets you move files. Reach for VNC in the situations where SSH cannot help you, which are the situations that matter most:
- **The firewall has locked you out.** A mistyped rule, a changed office IP address or an over-eager brute-force blocker will shut SSH in your face. The console is not affected, because it never touches the guest's firewall.
- **Networking on the VPS is broken.** A bad network configuration change, a wrong netmask or gateway, or an interface renamed by a kernel update all take the server off the network without stopping it running. On the console you can see it sitting there perfectly healthy and fix the configuration.
- **SSH itself will not start.** A broken configuration file, a full disk or a failed upgrade can leave the SSH daemon dead while everything else is fine.
- **The server will not finish booting.** This is the big one. A failed file system check, a missing disk in `/etc/fstab`, a kernel that will not load or a GRUB menu waiting for input all stall the boot before the network ever comes up. Only a console can show you the error, and only a console can answer the prompt. Without VNC, a server stuck at boot simply looks dead.
- **You are installing an operating system by hand.** A manual install from an ISO happens entirely on the console, because there is no operating system yet to connect to. See [How to Manually Install or Reinstall an OS Using Virtualizor for a Customized Installation](/virtualizor/how-to-manually-install-or-reinstall-an-os-from-an-iso-in-virtualizor/).
- **You have forgotten the root password.** Resetting it means booting into single-user or rescue mode and editing the boot entry, which is keyboard work at the console.
The practical habit worth forming: before you change anything that could cut your own connection, such as a firewall rule, an SSH port, a network interface or the `sshd` configuration, confirm you can open the VNC console first. Verifying your escape route takes ten seconds and saves an afternoon.
## Open the VNC Console
1. Log in to your Virtualizor end-user panel.
2. From the left-hand menu, click **List VPS**. 
3. Hover over the row for the VPS you want to reach. The row highlights. Click the **Manage** icon on that row. 
4. At the top right of the management page, click the **VNC** icon. 
5. A panel opens offering the console options. Click **Launch HTML 5 VNC Client**. 
6. The console opens and shows the virtual machine's screen, which will look something like this: 
### Use the HTML5 Client, Not the Java One
Older Virtualizor panels offered a Java VNC viewer alongside the browser client, and older guides still tell you to use it. Ignore that advice. Browsers removed support for Java applets years ago, so the Java option cannot run in a modern browser at all. If a screen or an old note mentions a Java viewer or warns that VNC needs Java installed, it is describing the legacy path. The **HTML 5** client is the one to use, and it needs nothing installed on your computer.
The same panel also shows the raw VNC host, port and password. Those are for connecting with a standalone VNC application instead of the browser, which is occasionally useful on a bad connection. Treat that password as a live credential for full console access to your server, because that is exactly what it is. Do not paste it into a chat or a ticket.
## Working in the Console
The console behaves like a physical monitor and keyboard, with the limitations that implies.
- **Copy and paste usually will not work** the way you expect. Your clipboard belongs to your computer, not to the virtual machine, so a long command has to be typed by hand. This is the single most common frustration with console work, and it is why SSH remains the better tool whenever SSH is available. Some console clients offer a clipboard or "send text" control in a side toolbar; use it if it is there.
- **Ctrl+Alt+Del has to be sent deliberately.** Pressing it on your keyboard will be caught by your own operating system, not passed through. Use the console's own key control to send it.
- **Key combinations your browser owns get intercepted.** Anything the browser treats as a shortcut, such as Ctrl+W or Ctrl+T, closes or opens a browser tab rather than reaching the server. Full-screen mode in the console reduces the collisions.
- **Keyboard layout is the guest's, not yours.** If the operating system on the VPS is set to a different layout, punctuation characters will land in the wrong place. That bites hardest when typing a password full of symbols, so if a password you are certain about keeps failing, suspect the layout before you suspect the password.
- **The console is text-only on most servers.** A Linux VPS without a desktop installed shows a plain login prompt, which is normal and not a fault.
- **The session is live, not a recording.** If the screen is blank, the server may simply have blanked it after a period of inactivity. Press a key and it will usually redraw.
## Security Notes Worth Knowing
- Console access is total access. Anyone who can reach it can boot into rescue mode and change the root password, which is precisely why it works when everything else has failed. Protect the Virtualizor panel login accordingly, and change it if you ever suspect it has been shared. See [How to Change the Password of Your Virtualizor Account](/virtualizor/how-to-change-your-virtualizor-account-password/).
- The VNC password shown in the panel is a standing credential for that VPS, not a one-time code. It stays the same until you change it, so change it if it has ever been shared, pasted into a ticket or seen on a screen share. See [How to Change the VNC Password in Virtualizor](/virtualizor/how-to-change-the-vnc-password-in-virtualizor/), and note that the VPS has to be stopped and started from the panel before a new VNC password takes effect.
- Close the console tab when you have finished. An open console left on an unlocked laptop is a logged-in root session in all but name.
## Troubleshooting
**Symptom**: the VNC icon is greyed out. The VPS is powered off. Start it, then reopen the console.
**Symptom**: the VNC icon is not on the management page at all. VNC has not been enabled for that virtual machine, which is a property of the VPS rather than anything you have done wrong. Turn it on as described in [How to Enable or Disable APIC, ACPI and VNC in Virtualizor](/virtualizor/how-to-enable-or-disable-apic-acpi-and-vnc-in-virtualizor/), remembering that the setting only takes effect after the VPS is power cycled.
**Symptom**: the console window opens but stays black. First press a key, since the screen may just be blanked. If it stays black, the virtual machine may have only recently been started and not yet produced any output, so give it a moment and reload. A console that is black immediately after a forced power off usually means the server is still running a file system check and has not reached a login prompt.
**Symptom**: the console fails to connect, times out or disconnects immediately. The browser client connects back to the Virtualizor panel on its own ports rather than the normal web ports, and restrictive corporate, university or guest networks routinely block them. Test from a different connection, such as a mobile hotspot, before assuming the server is at fault. Virtualizor also documents this happening when VNC was enabled on a VPS after that VPS was created, in which case a stop and start from the panel resolves it.
**Symptom**: your typing does not appear. Click once inside the console area first, because it needs keyboard focus. If characters appear but the wrong ones do, it is a keyboard layout mismatch inside the guest operating system.
**Symptom**: the console shows a login prompt but your password is rejected. Check the layout point above, then confirm you are using the operating system's root password and not your Virtualizor panel password. They are separate credentials and are often confused.
**Symptom**: the screen is frozen and nothing responds, including Ctrl+Alt+Del. The guest operating system has hung rather than the console failing. A hard reset from the panel is the next step, keeping in mind that it is an abrupt power cycle.
**Symptom**: the console works but the server is unreachable from the internet. That confirms the fault is in networking or the firewall rather than the server being down, which is useful information. Check the interface configuration, the routing table and the firewall rules from the console.
## Related Guides
- [How to Manually Install or Reinstall an OS Using Virtualizor for a Customized Installation](/virtualizor/how-to-manually-install-or-reinstall-an-os-from-an-iso-in-virtualizor/)
- [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/)
- [How to Reboot or Restart a VPS in Virtualizor](/virtualizor/how-to-reboot-or-restart-a-vps-in-virtualizor/)
- [How to Forcefully or Gracefully Shut Down the VPS in Virtualizor](/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/)
## Need a Hand?
If the console will not open, or it opens and shows a server stuck at a boot error you do not recognise, open a support ticket from your [Noiz client area](https://www.noiz.co.za). Include what the console screen shows, since that message is usually the fastest route to a diagnosis. The support team can confirm the console service is healthy on the host node and help you recover a VPS that will not boot on its own.
# How to Change Your VPS Hostname in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-change-your-vps-hostname-in-virtualizor/
Your VPS hostname is the server's own name on the network, and it is separate from any website domain the server hosts. This guide shows you how to change it from the Virtualizor end user panel on your Noiz VPS, and covers the two things that catch people out afterwards: the VPS needs a power cycle before the new name is fully in effect, and mail delivery depends on the hostname matching the reverse DNS record for the VPS IP address.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end user panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor documentation: Change Hostname (end user panel)](https://www.virtualizor.com/docs/enduser/change-hostname)
- [Virtualizor documentation: Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps)
- [Virtualizor documentation: List VPS](https://www.virtualizor.com/docs/enduser/list-vps)
## Prerequisites
- Access to your Virtualizor end user panel. See [How to Log In to the Virtualizor VPS Control Panel](/virtualizor/how-to-log-in-to-the-virtualizor-vps-control-panel/).
- A hostname you have already decided on, in fully qualified form, for example `server1.yourdomain.com` (replace with your own domain).
- A maintenance window. The change is not live until the VPS is stopped and started again, so treat it as a short planned outage rather than an in-hours tweak.
## Choose the Hostname Before You Change It
Virtualizor accepts a fully qualified domain name: letters, digits and hyphens, separated by dots, with no underscores and no trailing dot. Two conventions save trouble later:
- **Use a subdomain, not your main domain.** Naming the server `server1.yourdomain.com` rather than `yourdomain.com` keeps the machine name independent of the websites it hosts, so you can move sites between servers without the server identity following them around.
- **Create a DNS record for it first.** Add an A record for the new hostname pointing at the VPS IP address. Plenty of software, mail daemons in particular, will resolve the hostname at start-up and complain loudly if it does not resolve to the machine it is running on.
## Change the Hostname in Virtualizor
### Step 1: Open the VPS list
Log in to your Virtualizor end user panel, then click **List VPS** in the left side panel.

### Step 2: Manage the VPS
Hover your mouse over the row for the VPS you want to change. The row highlights. Click the **Manage** icon on that row to open the VPS management page.

### Step 3: Set the new hostname
On the VPS management page, open the hostname option. In the current end user panel it is listed as **Hostname** on the VPS management menu; on older builds it sits under a **Settings** tab as **Change Hostname**, which is what the screenshot below shows. Either way, type the new fully qualified hostname into the field and click **Change Hostname**.

Virtualizor confirms the change straight away, but at this point only the panel's record has been updated.
### Step 4: Power cycle the VPS
The hostname is applied to the running system at boot, so the VPS has to be restarted before the new name takes full effect. Virtualizor's own documentation asks for a stop followed by a start rather than a warm reboot, because a full power cycle is what guarantees the VPS picks up the new configuration from the host.
- [How to Force or Gracefully Shut Down a VPS in Virtualizor](/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/), then [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/).
- A restart from the panel is often enough on its own: see [How to Reboot or Restart a VPS in Virtualizor](/virtualizor/how-to-reboot-or-restart-a-vps-in-virtualizor/). If the old name is still showing afterwards, do the full stop and start.
### Step 5: Confirm it inside the VPS
Connect over SSH once the VPS is back up and check what the operating system now reports:
```
hostname -f
hostnamectl status
```
If the old name is still returned, set it at the operating system level as well and reboot once more:
```
sudo hostnamectl set-hostname server1.yourdomain.com
```
Also check that `/etc/hosts` maps the VPS IP address to both the fully qualified hostname and the short name. A stale entry there is a common cause of slow logins and of software that insists the hostname cannot be resolved.
## Update Reverse DNS and Mail Settings
Changing the hostname in Virtualizor changes the server's name. It does not change how the rest of the internet identifies your IP address, and that gap is where mail problems start.
- **Reverse DNS (PTR).** The PTR record for your VPS IP address is set at the network level, not inside the VPS, so it does not follow a hostname change. Open a ticket with Noiz support with the IP address and the new hostname, and the PTR record will be updated to match.
- **Forward and reverse must agree.** Receiving mail servers routinely check that the hostname a server announces in its SMTP greeting resolves to the connecting IP address, and that the IP address resolves back to that same hostname. If the two disagree, your mail gets deferred, filed as spam, or rejected outright. Getting the A record and the PTR record to match is not optional if the VPS sends mail.
- **Mail software keeps its own copy.** A mail server stores the name it announces in its own configuration. After a hostname change, restart the mail service and confirm the greeting is correct, for example with `openssl s_client -starttls smtp -connect localhost:25` or by reading the first line of a test SMTP session.
- **Server control panels keep their own copy too.** If you run control panel software on the VPS, change the hostname in that panel's own settings as well. Panels issue TLS certificates and generate configuration against the hostname they hold, not the one Virtualizor holds, and the two drifting apart causes certificate warnings on the panel login page.
## Troubleshooting
- **Symptom**: the form rejects the value. The hostname must be a valid fully qualified domain name. Remove underscores, spaces and any trailing dot, and make sure there is at least one dot in the name.
- **Symptom**: the panel shows the new hostname but the VPS still reports the old one. The power cycle has not happened, or the operating system is setting the hostname itself at boot. Stop and start the VPS, then set it with `hostnamectl set-hostname` if it still reverts.
- **Symptom**: the hostname reverts on every reboot. A cloud-init or template configuration inside the VPS is overwriting it. Set `preserve_hostname: true` in the cloud-init configuration inside the VPS, then set the hostname once more.
- **Symptom**: outgoing mail is suddenly rejected or marked as spam after the change. The PTR record still points at the old hostname. Raise a ticket with Noiz support to have reverse DNS updated, and confirm the A record for the new hostname points at the VPS IP address.
- **Symptom**: services are slow to start or log warnings about resolving the hostname. Add the VPS IP address, the fully qualified hostname and the short name to `/etc/hosts`.
## Need a Hand?
Reverse DNS for a Noiz VPS is handled by the Noiz team, so open a support ticket from your Noiz client area with the VPS IP address and the new hostname and it will be aligned for you. If you are on a managed plan, Noiz can carry out the whole hostname change, including the power cycle and the mail server checks, in an agreed maintenance window.
# How to Change Your Virtualizor Account Email Address
Source: https://docs.noiz.ie/virtualizor/how-to-change-your-virtualizor-account-email-address/
This guide shows you how to change the email address linked to your Virtualizor VPS control panel account, meaning the address you use to sign in and the address the panel sends its notifications to. The account email is sometimes called your login email or panel username, because Virtualizor uses the email address as your username when you sign in. Virtualizor does not let you edit this address yourself from the end user panel, so the change itself is completed by the Noiz support team. This guide shows you how to confirm the address currently on your account, how to request the change, and how to sign in once it has been done.
**Last reviewed:** 27 July 2026, against Virtualizor **3.2.9** (latest stable). This article follows the official Virtualizor end user documentation for the profile and account settings pages; the email change itself is an administrator-side action in Virtualizor, which is why it is handled by Noiz. Virtualizor releases frequently, so always cross-reference the current version of the official documentation before starting: direct links to every section used in this guide are provided below.
### Official Documentation Reference
- [Virtualizor End User Panel documentation index](https://www.virtualizor.com/docs/enduser/)
- [Change Account Password (documents the My Profile page and its tabs)](https://www.virtualizor.com/docs/enduser/change-account-password/)
- [User Settings (end user panel preferences)](https://www.virtualizor.com/docs/enduser/account-settings/)
- [Profile (end user API reference, lists the profile fields you can edit yourself)](https://www.virtualizor.com/docs/enduser-api/profile/)
- [Edit User (administrator API reference, the action that changes an account email address)](https://www.virtualizor.com/docs/admin-api/edit-user/)
## Prerequisites
- An active Noiz VPS that includes Virtualizor end user panel access.
- The panel address and login details from your Noiz welcome email.
- Access to a working mailbox at the new address you want to use.
## How the Virtualizor Account Email Works
In Virtualizor, your email address is more than a contact detail: it is also the username you type on the panel login screen. Because the address doubles as your login identity, Virtualizor only allows it to be changed from the administrator side of the panel, which Noiz operates. The end user panel lets you view the address, change your first and last name, change your account password, and adjust preferences such as language, theme and timezone, but it deliberately has no field for editing the email address itself.
Note that your Virtualizor panel login is separate from your Noiz client area login. Changing one does not change the other, so if you are moving to a new address permanently, update your Noiz client area contact details as well.
## Step 1: Confirm the Email Address on Your Account
Before requesting a change, check exactly which address is registered on your account so you can quote it accurately in your ticket.
1. Open your Virtualizor end user panel in a browser. The address is in your Noiz welcome email and looks similar to `https://vps.yourdomain.com:4083` (this is an example only: replace it with the actual address from your welcome email).
2. Sign in with your current email address and your panel password.
3. Click your username in the panel header.
4. Select **My Profile** from the menu.
5. On the **Profile** tab, note the email address currently registered on the account. You will see editable **First Name** and **Last Name** fields, but the email address itself cannot be edited here.
## Step 2: Request the Change From Noiz
1. Open a support ticket with the Noiz support team, ideally sent from the email address currently registered on the account, as this makes verification quick.
2. Include the following in your ticket:
- The current email address on your Virtualizor account.
- The new email address you want to use, typed out in full.
- Your VPS hostname or the service it relates to, so the right account is updated.
3. If you also want your Noiz client area and billing contact address updated to match, say so in the same ticket.
4. Wait for confirmation from the Noiz support team that the address has been changed before trying to sign in with it.
## Step 3: Sign In With Your New Email Address
1. Once Noiz confirms the change, return to your Virtualizor panel login page.
2. Enter your new email address as the username. Your password does not change, so use your existing panel password.
3. If your browser has saved the old login, update the saved entry so it does not autofill the old address.
From this point on, all panel notifications, such as password resets and server alerts, go to the new address.
## What You Can Change Yourself in the Panel
Although the email address is provider-managed, the end user panel does let you update several account details on your own:
- **First Name** and **Last Name**: on the **Profile** tab under **My Profile**, edit the fields and save your changes.
- **Account password**: on the **Account Password** tab under **My Profile**, enter a new password and click **Change Password**.
- **Panel preferences**: click your username, select **Settings**, adjust **Language**, **Theme** and **Timezone**, then click **Edit Settings**.
## Troubleshooting
**Symptom**: You cannot find an email field to edit on the My Profile or Settings pages. This is expected behaviour: Virtualizor does not allow end users to edit the account email address. Follow Step 2 above and the Noiz support team will change it for you.
**Symptom**: You no longer have access to the mailbox at your old address. Mention this clearly in your ticket. The Noiz support team will verify your identity using your account details instead before making the change.
**Symptom**: The panel rejects your new email address at login after the change was confirmed. Make sure you are typing the new address exactly as you supplied it, with no leading or trailing spaces, and that your browser is not autofilling the old address. Your password is unchanged, so if you have forgotten it, use the password reset link on the login page, which now emails your new address.
**Symptom**: Billing or invoice emails from Noiz still arrive at your old address. The Virtualizor panel and the Noiz client area are separate logins with separate contact details. Update your client area contact email as well, or ask the Noiz support team to change both in your ticket.
If you are on a Noiz managed VPS plan, you do not need to work through the panel steps yourself: contact the Noiz support team with your old and new addresses and they will take care of the whole change. If you get stuck at any point, open a support ticket with the Noiz support team.
# How to Change Your Virtualizor Account Password
Source: https://docs.noiz.ie/virtualizor/how-to-change-your-virtualizor-account-password/
This guide shows you how to change the password you use to sign in to your **Virtualizor** end-user panel, the control panel Noiz VPS clients use to manage their servers. The change is made from inside the panel and takes only a moment, so it is worth doing on a regular schedule and immediately if you suspect the credential has been exposed.
**Important:** this changes your *panel* password only. It is not the root or administrator password of the operating system running on your VPS, and it is not your Noiz client area password. See [Which Password Are You Actually Changing?](#which-password) below, because confusing the two is the single most common mistake with this task.
**Last reviewed:** 27 July 2026, against the current Virtualizor release. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor End User: Change Account Password](https://www.virtualizor.com/docs/enduser/change-account-password/)
- [Virtualizor End User: Account Settings](https://www.virtualizor.com/docs/enduser/account-settings/)
- [Virtualizor End User Documentation](https://www.virtualizor.com/docs/enduser/)
## Prerequisites
- Your Virtualizor end-user panel URL and your current login details, which are in your Noiz VPS welcome email.
- Working access to the panel. If you cannot sign in at all, see [Troubleshooting](#troubleshooting), as this procedure cannot recover a lost password.
- A new password prepared in advance, ideally generated and stored in a password manager.
## Which Password Are You Actually Changing?
A VPS involves several separate passwords that are easy to mix up. Changing one has no effect on the others.
- **Virtualizor panel password** (this article): the credential that signs you in to the Virtualizor end-user panel, where you reboot, reinstall, and monitor the VPS. Changing it does not touch anything inside the server itself.
- **VPS root or administrator password**: the operating system login used for SSH or Remote Desktop. This is set separately, and is covered in [How to Change the VPS Root/Admin Password in Virtualizor](/virtualizor/how-to-change-the-vps-rootadmin-password-in-virtualizor/).
- **VNC password**: used only for console access to the VPS screen, and managed on its own settings page.
- **Noiz client area password**: your billing and support login at noiz.co.za, which is entirely separate from the VPS panel.
If your goal is to lock an intruder out of the server, changing the panel password alone is not enough. Change the operating system password as well, and rotate any SSH keys.
## Change Your Virtualizor Account Password
1. Log in to your Virtualizor end-user panel. If you are not sure of the address, see [How to Log in to Virtualizor Control Panel](/virtualizor/how-to-log-in-to-the-virtualizor-vps-control-panel/).
2. At the top right of the panel, click your **username**, then choose **My Profile** from the dropdown menu. 
3. Open the **Account Password** tab.
4. Enter your new password in the fields provided, then click **Change Password**. 
The panel confirms the change straight away. There is no email confirmation step and no delay, so the new password is live the moment the confirmation appears.
## What Happens After the Change
A few consequences catch people out, so it is worth knowing them before you click the button:
- **The old password stops working immediately.** There is no grace period. Make sure the new password is recorded somewhere safe before you submit it.
- **Browsers and password managers keep offering the old value.** Update the saved entry, otherwise the next sign-in attempt fails and looks like the change did not apply.
- **The server itself is unaffected.** Websites, email, and services running on the VPS carry on as normal, and no reboot is needed. Nothing is interrupted by a panel password change.
- **Existing API keys stay valid.** If anything automated talks to Virtualizor using an API key, that key is a separate credential and is not rotated here. Rotate it separately if the account may have been compromised.
## Choosing a Password That Holds Up
Panel logins are exposed to the internet and see automated guessing attempts constantly, so treat this credential seriously:
- Use at least 16 characters, generated at random rather than composed by hand.
- Never reuse a password that protects anything else, and in particular never reuse the VPS root password here.
- Store it in a password manager rather than a note or a spreadsheet.
- Pair it with two-factor authentication, which is the single biggest improvement you can make to panel security. See [How to Enable or Disable the VPS Login Alert in Virtualizor](/solusvm/how-to-enable-or-disable-the-solusvm-vps-login-alert/) for how to switch it on.
## Troubleshooting
**The new password is rejected as too weak**: Virtualizor enforces a minimum complexity rule. Add length and mix character types, and avoid dictionary words, your domain name, and anything based on your username.
**There is no Account Password tab on My Profile**: on some deployments the panel administrator restricts self-service password changes. Contact Noiz support and the password can be reset for you.
**You cannot log in to change the password**: this procedure needs a working session, so it cannot help you recover a forgotten password. Open a support ticket from your Noiz client area and the support team will verify your identity and issue a reset.
**The change appeared to work but the new password fails**: this is almost always the browser autofilling the old value. Clear the saved credential for the panel, type the new password manually, and try again in a private browsing window to confirm.
**You changed the panel password but can still not reach the server over SSH**: SSH uses the operating system password, not the panel password. Change the root password instead, using the article linked above.
## Need a Hand?
If you are on a Noiz managed VPS plan, or you believe your panel account has been accessed by somebody else, open a support ticket from your [Noiz client area](https://www.noiz.co.za). The support team can reset the panel password, help you rotate the server credentials, and check the account for signs of unauthorised access.
# How to Change the Disk Driver to Virtio or IDE in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-change-the-disk-driver-to-virtio-or-ide-in-virtualizor/
This guide shows you how to switch the disk driver of your VPS between Virtio and IDE from the Virtualizor end user panel. The disk driver, sometimes called the disk bus or storage controller, is the virtual hardware interface your operating system uses to talk to its disk. Virtio is a paravirtualised driver that gives much better disk performance, while IDE is plain emulated hardware that almost every operating system supports out of the box. This article is for Noiz VPS customers who manage their server through the Virtualizor control panel.
**Last reviewed:** 27 July 2026, against Virtualizor **3.2.9** (latest stable). This article describes the **Enable Virtio** setting on the **VPS Configuration** page of the Virtualizor end user panel; Virtualizor does not publish a single dedicated procedure for this task, so the steps below are assembled from the official end user guides and the end user API reference. Virtualizor releases frequently, so always cross-reference the current version of the official documentation before starting; direct links to every section used in this guide are provided below.
### Official Documentation Reference
- [Virtualizor End User Guide: List VPS](https://www.virtualizor.com/docs/enduser/list-vps/)
- [Virtualizor End User Guide: Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps/)
- [Virtualizor End User API Reference: VPS Configuration (HVM Settings)](https://www.virtualizor.com/docs/enduser-api/vps-configuration/)
- [Virtualizor End User Guide: Re-Install OS](https://www.virtualizor.com/docs/enduser/re-install-os/)
- [Virtualizor Admin Guide: Manage VPS (full disk driver options, provider side)](https://www.virtualizor.com/docs/admin/manage-vps/)
## Prerequisites
- A Noiz VPS running on KVM virtualisation. The disk driver setting does not apply to container-based VPS products.
- Your Virtualizor end user panel address and login details, sent in your Noiz VPS welcome email.
- A recent backup of any important data on the VPS, in case you need to reinstall the operating system.
## Virtio or IDE: Which Should You Choose?
Choose the driver based on what your operating system supports:
- **Virtio** is the recommended choice for performance. Modern Linux distributions include Virtio support in the kernel by default, so the standard Noiz Linux templates work with Virtio immediately. Windows does not ship with Virtio drivers, so a Windows VPS only boots with Virtio if the Virtio drivers were installed inside Windows first.
- **IDE** is slower but universally compatible. Use it when your operating system has no Virtio drivers, for example an older or custom Windows installation, or an appliance image you imported from elsewhere.
The best time to change the disk driver is **before** you install or reinstall the operating system. If you switch an already installed system from IDE to Virtio and the system has no Virtio drivers, the VPS will fail to boot until you switch back or reinstall.
In the Virtualizor end user panel this choice is a single checkbox called **Enable Virtio** rather than a drop-down list: ticked means your VPS uses Virtio, unticked means it uses emulated IDE hardware. Enabling Virtio also switches the virtual network card to Virtio, as noted in the panel's own help text for the network interface type setting. Other disk driver types, such as SATA or SCSI, can only be set on the provider side, so open a support ticket with the Noiz support team if you specifically need one of those.
## How to Change the Disk Driver
### Step 1: Log in to the Virtualizor End User Panel
1. Open the panel address from your Noiz VPS welcome email in a browser. It has the form `https://panel.yourdomain.com:4083`, where `panel.yourdomain.com` is an example you should replace with the address in your welcome email.
2. Enter your username and password, then sign in.
### Step 2: Open the Management Page for Your VPS
1. In the left-hand menu, click **List VPS**.
2. Hover over the VPS you want to change; the row is highlighted. If you have only one VPS, there is a single row.
3. Click the **Manage** icon at the end of the highlighted row. Depending on the panel theme, this is drawn as a wrench or as an arrow next to the VPS ID.
### Step 3: Open VPS Configuration
1. On the VPS management page, click the **Settings** tab.
2. Select **VPS Configuration**.
### Step 4: Set the Disk Driver
1. On the **VPS Configuration** page, find the **Enable Virtio** checkbox.
2. Tick **Enable Virtio** to use the Virtio disk driver, or untick it to use IDE.
3. Leave the other options, such as **Boot Order** and **Select ISO**, as they are unless you have a reason to change them.
4. Click **Submit**.
### Step 5: Reboot the VPS
1. Return to the VPS management page and click the **Reboot** icon, then confirm.
2. Wait a minute or two, then check that the VPS status shows as online and that you can reach your services.
The new disk driver only takes effect after this reboot. If you changed the driver in preparation for a fresh operating system installation, run the reinstall now so the installer detects the disk on the new driver from the start.
## Troubleshooting
**The VPS does not boot after enabling Virtio**: your operating system has no Virtio drivers installed. Go back to **Settings**, then **VPS Configuration**, untick **Enable Virtio**, click **Submit** and reboot. To move to Virtio permanently, either install the Virtio drivers inside the operating system first (required for Windows) or reinstall the operating system with Virtio enabled.
**You cannot see the VPS Configuration page or the Enable Virtio checkbox**: these settings can be hidden on the provider side, and they are not shown for container-based VPS products. Open a support ticket with the Noiz support team and the change can be made for you.
**The panel reports that the VPS is in rescue mode and cannot be changed**: VPS Configuration is locked while rescue mode is active. Disable rescue mode from the VPS management page, then repeat the steps above.
**Disk performance is still poor after switching to Virtio**: confirm the operating system is actually using the Virtio device. On Linux, Virtio disks appear as `/dev/vda` rather than `/dev/sda` or `/dev/hda`; run `lsblk` to check. If the disk still shows as an IDE device after a reboot, the change did not apply, so submit the form again and reboot.
If you are unsure which driver your operating system supports, or your VPS will not boot after a change, open a support ticket with the Noiz support team and include your VPS hostname and the driver you were switching to.
# How to Change the Network Card to Virtio, Intel PRO, or Realtek in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-change-the-network-card-to-virtio-intel-pro-or-realtek-in-virtualizor/
This guide shows you how to change the virtual network card on your VPS using the Virtualizor end-user panel. The network card is sometimes called the network interface card (NIC), network adapter, or network driver: it is the emulated hardware your VPS operating system uses to reach the network. Virtualizor lets you switch between several card types, including **Virtio**, **Intel E1000** (the emulated Intel PRO/1000 adapter) and **Realtek 8139**. Switching cards is most often needed when an operating system does not have a driver for the current card, or when you want the better network performance that Virtio offers.
**Last reviewed:** 27 July 2026, against Virtualizor **3.2.9** (latest stable). This article reproduces the official Virtualizor procedure for changing the network card of a VPS from the end-user panel. Virtualizor releases frequently, so always cross-reference the current version of the official documentation before starting. Direct links to every section used in this guide are provided below.
### Official Documentation Reference
- [Virtualizor End User panel: Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps/): how to open the VPS management page
- [Virtualizor End User panel: Enduser ISO](https://www.virtualizor.com/docs/enduser/end-user-iso/): documents the VPS Configuration screen and the stop-start requirement
- [Virtualizor End User API: VPS Configuration](https://www.virtualizor.com/docs/enduser-api/vps-configuration/): the full list of network card types the panel offers
- [Virtualizor FAQ: DHCP and network driver issues](https://www.virtualizor.com/docs/faq/dhcp-issues/): official guidance on Virtio drivers for Windows and the Intel E1000 fallback
- [Virtualizor End User panel: VNC](https://www.virtualizor.com/docs/enduser/vnc/): console access that works even when the VPS has no network
- [Virtualizor 3.2.9 stable release announcement](https://www.virtualizor.com/blog/virtualizor-3-2-9-launched-in-stable/)
## Prerequisites
- A KVM-based VPS managed through Virtualizor. Container-based virtualisation does not use an emulated network card, so this option does not apply there.
- Your Virtualizor end-user panel address and login details, which are in your Noiz welcome email.
- A maintenance window of a few minutes: the VPS must be stopped and started for the new card to take effect.
- If you plan to switch a Windows VPS to Virtio: the Virtio network drivers must be installed inside Windows first. See the Windows section below.
## Which Network Card Should You Choose?
The **Network Card** drop-down in Virtualizor lists the following options, exactly as named in the official documentation:
- **Realtek 8139(default)**: the standard emulated card. Almost every operating system, including very old ones, ships with a driver for it, but it is the slowest option.
- **Virtio**: a paravirtualised card with the best network performance and lowest overhead. Modern Linux distributions support it out of the box. Windows needs the Virtio drivers installed before you switch.
- **Intel E1000**: emulates the widely supported Intel PRO/1000 gigabit adapter. A good middle ground: Windows and Linux recognise it without extra drivers, and Virtualizor officially recommends it as the fallback when Virtio drivers cannot be installed.
- **Novell NE2000**, **Intel i82559er**, **AMD PCNET** and **Novell E2000 ISA**: legacy cards for old operating systems. Only choose these if you know your OS specifically needs one of them.
For most Linux servers, choose `Virtio`. For Windows without Virtio drivers, or any OS that fails to detect the current card, choose `Intel E1000`.
## Change the Network Card
### Step 1: Open the VPS Management Page
1. Log in to your Virtualizor end-user panel. The address is in your Noiz welcome email and looks like `https://vps.yourdomain.com:4083` (this is an example only, replace it with the address you were given).
2. Click **List All** to display your VPS list.
3. Click the arrow shown next to the **VPS ID** of the server you want to change. This opens the VPS management page.
### Step 2: Open VPS Configuration
1. On the VPS management page, select the **VPS Configuration** option. This screen also holds the boot order and ISO settings for your VPS.
### Step 3: Select the New Network Card
1. Find the **Network Card** drop-down menu.
2. Select the card you want, for example `Virtio` or `Intel E1000`.
3. Save the configuration.
### Step 4: Stop and Start the VPS
1. From the panel, **Stop** the VPS and wait for it to power off completely.
2. **Start** the VPS again.
A full stop and start is required so the VPS is rebuilt with the new virtual hardware. A reboot issued from inside the operating system is not always enough, because the virtual machine itself is not recreated.
## Installing Virtio Drivers on a Windows VPS
Windows does not include Virtio network drivers, so install them before switching the card to Virtio. This is the procedure from the official Virtualizor FAQ:
1. Download the official Virtio driver ISO, linked from the [virtio-win driver documentation](https://docs.fedoraproject.org/en-US/quick-docs/creating-windows-virtual-machines-using-virtio-drivers/).
2. On the **VPS Configuration** screen, attach the driver ISO as the **secondary ISO**, then stop and start the VPS. If you cannot add your own ISOs, ask the Noiz support team to attach the driver ISO for you.
3. Inside Windows, open **Device Manager**, right-click the network adapter showing a warning mark and choose to update or install its driver.
4. Browse to the mounted ISO, choose the `NetKVM` folder, then the folder matching your Windows version and architecture, and complete the installation.
5. Switch the network card to `Virtio` as described above, then stop and start the VPS.
## Troubleshooting
**Symptom: no network after switching to Virtio.** The operating system has no Virtio driver. Use the panel's **VNC** console to check: on Windows the network adapter appears in Device Manager with a warning mark. Either install the Virtio drivers as described above, or switch the card back to `Intel E1000` and stop and start the VPS. This fallback is the official Virtualizor recommendation.
**Symptom: the change does not seem to take effect.** The VPS was probably rebooted from inside the operating system rather than stopped and started from the panel. Stop the VPS, wait for it to power off fully, then start it again.
**Symptom: there is no VPS Configuration option on the management page.** This option only appears when it has been enabled for your service, and it does not exist for container-based VPS products. Open a support ticket and the Noiz team will change the card for you from the administrative side.
**Symptom: you cannot reach the VPS at all after the change.** Use the **VNC** option in the panel, which gives you console access without needing a working network connection, and revert the card to its previous setting if necessary.
If you are on a Noiz managed VPS plan, you do not need to do this yourself: contact the Noiz support team and the change will be made for you. If you are self-managed and get stuck at any step, open a support ticket with the Noiz support team and include your VPS ID and the card type you are trying to use.
# How to Change the VNC Password in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-change-the-vnc-password-in-virtualizor/
This guide shows you how to change the **VNC password** on a VPS from **Virtualizor**, the panel Noiz VPS clients use to manage their servers. The VNC password protects the virtual console attached to your server, the out-of-band screen and keyboard you fall back on when SSH or Remote Desktop will not let you in.
**Important:** this is not your Virtualizor login password and it is not the root or administrator password of the operating system on the VPS. Three separate credentials are in play and they are easy to confuse, so the section [Which Password Is This?](#which-password) below sets them apart before you change anything.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end-user panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor End User: VNC Password](https://www.virtualizor.com/docs/enduser/vnc-password/)
- [Virtualizor End User: VNC](https://www.virtualizor.com/docs/enduser/vnc/)
- [Virtualizor End User: VPS Management](https://www.virtualizor.com/docs/enduser/vps-management/)
## Prerequisites
- Your Virtualizor end-user panel URL and login details, which are in your Noiz VPS welcome email.
- An active Noiz VPS running on hardware virtualisation. The VNC console, and therefore the VNC password, is a KVM feature.
- A short maintenance window, because the new password only becomes live once the VPS is power cycled.
## Which Password Is This?
Most support tickets about this task are really a case of the wrong password being changed. Three credentials sit around a Noiz VPS and each one opens a different door.
- **The VNC password** is what this guide changes. It belongs to the virtual console device on the virtual machine, so it lives on the host node beside the VPS configuration rather than inside your operating system. Changing it has no effect on anything running on the server.
- **Your Virtualizor panel password** signs you in to the management panel itself, where you can reboot, reinstall and reconfigure the VPS. Change it in [How to Change Your Virtualizor Account Password](/virtualizor/how-to-change-your-virtualizor-account-password/).
- **The root or administrator password** is the operating system credential you use over SSH or Remote Desktop, and the one you type at the console login prompt once VNC has connected. Change it in [How to Change the VPS Root or Admin Password in Virtualizor](/virtualizor/how-to-change-the-vps-rootadmin-password-in-virtualizor/).
The practical distinction: the VNC password gets you a picture of the screen, and the root password gets you logged in to what is on it. If you can see a login prompt but cannot get past it, the VNC password is working perfectly and the problem is the operating system credential.
## Change the VNC Password
1. Log in to your Virtualizor end-user panel.
2. From the left-hand menu, click **List VPS**. 
3. Hover over the row for the VPS you want to change. The row highlights. Click the **Manage** icon on that row. 
4. Open the **Settings** tab and choose **VNC Password**. 
5. Type the new password, type it again to confirm, and click **Change VNC Password**. Virtualizor confirms that the VNC password has been changed successfully. 
6. Power cycle the VPS. Use **Restart** from the panel, or **Stop** followed by **Start**. The console is configured when the virtual machine is built at boot, so the new password becomes live at the next start and not before.
## The Gotchas Worth Knowing
- **Eight characters is the practical limit.** Classic VNC authentication is built around an eight byte key, so a great many hypervisor and viewer combinations only ever check the first eight characters of what you typed. A twenty character password is not twenty characters of protection, and worse, it can behave inconsistently depending on which client you connect with. Set exactly eight characters, make them random, and treat the console password as a single-purpose credential rather than something you reuse.
- **A reboot from inside the operating system is not enough.** Running `reboot` over SSH restarts the guest, but the virtual machine keeps running with the console definition it was created with. Stop and start it, or restart it from Virtualizor, so the machine is built again from its configuration.
- **Changing it does not kick anyone off.** A console session that is already connected stays connected until the power cycle. If you are changing the password because you think someone else has it, the reboot is the part that actually ends their access, so do not leave it until later.
- **You rarely type this password yourself.** When you launch the console from inside Virtualizor, the panel authenticates the session for you. The password matters when a client asks for it directly, which is why a stale or mistyped one often shows up as nothing more useful than a console that refuses to connect.
- **Reinstalling the operating system will not reset it.** The credential belongs to the virtual machine configuration on the host node, not to anything inside the guest, so wiping and rebuilding the server leaves the VNC password exactly as it was. If you have lost it, set a new one here instead of reinstalling.
- **It is a hardware virtualisation feature.** Virtualizor documents the VNC password for KVM. On container-based virtualisation there is no emulated graphics device to attach a console to, so the option will not be on the screen at all. That is normal rather than a fault.
- **The console still sits behind your panel login.** Changing the VNC password hardens one layer. If your Virtualizor account password is weak or shared, the console is reachable regardless, so treat the two as a pair.
## Troubleshooting
**Symptom**: the password saved but the console still accepts the old one. The VPS has not been power cycled since the change, or it was rebooted from inside the operating system. Restart it from Virtualizor.
**Symptom**: the new password is rejected by an external VNC viewer. The password is almost certainly longer than eight characters and the viewer is sending a truncated version of it. Set an eight character password and power cycle again.
**Symptom**: the **VNC Password** option is not under **Settings**. Either the VPS is on a virtualisation type without a virtual console, or VNC is switched off for the machine. Check the VNC tick box first, as covered in [How to Enable or Disable APIC, ACPI and VNC in Virtualizor](/virtualizor/how-to-enable-or-disable-apic-acpi-and-vnc-in-virtualizor/).
**Symptom**: the console connects and then shows a black screen. The password worked. That is usually a healthy server whose console has blanked after boot, so press `Enter` and wait for the login prompt to redraw.
**Symptom**: the console connects but the login is refused. The VNC password is doing its job and the operating system credential is the one at fault. Reset the root or administrator password instead.
## Related Guides
- [How to Access Your VPS via the VNC Console in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/)
- [How to Change the VPS Root or Admin Password in Virtualizor](/virtualizor/how-to-change-the-vps-rootadmin-password-in-virtualizor/)
- [How to Change Your Virtualizor Account Password](/virtualizor/how-to-change-your-virtualizor-account-password/)
## Need a Hand?
If the VNC password will not save, the option is missing from the **Settings** tab, or the console still refuses to connect after a power cycle, open a support ticket from your [Noiz client area](https://www.noiz.co.za). The support team can check the virtual machine definition on the host node and confirm what the VPS was actually built with.
# How to Change the VPS Root/Admin Password in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-change-the-vps-rootadmin-password-in-virtualizor/
Your Noiz VPS has two or three separate passwords, and this article covers only one of them: the **root (or Administrator) password of the operating system running inside the VPS**. That is the credential you use for SSH, for console logins, and for anything that asks you to authenticate as the server's superuser. Virtualizor can reset it for you from the outside, which means you can recover access even when you have lost the password entirely and cannot log in to the VPS at all.
**Last reviewed:** 27 July 2026, against the current Virtualizor release. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor Docs: Change Root Password](https://www.virtualizor.com/docs/enduser/change-root-password) (the vendor's reference for this feature, including the OpenVZ and KVM/Xen behaviour difference)
- [Virtualizor Docs: Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps) (a tour of the management page these steps are performed on)
- [Virtualizor Docs: List VPS](https://www.virtualizor.com/docs/enduser/list-vps)
## Know Which Password You Are Changing
This is the single most common source of confusion, so it is worth thirty seconds before you start. Changing the wrong one will not lock you out, but it will not solve your problem either.
- **The VPS root/Administrator password** (this article). Lives inside the server's operating system. Used for SSH, for the VNC console login prompt, and for `sudo` or Administrator access. Virtualizor rewrites it on the VPS disk on your behalf.
- **Your Virtualizor account password.** Lives in the Virtualizor panel itself and is what you type to log in to Virtualizor. It has nothing to do with the operating system on the VPS. See [How to Change Your Virtualizor Account Password](/virtualizor/how-to-change-your-virtualizor-account-password/).
- **The VNC password.** Protects the remote console session before the operating system's own login prompt appears. It is separate again. See [How to Change the VNC Password in Virtualizor](/virtualizor/how-to-change-the-vnc-password-in-virtualizor/).
If you can log in to Virtualizor but not to the server, you want this article. If you cannot log in to Virtualizor at all, you want article 4949 instead.
## Prerequisites
- Access to your Virtualizor control panel, with the login details supplied by Noiz when the VPS was provisioned.
- A maintenance window of a few minutes. On KVM and Xen virtualisation the new password only takes effect after the VPS is power cycled, so any sites or services running on it will be briefly offline.
- A new password chosen in advance. Root is the most attacked account on any internet-facing server, so make it long and random rather than memorable.
## Change the Root Password in Virtualizor
### Step 1: Open the VPS list
Log in to your Virtualizor control panel, then click **List VPS** in the left-hand menu.

### Step 2: Open the VPS management page
Hover over the row for the VPS you want to change. The row highlights, and a set of action icons becomes available. Click the **Manage** icon on that row.

If more than one VPS is listed on your account, confirm you have the right one before going further. Match the hostname or the primary IP address rather than relying on list order, which can change.
### Step 3: Open the Change Password panel
On the VPS management page, click **Settings**, then choose **Change Password**.

### Step 4: Enter and apply the new password
Type the new root password, then confirm by clicking **Change Password**.

Virtualizor will report success straight away. On KVM and Xen this success message means the change has been accepted and queued, not that it is live yet. Do not close the panel and assume you are finished. Continue to step 5.
### Step 5: Power off the VPS
At the top right of the management page, choose **Poweroff**.

### Step 6: Start the VPS again
Once the VPS shows as stopped, click **Start**.

Booting typically takes a minute or two, sometimes longer on a larger server. When it is back up, log in over SSH or the console with the new password.
## Why the Power Cycle Is Required
On OpenVZ containers the new root password applies immediately and no restart is needed. On KVM and Xen, which is what most modern VPS platforms use, Virtualizor cannot reach inside a running guest operating system to edit its password file. Instead it writes the change to the VPS disk from the host side and applies it as the machine comes back up. Until that happens, the old password is still the live one.
This is also why you should do the stop and start *from Virtualizor*. Running `reboot` or `shutdown -r` from inside the VPS is a guest-initiated restart and will not necessarily trigger the host-side step that applies the queued password. If you have already rebooted from the command line and the new password still does not work, perform a proper **Poweroff** followed by **Start** in the panel and try again.
The related power controls are covered in more detail in [How to Force or Gracefully Shut Down a VPS in Virtualizor](/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/) and [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/).
## Choosing a Root Password That Holds Up
Every VPS with a public IP address gets automated SSH login attempts against `root` within hours of coming online. That is normal background noise on the internet, but it means a weak root password is found quickly rather than eventually.
- Use at least 16 characters, generated randomly, and store it in a password manager rather than a note or a spreadsheet.
- Do not reuse the password from your Virtualizor account, your Noiz client area, or any hosting control panel on the server. Those are separate systems and a breach of one should not hand over the others.
- Avoid the domain name, the hostname, the company name, or the year. Those are the first things a dictionary attack tries.
- Better still, once you are back in, add an SSH key and disable password authentication for `root` altogether. A key cannot be guessed, and you keep the root password purely as a console fallback for the day SSH is unavailable.
## Troubleshooting
**Symptom**: the new password is rejected after the restart. Confirm the VPS actually stopped and started rather than only rebooting, then retry. Also check for a stray leading or trailing space picked up when the password was pasted into the form, and confirm your keyboard layout matches at the login prompt, which catches out anyone typing symbols on a non-UK layout through a console.
**Symptom**: the password was accepted but the VPS did not come back up. Open the console and watch it boot so you can see where it stops. See [How to Access Your VPS via the VNC Console in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/). A VPS that fails to boot is a separate fault from the password change and needs diagnosing on its own.
**Symptom**: the console asks for a password before you reach the operating system's login prompt. That is the VNC password, not the root password. Reset it using article 4959.
**Symptom**: the form saves but nothing changes, on a VPS where SSH key authentication is already enforced. The root password has genuinely been reset; SSH is simply refusing password logins by policy. Use your key, or connect through the console where the password does apply.
**Symptom**: **Change Password** is missing or greyed out. The option can be restricted at the plan level, or the VPS may be suspended. Contact Noiz support and the password can be reset for you.
## Getting Help From Noiz
If you are locked out of the server and the reset is not taking effect, open a ticket from your Noiz client area with the VPS hostname or IP address and a note of what you have already tried. Noiz support can verify the password change from the host side and confirm whether the VPS is booting correctly. If your VPS is on a managed plan, Noiz can perform the reset and the restart for you at a time that suits your traffic.
# How to Check VPS Online/Offline Status in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-check-vps-onlineoffline-status-in-virtualizor/
This guide shows you how to tell at a glance whether a VPS is powered on or powered off, using **Virtualizor**, the panel Noiz VPS clients use to manage their servers. It also explains what the status indicator really measures, because "online" in Virtualizor answers a narrower question than most people expect.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end-user panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor End User: List VPS](https://www.virtualizor.com/docs/enduser/list-vps)
- [Virtualizor End User: VPS Management](https://www.virtualizor.com/docs/enduser/vps-management)
## Prerequisites
- Your Virtualizor end-user panel URL and login details, which are in your Noiz VPS welcome email.
- An active Noiz VPS service. A cancelled or terminated service no longer appears in the panel at all.
## Check the Status in Virtualizor
1. Log in to your Virtualizor end-user panel.
2. From the left-hand menu, click **List VPS**. 
3. Each VPS in the list has a small coloured circle beside it, just under the **refresh** icon. A **green circle** means the VPS is **online** (powered on). A **red circle** means it is **offline** (powered off or stopped). 
4. Click the **refresh** icon to poll the server again and update the indicator.
The indicator is a snapshot from the last poll, not a live feed. If you have just started, stopped or rebooted the VPS, give it a few seconds and click **refresh** rather than trusting the colour that was already on screen.
## What Green and Red Actually Mean
The status circle reports one thing only: whether the virtual machine is running on the host node. It is the equivalent of asking whether a physical server's power light is on.
- **Green does not mean your website or services are working.** A VPS can be powered on and reachable while the web server, database or mail service inside it has crashed, or while the operating system has failed part-way through boot. If the panel shows green but nothing responds, the fault is inside the VPS, not at the power level.
- **Red means the machine is not running.** Nothing inside it is reachable, including SSH, so the fix has to come from the panel or from Noiz support, never from inside the server.
- **A suspended VPS shows as offline.** Suspension is applied outside the VPS and powers it off, so the red circle is expected and starting it from the panel will not stick until the suspension is lifted.
## Client Area Status Is Not the Same as Power Status
Your Noiz client area shows a status against the VPS service itself, such as **Active**, **Suspended** or **Cancelled**. That is a billing and provisioning state. It tells you the standing of the account, not whether the machine is switched on. A service can sit at **Active** in the client area while the VPS is powered off in Virtualizor, and both readings are correct.
Use the client area to confirm the service is in good standing and to reach the panel or open a ticket. Use Virtualizor for the power state. When the two disagree in a way you cannot account for, and particularly when the service reads **Suspended**, the client area is the place to check for an unpaid invoice.
## Troubleshooting
**The VPS shows offline and you did not stop it**: the most common cause is a shutdown issued from inside the server. Running `shutdown -h now`, `poweroff` or `halt` over SSH powers the machine off and it will not come back on its own, because there is nothing left running to bring it up. Start it again from Virtualizor. Use `reboot` when you want the server to come back.
**It went offline on its own**: check whether the VPS ran out of memory, whether an automatic update triggered a shutdown rather than a reboot, and whether the service is suspended for an unpaid invoice. If none of those apply, open a ticket so Noiz can check the host node.
**The status will not change after you click start**: refresh the page rather than only the indicator, then check for a queued task in the panel. A start that immediately reverts to offline usually means the VPS is suspended, or that the operating system is failing at boot and needs console access to diagnose.
**Green circle, but the site is down**: the machine is up and the problem is a service inside it. Connect over SSH and check the web server, database and disk space before assuming anything is wrong with the VPS itself.
## Need a Hand?
If a VPS is stuck offline, will not start, or shows a status you cannot explain, open a support ticket from your [Noiz client area](https://www.noiz.co.za/clientarea.php). The support team can check the host node, confirm the true power state and start the server for you.
# How to Check VPS RAM, IP, Disk Capacity, and Virtualization Type in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-virtualizor/
Every VPS has a set of numbers attached to it: how much RAM it was given, how much disk it has and how much of that is used, which IP addresses belong to it, how much bandwidth it has consumed this cycle, and which virtualisation technology it runs on. All of that lives in the Virtualizor end user panel, and you do not need to log in to the server itself to read any of it.
This guide shows you where each figure is, what the **Type** column actually means for what you are allowed to do inside your VPS, and how to interpret the numbers so they match what you see when you log in to the operating system.
The virtualisation type matters more than most people expect. It decides whether you can run Docker, install a VPN, load a kernel module, or ask for a different operating system. Check it before you buy software that depends on any of those.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end user panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor Docs: List VPS](https://www.virtualizor.com/docs/enduser/list-vps)
- [Virtualizor Docs: Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps)
- [Virtualizor Docs: VM IP management](https://www.virtualizor.com/docs/enduser/vm-ip-management)
## Prerequisites
- An active Noiz VPS, and the Virtualizor end user login details supplied when the server was set up.
- The Virtualizor end user panel address for your server. It runs on its own port, separate from the admin panel, so it is not reachable on the usual web address. See [How to Log in to Virtualizor Control Panel](/virtualizor/how-to-log-in-to-the-virtualizor-vps-control-panel/) if you are not sure.
- Nothing needs to be installed and the VPS does not need to be running. These figures are readable whether the server is online or powered off.
## Check the Virtualisation Type from the VPS List
1. Log in to your Virtualizor end user panel.
2. In the left sidebar, click **List VPS**. On some builds this is shown as **List All** or sits under a **Virtual Servers** heading, but it is the same page. 
3. The list shows one row per VPS on your account. The **Type** column is the virtualisation technology your server runs on, usually `KVM` or `OpenVZ`, and sometimes `LXC`, `Xen` or `Proxmox` depending on the platform the server was built on. The same row also shows the VPS ID, its hostname, its primary IP address, and whether it is currently running or suspended. If you have a long list, the search filters at the top of the page let you narrow it by ID, IP address, hostname, status or type. 
## Open the VPS to See RAM, IP, Disk and Bandwidth
4. Click the VPS you want to inspect. If your account holds several, check the hostname and IP in the row before you click, because the management pages that follow act on whichever server you opened. If your account holds only one VPS, Virtualizor may take you straight to its management page when you log in and you will not see the list at all. That is normal. 
5. The **VPS Information** panel on the management page carries the full specification: allocated RAM, allocated and used disk space, CPU cores and CPU allocation, the primary IP address and any additional addresses, the hostname, the operating system template, and bandwidth used against the allowance for the current cycle. 
## What the Virtualisation Type Means for You
This is the one field on the page with real consequences, so it is worth understanding rather than just noting.
### KVM, Xen and other full virtualisation
A KVM server is a full virtual machine. It boots its own kernel, exactly as a physical machine would, and the resources allocated to it are its own.
- You can replace or upgrade the kernel, load kernel modules, and run anything that needs them: Docker, WireGuard, OpenVPN, full `nftables` or `iptables` rulesets, custom filesystems.
- You can install effectively any operating system, including Windows and the BSDs, and you can boot from an ISO image.
- Memory is dedicated. What the panel says you have is what the operating system sees, and tools such as `free -h` report your VPS rather than the host.
- You get a real console over VNC, so you can recover a server that has lost network connectivity.
If you have a choice and you intend to run containers, a VPN, or anything that touches the kernel, KVM is the type you want.
### OpenVZ, LXC and other container virtualisation
An OpenVZ or LXC server is a container. It shares the host machine's kernel instead of booting its own, which makes it lighter and quicker to provision, but it also draws some hard limits.
- You cannot change the kernel or load kernel modules. Anything that depends on a module the host does not already provide will not run.
- Docker, some VPN software, and firewall rules relying on less common netfilter modules may be unavailable or restricted.
- Only Linux templates are offered. There is no Windows and no BSD on a container.
- Memory reporting can be confusing. Depending on the platform, `free` and `top` inside the container may reflect the host machine rather than your own allocation, so the panel figure is the one to trust for what you are entitled to.
- Swap behaves differently or may not exist at all, so a memory spike that a KVM server would survive by swapping can instead end in the process being killed.
None of that makes a container a poor choice. For a straightforward web or application server it is efficient and perfectly capable. It only becomes a problem when software further down the line assumes kernel access, which is why checking the type first saves an afternoon.
If you are not certain which type suits what you are planning, ask Noiz support before you build the server rather than after. Changing virtualisation type means rebuilding on a different platform, not flipping a setting.
## Reading the Numbers Correctly
- **Disk usage in the panel can lag.** Virtualizor polls usage on a schedule rather than continuously, so the figure may be minutes or longer behind reality. If you are actively deleting files to free space, `df -h` inside the VPS is the live answer and the panel will catch up.
- **Panel disk usage and `df -h` will not match exactly.** On KVM the panel measures the whole virtual disk image, which includes the swap partition, filesystem overhead and space reserved for the root user. Your own view from inside sees only the mounted filesystem. A gap of a few per cent is expected, not a fault.
- **RAM shown inside the VPS is usually slightly under the allocation.** The kernel and firmware reserve a little at boot. Losing a few tens of megabytes off the figure is normal.
- **Bandwidth is per cycle, not lifetime.** The counter resets at the start of each billing cycle. If the number looks alarmingly high, check how far into the cycle you are before drawing conclusions.
- **The primary IP is the one that matters for DNS and mail.** Additional addresses are listed alongside it. Reverse DNS is normally set on the primary, so use that one when pointing a hostname or configuring outbound mail.
- **Never set an IP inside the operating system that is not listed here.** The addresses assigned in Virtualizor are the only ones routed to your VPS. Typing a different address into the network configuration will take the server off the network, and recovering it then means a VNC console session.
- **Hostname is recorded in two places.** The hostname Virtualizor shows is its own record of the server. Changing it inside the operating system does not update Virtualizor, and updating it in Virtualizor pushes the change into a running VPS only where the template supports it. Keep the two in step deliberately.
## Troubleshooting
- **Symptom**: the **Type** column is blank or shows something unfamiliar. Some builds label containers `OpenVZ 7` or `LXC` and full virtual machines `KVM`, `Xen`, `XenServer` or `Proxmox`. If the column is genuinely empty, the panel has lost contact with the host node. Open a ticket rather than acting on the blank.
- **Symptom**: there is no **List VPS** entry in the sidebar. You are on a single VPS account and Virtualizor has opened the server directly, or you have logged in to the admin panel rather than the end user panel. The two run on different ports.
- **Symptom**: disk shows nearly full but you cannot find the files. Look at logs and old backups first, usually under `/var/log` and `/var/backups`, then at package caches. On a KVM server also check whether the filesystem has run out of inodes with `df -i`, which fills up independently of space and produces the same "no space left" errors.
- **Symptom**: the panel says the VPS has more RAM than the operating system reports. Expected on a container, where the reporting tools may not be container-aware, and expected in a small way on KVM because of boot-time reservation. Trust the panel for entitlement.
- **Symptom**: bandwidth is climbing with no traffic you recognise. Backups leaving the server, package updates, and bot or scanner traffic all count. If the rise is sudden and large, treat it as a possible compromise and contact Noiz support.
- **Symptom**: the figures look stale across the whole page. Refresh the page rather than relying on the cached view, and if it persists the statistics collection on the host may have stalled. Support can force a refresh from the master server.
## Related Guides
- [How to Log in to Virtualizor Control Panel](/virtualizor/how-to-log-in-to-the-virtualizor-vps-control-panel/)
- [How to Check Whether the VPS Status is Online or Offline in Virtualizor](/virtualizor/how-to-check-vps-onlineoffline-status-in-virtualizor/)
- [How to Change Hostname in Virtualizor](/virtualizor/how-to-change-your-vps-hostname-in-virtualizor/)
- [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/)
## Need a Hand?
If the specification in the panel does not match what you ordered, if you need more RAM or disk on an existing VPS, or if you are unsure whether your virtualisation type will support a piece of software before you commit to it, open a ticket from your Noiz client area. Include the VPS hostname or IP address and what you are trying to run, and the support team will confirm what the server can do and what an upgrade would involve.
# How to Delete the Self-Shutdown Timer in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-delete-the-self-shutdown-timer-in-virtualizor/
A self-shutdown timer tells Virtualizor to power your VPS down at a scheduled time. When you no longer want that to happen, you delete the timer. This guide shows you how to remove a self-shutdown timer from a VPS in the Virtualizor end-user panel, and explains what deleting the timer does and does not change.
Deleting is the right choice when you want the schedule gone entirely. If you only want to move the time or change the action, edit the existing timer instead of deleting and rebuilding it.
**Last reviewed:** 27 July 2026, against the current Virtualizor release. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor documentation: Self Shutdown](https://www.virtualizor.com/docs/enduser-api/self-shutdown/)
- [Virtualizor documentation: Delete Self Shutdown](https://www.virtualizor.com/docs/enduser-api/delete-self-shutdown)
- [Virtualizor documentation: Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps)
- [Virtualizor documentation: End User panel guide](https://www.virtualizor.com/docs/enduser)
## Prerequisites
- Your Virtualizor end-user login details, supplied by Noiz when the VPS was provisioned.
- At least one self-shutdown timer already set on the VPS. If none exists, there is nothing to delete.
- The name or IP address of the VPS you are working on, so you delete the timer on the right machine.
## Deleting a Self-Shutdown Timer
1. Log in to your Virtualizor control panel.
2. From the left side panel, click **List VPS**. 
3. Hover your mouse over the appropriate VPS so that its row is highlighted, then click the **Manage** icon in that row. 
4. Click **Self Shut Down**. 
5. If more than one timer is listed, hover over the one you want to remove so that its row is highlighted, then click the **Delete** button in that row. 
6. Confirm with **OK** when prompted. The timer disappears from the list and no longer runs.
## What Deleting a Timer Actually Changes
Reading the deletion correctly saves a support ticket later, so it is worth being precise about it.
- **It cancels a future action, not a past one.** Deleting the timer stops the scheduled shutdown from happening again. It does not power a VPS back on that the timer has already shut down. If the server is already off, start it from the VPS management screen.
- **The VPS itself is untouched at the moment of deletion.** A running VPS keeps running, and services on it are not restarted. Removing the schedule is a control-panel change, not a server action.
- **Timers are per-VPS.** Deleting a timer on one VPS has no effect on any other VPS in your account, even if they share the same schedule. Repeat the steps on each machine.
- **Deletion is immediate and is not reversible.** There is no undo and no bin to restore from. If you remove the wrong timer, create it again from scratch.
- **Check the time zone before you assume a timer is wrong.** Scheduled times follow the time configured in the panel, which is not always the local time on your desk or inside the guest operating system. A timer that appears to fire at the wrong hour is usually a time zone mismatch rather than a fault, and editing it is a better fix than deleting it.
- **Scheduling inside the VPS is separate.** If the guest operating system also has its own shutdown scheduled, through a cron job or a systemd timer for example, removing the Virtualizor timer will not stop it. Check inside the VPS as well when a shutdown keeps recurring.
## Troubleshooting
**Symptom**: There is no **Self Shut Down** option on the VPS management screen. You may be looking at the wrong VPS, or the option may not be exposed for that virtualisation type. Go back to **List VPS**, confirm the hostname or IP address, and open **Manage** again. If it is still absent, contact Noiz support.
**Symptom**: The **Delete** button does nothing when clicked. The confirmation step uses a browser dialog. If your browser suppresses dialogs on that page, or a script blocker is active, the confirmation never appears and nothing is deleted. Allow dialogs for the panel, or try a different browser, then repeat the deletion.
**Symptom**: The timer is gone from the list, but the VPS still shuts down on schedule. Something outside Virtualizor is triggering it. Check for a scheduled task inside the guest operating system, and check whether a second timer with a similar time is still listed.
**Symptom**: The timer list is empty even though a shutdown was scheduled. A timer that has already run may no longer be listed. Nothing further is needed in that case, because a schedule that has already fired will not repeat unless it was created as a recurring one.
## Related Articles
- [How to Set Self Shutdown/Start/Reboot Timer for Your VPS in Virtualizor](/virtualizor/how-to-set-a-self-shutdown-start-or-reboot-timer-for-your-vps-in-virtualizor/)
- [How to Edit the Self-Shutdown Timer in Virtualizor](/virtualizor/how-to-edit-the-self-shutdown-timer-in-virtualizor/)
## Need a Hand?
If a timer will not delete, or a VPS keeps shutting down after the schedule has been removed, open a ticket from your Noiz client area with the VPS hostname or IP address and the time the shutdown occurred. The Noiz support team can check the schedule against the server logs and confirm what triggered it.
# How to Disable Rescue Mode in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-disable-rescue-mode-in-virtualizor/
Rescue mode boots your VPS into a small temporary recovery system instead of your own installed operating system, so you can mount the real disk and copy data off a server that will not start properly. Once the recovery work is finished you have to switch rescue mode back off again, otherwise the VPS keeps booting the recovery system and your own sites, mail and databases stay offline. This guide shows you how to disable rescue mode from the Virtualizor Enduser Panel and how to confirm the VPS has come back up on its real operating system.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its Enduser Panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor Enduser Panel: Rescue Mode](https://www.virtualizor.com/docs/end-user/rescue-mode/)
- [Virtualizor Enduser Panel: Manage VPS](https://www.virtualizor.com/docs/end-user/manage-vps/)
- [Virtualizor Enduser Panel: List VPS](https://www.virtualizor.com/docs/end-user/list-vps/)
## Prerequisites
- Your Virtualizor Enduser Panel login. See [How to Log In to the Virtualizor VPS Control Panel](/virtualizor/how-to-log-in-to-the-virtualizor-vps-control-panel/).
- A VPS that is currently running in rescue mode. If you need the companion procedure, see [How to Start Your VPS in Rescue Mode Using Virtualizor](/virtualizor/how-to-start-your-vps-in-rescue-mode-using-virtualizor/).
- Any files you rescued already copied off the server, because the recovery environment itself is temporary and is discarded when rescue mode is switched off.
## Why Rescue Mode Has to Be Switched Off
Rescue mode is not a one-off boot. For as long as it is enabled, every start and every reboot brings up the temporary recovery system rather than your installed operating system. That means the VPS answers on its IP address and accepts SSH, yet none of your own services are running: no web server, no mail, no database, no control panel. This is the single most common reason a VPS looks alive but every site on it is down after a recovery session.
If uptime monitoring is pointed at the server, expect it to keep alerting until rescue mode is off and the real system has booted.
## Finish Your Recovery Work First
Before switching rescue mode off, tidy up inside the recovery environment so the real operating system boots cleanly:
- Copy everything you need off the server, or onto the mounted original disk. Anything left only in the recovery system is lost.
- Flush pending writes and unmount the original disk you mounted, for example `sync` followed by `umount /mnt`. Disabling rescue mode with the disk still mounted and dirty can trigger a filesystem check on the next boot, which makes the VPS look like it is hanging when it is really repairing itself.
- Close any SSH sessions into the recovery system.
## Disable Rescue Mode in Virtualizor
### Step 1: Log in to Virtualizor
Log in to your Virtualizor Enduser Panel.
### Step 2: Open the VPS list
From the left side panel, click **List VPS**.

### Step 3: Open the VPS you want to manage
Hover your mouse over the appropriate VPS and that row will be highlighted. Then click the **Manage** icon in the highlighted row.

### Step 4: Open Rescue Mode
Click **Rescue Mode**. Depending on your Virtualizor version and theme this appears either as a tab or as a button on the Manage VPS page, but the label is the same.

### Step 5: Disable rescue mode
Click **Disable Rescue Mode**. Virtualizor switches the VPS back to its normal boot configuration and starts it on your own installed operating system.

Your VPS will now start in normal mode. Give it a minute or two to boot and for services to come up before you judge whether it is working.
## After Disabling: Confirm the VPS Booted Normally
- Log in with your **normal server credentials**. The password you set when you switched rescue mode on belongs to the temporary recovery system only, and it does not change the root password of your real operating system.
- Load one of your sites, and check that mail and any database driven applications respond.
- If SSH now refuses to connect with a warning that the remote host identification has changed, that is your SSH client remembering the recovery system's host key from your rescue session. Remove the stale entry with `ssh-keygen -R yourdomain.com`, replacing `yourdomain.com` with your own server name or IP address, then connect again and accept the key.
- If the boot itself is what you want to watch, open the console. See [How to Access Your VPS via the VNC Console in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/).
## Troubleshooting
**Symptom**: Virtualizor shows that **no actions are allowed**. While rescue mode is active most VPS actions are deliberately locked out. Click the **Reload this page** icon to refresh the page. All actions become visible again once rescue mode has been disabled.
**Symptom**: the page still shows **Enable Rescue Mode** and nothing changed. The change has already been applied and the page is showing you the next available action. Refresh the page and confirm the VPS status, rather than clicking again, which would put the VPS straight back into rescue mode.
**Symptom**: the VPS is reachable but every site returns a connection error. The VPS is almost certainly still in the recovery system. Recheck the Rescue Mode page and confirm the button reads **Enable Rescue Mode**, which means rescue mode is currently off.
**Symptom**: there is no Rescue Mode option on the Manage VPS page at all. Virtualizor offers rescue mode on KVM and Xen based virtualisation only, so a VPS built on another virtualisation type will not show it. To check what your VPS runs on, see [How to Check VPS RAM, IP, Disk Capacity, and Virtualization Type in Virtualizor](/virtualizor/how-to-check-vps-ram-ip-disk-capacity-and-virtualization-type-in-virtualizor/).
**Symptom**: the VPS takes far longer than usual to come back. A filesystem check after an unclean unmount, or services waiting on a network mount, will both do this. Watch the console output before forcing another reboot, because interrupting a filesystem repair can make the damage worse. If it is still not up after a reasonable wait, see [How to Reboot or Restart a VPS in Virtualizor](/virtualizor/how-to-reboot-or-restart-a-vps-in-virtualizor/).
## Need a Hand?
If the VPS will not boot cleanly after rescue mode is disabled, or you are not sure whether the underlying problem that sent you into rescue mode has actually been fixed, open a ticket with the Noiz support team from your client area and include the VPS hostname, roughly when the fault started, and what you did inside the recovery environment. That detail lets the team pick up where you left off instead of starting the diagnosis again.
# How to Edit the Self-Shutdown Timer in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-edit-the-self-shutdown-timer-in-virtualizor/
A self-shutdown timer in Virtualizor is a scheduled power action: at a date and time you choose, Virtualizor automatically starts, stops, restarts or powers off your VPS. This guide shows you how to change an existing timer on a Noiz VPS, so you can move the scheduled time, correct a wrong date, or switch the action without deleting the timer and starting again.
You may see this feature referred to as the self-shutdown timer, a scheduled power action, or simply a VPS timer. In the Virtualizor end-user panel it is always listed under **Self Shut Down**.
**Last reviewed:** 27 July 2026, against the current Virtualizor release. This guide is written for Noiz VPS hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor: Self Shutdown](https://www.virtualizor.com/docs/enduser-api/self-shutdown): the reference section covering the self-shutdown feature.
- [Virtualizor: Start Self Shutdown](https://www.virtualizor.com/docs/enduser-api/start-self-shutdown): documents the exact fields a timer holds, including the four action values and the expected date format.
- [Virtualizor: VPS Management](https://www.virtualizor.com/docs/enduser-api/vps-management/): the wider VPS management reference, covering the other actions available against a VPS.
## Prerequisites
- Your Virtualizor end-user panel login details for the VPS, supplied by Noiz when the service was provisioned.
- At least one self-shutdown timer already saved against the VPS. If none exists yet, create one first: [How to Set Self Shutdown/Start/Reboot Timer for Your VPS in Virtualizor](/virtualizor/how-to-set-a-self-shutdown-start-or-reboot-timer-for-your-vps-in-virtualizor/).
## Edit an Existing Self-Shutdown Timer
### Step 1: Open the VPS list
Log in to your Virtualizor control panel, then click **List VPS** in the left-hand menu.

### Step 2: Open the VPS you want to change
Hover over the row for the appropriate VPS. The row highlights and its action icons appear. Click the **Manage** icon on that row.

### Step 3: Open Self Shut Down
Click **Self Shut Down**.

### Step 4: Choose the timer to edit
Virtualizor lists every timer saved against the VPS. If more than one is listed, hover over the row you want. The row highlights, then click **Edit** on that row.

Check the action and time on the row before you click **Edit**, not after. Timers are listed by their stored values rather than by any name you gave them, so on a VPS with several timers it is easy to open the wrong one.
### Step 5: Change the values and save
Adjust the fields as needed, then click **Edit** to save. A timer holds only these values:
- **Action**: one of `Start`, `Stop`, `Restart` or `Power Off`. These are four distinct actions in Virtualizor, so re-read the selection after changing it: `Stop` and `Power Off` are not interchangeable, and picking the wrong one on a live server is the difference between a clean stop and an abrupt one.
- **Date**: the calendar date the action runs.
- **Hours** and **Minutes**: the time of day, on a 24-hour clock.
Editing updates the timer in place. It does not create a second one. If you want the VPS to perform two actions, for example stop at night and start in the morning, save a separate timer for each rather than editing one back and forth.
## Things Worth Knowing Before You Save
### The date format is month first
Virtualizor stores self-shutdown dates in `mm/dd/yyyy` order, which is the opposite of the `dd/mm/yyyy` convention used in South Africa and Ireland. A timer entered as `09/03/2026` means 3 September, not 9 March. Use the date picker rather than typing the date freehand, and read the saved value back once to confirm it lands where you expect.
### The clock that matters is Virtualizor's, not your laptop's
The timer fires against the panel's own clock, interpreted in the timezone set in your Virtualizor account preferences. That timezone is not taken from your browser or your operating system, so a timer set from a device in a different timezone will not necessarily run at the local hour you had in mind. Confirm the timezone in your Virtualizor preferences before scheduling anything time-sensitive, and take note of the current time Virtualizor itself displays.
### A self-shutdown timer is not a maintenance plan
A scheduled stop or power off takes the VPS offline at the appointed moment regardless of what is running on it. If the server hosts a database, a queue worker or anything mid-write, schedule the action for a genuinely quiet window and make sure your own backups have completed first. Virtualizor will carry out the action you asked for; it will not wait for a busy application to finish.
## Troubleshooting
- **The Edit option does not appear when you hover**: the row only exposes its controls on hover, and very narrow browser windows can push the controls out of view. Widen the window or scroll the table horizontally.
- **The timer ran a day earlier or later than expected**: almost always the `mm/dd/yyyy` date order. Reopen the timer and read the date back in month-first order.
- **The timer ran at the wrong hour**: check the timezone in your Virtualizor account preferences, then re-save the timer against that timezone.
- **Your changes do not appear in the list**: the save is only committed when you click **Edit** on the form itself. Navigating away from the form, or closing it with the browser back button, discards the changes.
- **You no longer need the timer at all**: remove it rather than setting it to a far-future date. See [How to Delete the Self-Shutdown Timer in Virtualizor](/virtualizor/how-to-delete-the-self-shutdown-timer-in-virtualizor/).
## Related Guides
- [How to Set Self Shutdown/Start/Reboot Timer for Your VPS in Virtualizor](/virtualizor/how-to-set-a-self-shutdown-start-or-reboot-timer-for-your-vps-in-virtualizor/)
- [How to Delete the Self-Shutdown Timer in Virtualizor](/virtualizor/how-to-delete-the-self-shutdown-timer-in-virtualizor/)
If a timer is not firing as scheduled, or you are unsure whether a stop action is safe for the workload on your VPS, open a ticket with the Noiz support team and include the VPS hostname and the timer you set. Noiz can check the action from the server side and advise on a safer schedule.
# How to Enable or Disable APIC, ACPI, and VNC in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-enable-or-disable-apic-acpi-and-vnc-in-virtualizor/
This guide shows you how to turn **APIC**, **ACPI** and **VNC** on or off for a VPS in **Virtualizor**, the panel Noiz VPS clients use to manage their servers. All three live on the same **VPS Configuration** screen and are set with a tick box each, so the clicking takes about thirty seconds. The part worth reading is what each one actually does, because two of them decide whether you can shut your server down cleanly and whether you can still reach it when the network is broken.
The product is **Virtualizor**, not "Virtualizer". You will see the misspelling in older notes and forum posts, and it is the same panel.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end-user panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor End User: VPS Configuration](https://www.virtualizor.com/docs/enduser/vps-configuration)
- [Virtualizor End User: VPS Management](https://www.virtualizor.com/docs/enduser/vps-management)
- [Virtualizor End User: VNC](https://www.virtualizor.com/docs/enduser/vnc)
## Prerequisites
- Your Virtualizor end-user panel URL and login details, which are in your Noiz VPS welcome email.
- An active Noiz VPS service.
- A maintenance window. The new settings only take effect after the VPS is power cycled, so plan for a short outage.
## What Each Setting Does
These are properties of the virtual machine itself, not of the operating system installed on it. They describe what hardware the hypervisor presents to your server, which is why a change only lands once the virtual machine is rebuilt from its configuration at the next power cycle.
### ACPI
**ACPI** is the Advanced Configuration and Power Interface. In a virtual machine it is the mechanism that lets the hypervisor press a virtual power button, and it is what makes a *graceful* shutdown possible. When you click **Stop** or **Restart** in Virtualizor, the panel sends an ACPI power event to the guest. The operating system sees it, stops its services in order, flushes buffered writes to disk and powers itself off properly.
With ACPI disabled there is no way to deliver that signal. The graceful **Stop** button appears to do nothing at all, and the only thing left that works is **Power Off**, which cuts the machine dead and risks the database corruption and dirty file systems that a clean shutdown exists to avoid. Unless you have a specific reason not to, leave ACPI enabled. The related shutdown behaviour is covered in [How to Forcefully or Gracefully Shut Down the VPS in Virtualizor](/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/).
### APIC
**APIC** is the Advanced Programmable Interrupt Controller, the virtual hardware that routes interrupts to the processor. It is what allows a virtual machine to use more than one CPU core sensibly and it feeds the timer sources the guest relies on to keep accurate time. Any modern Linux or Windows guest expects it to be there.
Disabling APIC is a compatibility measure for genuinely old operating systems that misbehave with a virtual APIC. On anything current it tends to produce the opposite of a fix: interrupts funnel through a single legacy controller, additional cores go unused or perform badly, and the guest clock drifts. Leave it enabled unless support has told you otherwise for a specific guest.
### VNC
**VNC** gives you a virtual console attached to the VPS, the equivalent of standing in front of the server with a monitor and keyboard plugged in. It works independently of the operating system's own networking, which is exactly why it matters: it is how you get in when SSH is refusing connections, when a firewall rule has locked you out, when the network configuration is wrong, or when the machine is sitting at a boot menu or a file system repair prompt that no remote service is up to answer.
Turning VNC off closes that door. Do it only if you have a policy reason to, and be clear that you are removing your own out-of-band recovery route. Using the console once it is enabled is covered in [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/).
## Enable or Disable APIC, ACPI and VNC
1. Log in to your Virtualizor end-user panel.
2. From the left-hand menu, click **List VPS**. 
3. Hover over the row for the VPS you want to change. The row highlights. Click the **Manage** icon on that row. 
4. Open the **Settings** tab and choose **VPS Configuration**. 
5. Tick the box beside **VNC**, **ACPI** or **APIC** to enable it, or clear the box to disable it. The three are independent of each other, so you can change one and leave the rest alone. 
6. Click **Submit**. Virtualizor saves the change against the VPS configuration.
7. Power cycle the VPS so the change takes effect. Use **Stop** and then **Start** from the panel, or the panel's **Restart**.
## The Gotchas Worth Knowing
- **A reboot from inside the operating system is not enough.** Running `reboot` over SSH restarts the guest but the virtual machine keeps running with the hardware definition it was created with, so your new setting is ignored. The machine has to be stopped and started, or restarted from Virtualizor, for the configuration to be read again.
- **ACPI is only half the story.** Enabling it lets the hypervisor deliver the shutdown signal, but something inside the guest has to listen for it. Full server distributions handle this through systemd, and it works out of the box. Minimal or container-style images sometimes ship without any ACPI handler at all, and on those a graceful shutdown is still ignored even with the box ticked. If that is what you are seeing, install `acpid` in the guest and try again.
- **These settings belong to hardware virtualisation.** They describe emulated hardware, so they are meaningful on a fully virtualised VPS. If your service uses container-based virtualisation, the container shares the host kernel and has no virtual power controller or graphics device of its own, so some or all of these boxes will simply not be on the screen. That is normal, not a fault.
- **Disabling VNC does not tighten security in any general sense.** The console is already behind your Virtualizor login. Turning it off removes your emergency access, not an exposed service, so the practical result is usually that a future lockout becomes a support ticket rather than a five-minute fix.
- **Check the state before you assume.** A tick box that already looks the way you want it means there is nothing to change. Submitting an unchanged form and rebooting achieves an outage and nothing else.
## Troubleshooting
**Symptom**: the setting was submitted but nothing behaves differently. The VPS has not been power cycled since the change, or it was rebooted from inside the operating system rather than from the panel. Stop it and start it again from Virtualizor.
**Symptom**: the graceful **Stop** is still ignored with ACPI enabled. Either the guest has no ACPI handler installed, or the operating system is too badly hung to respond to anything. Install `acpid` for the first case. For the second, a forced **Power Off** is the remaining option, and the server may run a file system check on the way back up.
**Symptom**: VNC opens to a black screen. That is usually a healthy server whose console has blanked after boot. Press `Enter` and wait for the login prompt to redraw. If it stays black, the guest may be sending its output to a serial console instead of the graphics device.
**Symptom**: the VNC option is ticked but the console still will not connect. Confirm the VPS is actually running, then power cycle it, because the console device is attached when the virtual machine is created.
**Symptom**: the clock drifts or extra cores appear idle after APIC was disabled. Re-enable APIC and power cycle. Those are the classic symptoms of a modern guest running without a proper interrupt controller.
**Symptom**: one or more of the tick boxes is missing. The VPS is on a virtualisation type that does not expose that setting, or it has been locked at host level. Open a ticket and Noiz support will confirm which applies.
## Related Guides
- [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/)
- [How to Forcefully or Gracefully Shut Down the VPS in Virtualizor](/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/)
## Need a Hand?
If a setting will not save, a tick box you expect is not on the screen, or your VPS stopped responding to a graceful shutdown after a change, open a support ticket from your [Noiz client area](https://www.noiz.co.za). The support team can check the virtual machine definition on the host node and confirm what the VPS was actually built with.
# How to Force or Gracefully Shut Down a VPS in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/
This guide shows you how to shut a VPS down from **Virtualizor**, the panel Noiz VPS clients use to manage their servers. Virtualizor gives you two very different ways to do it: a **graceful** shutdown that asks the operating system to close down properly, and a **forced** power off that cuts the virtual machine dead. They look almost identical in the panel and they are not remotely equivalent, so the important part of this guide is knowing which one to click.
The product is **Virtualizor**, not "Virtualizer". You will see the misspelling in older notes and forum posts, and it is the same panel.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end-user panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor End User: VPS Management](https://www.virtualizor.com/docs/enduser/vps-management)
- [Virtualizor End User: List VPS](https://www.virtualizor.com/docs/enduser/list-vps)
## Prerequisites
- Your Virtualizor end-user panel URL and login details, which are in your Noiz VPS welcome email.
- An active Noiz VPS service.
- A way to start the server again afterwards. Once a VPS is off, SSH is gone with it, so the only way back on is the panel. See [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/).
## Graceful Shutdown Versus Forced Power Off
Understand the difference before you click anything.
- **Stop** is the graceful option. Virtualizor signals the operating system to shut itself down in an orderly way. Services are told to stop, open files are closed, buffered writes are flushed to disk, and the machine powers off when that is finished. This is the option you want almost every time.
- **Power Off** is the forced option. It removes power from the virtual machine immediately, with no warning to anything running inside it. It is the exact equivalent of pulling the plug out of the wall on a physical server.
**A forced power off can corrupt data.** Anything still sitting in memory or in a write buffer is lost, and a database, mail queue or filesystem journal caught mid-write can be left inconsistent. In practice that shows up later as a database table that will not open, a filesystem that needs a check on the next boot, or an application that starts but behaves oddly. Use **Power Off** only when the server has genuinely stopped responding and a graceful **Stop** has already been tried and failed.
## Gracefully Shut Down a VPS in Virtualizor
1. Log in to your Virtualizor end-user panel.
2. From the left-hand menu, click **List VPS**. 
3. Hover over the row for the VPS you want to shut down. The row highlights. Click the **Manage** icon on that row. 
4. At the top right of the management page, click **Stop**. 
The shutdown is not instant. The operating system has to stop each service in turn, and a busy database or mail server can take a while to close cleanly. Give it a minute or two. Virtualizor displays a confirmation message when the VPS has stopped, and the status indicator on **List VPS** turns red.
## Force a Shutdown When the VPS Will Not Stop
If the graceful **Stop** does nothing, the operating system is usually too wedged to respond to the shutdown signal, commonly after it has run out of memory or a kernel-level fault. In that case use **Power Off** on the same management page.

Before you click it, wait long enough to be sure the graceful stop has really failed rather than simply being slow. A server that takes three minutes to shut down cleanly is normal; killing it at thirty seconds because nothing appeared to happen is how avoidable corruption gets caused.
After a forced power off, allow extra time on the next boot. The filesystem may run a consistency check, and databases may replay their journals before accepting connections. Do not force another power off part-way through that recovery, because interrupting a filesystem check is considerably worse than the original unclean shutdown.
## Shut Down From the Command Line
If you can still reach the server over SSH, you can shut it down from inside. This is an orderly shutdown, the same in effect as the panel's **Stop**, because the request comes from the operating system itself.
1. Connect to the VPS over SSH as `root` or a user with `sudo`.
2. Run: `poweroff`
The connection drops as soon as the shutdown begins, which is expected and not an error. `shutdown -h now` and `halt` do the same job.
**The important gotcha:** a VPS shut down from the command line will not come back on its own. There is nothing left running inside it to start anything, and SSH is unreachable, so the machine can only be powered on from Virtualizor. If what you actually wanted was for the server to come back up, use `reboot` instead, or follow [How to Reboot or Restart a VPS in Virtualizor](/virtualizor/how-to-reboot-or-restart-a-vps-in-virtualizor/).
## Before You Shut Anything Down
- **Everything on the VPS goes offline.** Websites, mail, databases and any application on the server stop answering for the whole time it is powered off. If mail is hosted on the VPS, sending servers will queue and retry rather than deliver, and a long outage risks bounces.
- **Take a backup or snapshot first** if the shutdown is part of maintenance you might need to undo.
- **Check you can get back in.** Confirm you can log in to Virtualizor before you power the server off, not after.
- **Shutting down does not pause billing.** The VPS keeps its resources, its IP address and its invoice while it is off. If you are shutting down because you no longer need the service, cancel it from your Noiz client area instead.
## Troubleshooting
**Symptom**: **Stop** was clicked and nothing happens. Give it a couple of minutes and refresh the page. If the status is still green, the operating system is not responding to the shutdown signal. Try once more, then fall back to **Power Off**.
**Symptom**: the VPS shows as offline but the website is still resolving. That is cached DNS or a caching proxy in front of the site, not the server. The origin is down.
**Symptom**: the VPS was shut down and now will not start. Check whether the service is suspended in your Noiz client area, since a suspended VPS will not stay powered on. If the service is in good standing and the VPS still will not boot, the operating system is likely failing during boot and needs console access to diagnose.
**Symptom**: after a forced power off, services do not come back. Give the boot longer than usual, because filesystem checks and database recovery run first. If a database still refuses to start, its tables may need repairing after the unclean shutdown.
**Symptom**: the server shut down without anyone asking it to. A `poweroff`, `halt` or `shutdown -h` issued inside the VPS, including one triggered by an automatic update or a script, powers the machine off permanently. It has to be started again from the panel.
## Related Guides
- [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/)
- [How to Reboot or Restart a VPS in Virtualizor](/virtualizor/how-to-reboot-or-restart-a-vps-in-virtualizor/)
- [How to Check Whether Your VPS Is Online or Offline in Virtualizor](/virtualizor/how-to-check-vps-onlineoffline-status-in-virtualizor/)
## Need a Hand?
If a VPS will not shut down, will not start again afterwards, or came back from a forced power off with damaged data, open a support ticket from your [Noiz client area](https://www.noiz.co.za). The support team can check the host node, confirm the real power state and help recover a server that did not come back cleanly.
# How to Log In to the Virtualizor VPS Control Panel
Source: https://docs.noiz.ie/virtualizor/how-to-log-in-to-the-virtualizor-vps-control-panel/
Your Noiz VPS is managed through **Virtualizor**, and the part of Virtualizor you log in to is called the **end user panel**. From there you can start, stop and reboot the server, open a console, reinstall the operating system, view resource graphs and manage networking. This guide shows you how to find your credentials, reach the correct address, sign in, and get past the handful of login problems that account for almost every support ticket on this subject.
The product name is spelled **Virtualizor**, not "Virtualizer". Searching the vendor documentation with the wrong spelling returns nothing.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end user panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor end user panel documentation](https://www.virtualizor.com/docs/enduser/) (the full feature index)
- [List VPS](https://www.virtualizor.com/docs/enduser/list-vps/) (the page you land on after signing in)
- [Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps/)
- [Two factor authentication (end user panel)](https://www.virtualizor.com/docs/enduser/two-factor-authentication/)
## Prerequisites
- An active VPS service with Noiz.
- Your VPS welcome email, which contains the control panel address, your username and your initial password.
- A current desktop or mobile browser. No plugin, client or VPN is required.
## Step 1: Find Your Login Details
Everything you need was sent in your **VPS welcome email** when the server was provisioned. Noiz does not publish panel hostnames on the website, so treat that email as the authoritative record and keep it somewhere you can find again.
The welcome email contains three items, in this shape:
- **Control Panel URL:** `https://cp.example.com:4083` (or the same address written as an IP address, for example `https://198.51.100.25:4083`). Replace `cp.example.com` with the hostname in your own email.
- **Username:** your email address.
- **Password:** the initial panel password.
If the welcome email has been lost, do not guess. Open a ticket from the [Noiz client area](https://www.noiz.co.za/login) and Noiz will resend the connection details to the account holder.
### Three Different Passwords, One VPS
This is the single most common source of confusion, so it is worth being explicit. A Noiz VPS involves three separate credentials that are not interchangeable:
- **Noiz client area login**: for billing, invoices and support tickets at [noiz.co.za/login](https://www.noiz.co.za/login). Changing this does nothing to the VPS.
- **Virtualizor panel login**: the credentials in this guide. This controls the server from the outside (power, reinstall, console, networking).
- **VPS root or administrator password**: used for SSH or Remote Desktop *inside* the operating system. Virtualizor can reset it, but it is a different password.
If a password is rejected, check which of the three you are actually typing before assuming anything is broken.
## Step 2: Open the Control Panel Address
Paste the control panel URL from your welcome email into the browser address bar exactly as it was sent, **including the port number after the colon**.
The port matters. Virtualizor does not run the end user panel on the ordinary web ports by default:
- `4083` is the end user panel over HTTPS. This is the one you want.
- `4082` is the same panel over plain HTTP. Use `4083` instead so the session is encrypted.
- `4085` and `4084` belong to the Virtualizor *administrator* panel, which is reserved for Noiz staff. Your credentials will never work there, and a rejected login on those ports is expected behaviour, not a fault.
Typing the hostname without the port lands you on whatever is being served on port 443 for that name, which is usually not Virtualizor. That produces a blank page, a certificate error or an unrelated website, and it is very often mistaken for the panel being down.
If the address in your welcome email has no port on the end, that is deliberate: the panel has been published on the standard HTTPS port for your service. Use it as written.
### About the Certificate Warning
If the panel is reached by its IP address rather than by its hostname, the browser may warn that the certificate does not match. The certificate is issued for the hostname, not for the raw IP, so the mismatch is expected. Use the **hostname** form of the URL from your welcome email and the warning disappears. Persistent certificate errors on the hostname form are worth a support ticket.
## Step 3: Sign In
1. On the **Sign in** panel, enter your **email address** in the first field. The field is labelled **Email** because the end user login is your email address, not a system account name such as `root` or `admin`.
2. Enter your **Password** in the second field. Use the eye icon at the right of the field to reveal what you have typed, which is the quickest way to catch a stray space pasted in from the welcome email.
3. Click **Login**.

If two factor authentication is enabled on your account, a one time code is requested on the next screen. Enter the code from your authenticator app, or the code emailed to you, depending on which method is configured. Two factor is worth enabling on any account that can power off or reinstall a production server: see the [Virtualizor two factor documentation](https://www.virtualizor.com/docs/enduser/two-factor-authentication/) for the setup steps.
## Step 4: What You See After Logging In
A successful login lands you on **List VPS**, which shows every server on your account with its power state. Click a server to open its management view, where the work is divided across tabs including **Overview**, **Graphs**, **Settings**, **Install**, **Tasks And Logs**, **Services**, **Networking**, **Rescue Mode** and **Backups**.
Your name in the top right corner opens the account menu, which holds **My Profile**, **Settings** (language, timezone, theme and security options, including two factor authentication) and **Logout**. A dark theme is available from the same settings area if you prefer it.
Two habits are worth forming on first login:
- **Change the initial password.** The password in the welcome email has travelled through your mailbox in plain text. See [How to Change the Password of Your Virtualizor Account](/virtualizor/how-to-change-your-virtualizor-account-password/).
- **Bookmark the full URL including the port.** It saves rediscovering the welcome email every time.
## Troubleshooting
**Symptom**: the page will not load at all, or the browser reports a connection timeout. The panel port is not a standard web port, and some corporate, school and public Wi-Fi networks only permit outbound traffic on ports 80 and 443. Test the same URL from a mobile connection. If it loads there, the block is on the network you were using, not on the server.
**Symptom**: "Invalid login" although the password is definitely correct. Check for a trailing space picked up when copying from the email, confirm you are using the email address rather than a system username, and confirm you are on the end user port and not the administrator port. If it still fails, use the **Forgot Password** link on the sign in page to send a reset to the email address on the account.
**Symptom**: the reset email never arrives. Check the spam folder first. If the account email address is out of date, it cannot be fixed from the login screen: see [How to Change Your Virtualizor Account Email Address](/solusvm/how-to-change-the-solusvm-account-email-address/), or raise a ticket so Noiz can verify the account holder and correct it.
**Symptom**: you can log in, but the VPS itself is unreachable over SSH or Remote Desktop. The panel and the server are independent. A panel login proves the management layer is healthy; it says nothing about the operating system inside the VPS. Open the console from the server's management view to see what the machine is actually doing. See [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/).
**Symptom**: the panel loads, but the server list is empty. The account you signed in with is not the account the VPS is attached to. This happens when a colleague ordered the service. Log in with the address that received the welcome email.
## Getting Help
If the panel is unreachable from more than one network, or the login is rejected after a password reset, raise a ticket from the [Noiz client area](https://www.noiz.co.za/login). Include the exact URL you tried, the error text or a screenshot, and whether the same address works from a different connection. That detail lets Noiz separate a network problem from a panel problem on the first reply instead of the third.
# How to Manually Install or Reinstall an OS From an ISO in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-manually-install-or-reinstall-an-os-from-an-iso-in-virtualizor/
This guide shows you how to install or reinstall an operating system on a Noiz VPS by booting it from an ISO image in **Virtualizor** and stepping through the installer yourself over the VNC console. This is the manual route, and you use it when you need control that the one-click reinstaller cannot give you: a custom partition layout, your own LVM or RAID scheme, encrypted volumes, a specific filesystem, or an operating system that is not on the template list.
If you do not need any of that, use the automatic reinstaller instead. It is faster, it configures networking for you, and it is far harder to get wrong. See [How to Reinstall an OS Using the Virtualizor Automatic OS-Reinstaller](/virtualizor/how-to-reinstall-an-os-using-the-virtualizor-automatic-os-reinstaller/). The manual method exists precisely because the automatic reinstaller does not let you touch the partition table.
**This procedure destroys everything on the VPS.** Once you start the installer and write a partition table, the existing operating system, websites, databases, mail and configuration on that disk are gone, and there is no undo. Take a full backup off the server first and confirm you can actually restore from it. A backup you have never tested is not a backup.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end-user panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor End User: Enduser ISO](https://www.virtualizor.com/docs/enduser/end-user-iso)
- [Virtualizor: Changing Boot Order](https://www.virtualizor.com/docs/admin/changing-boot-order)
- [Virtualizor End User: VNC](https://www.virtualizor.com/docs/enduser/vnc)
- [Virtualizor End User: Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps)
## Prerequisites
- Your Virtualizor end-user panel URL and login details, which are in your Noiz VPS welcome email.
- A verified, off-server backup of anything on the VPS you cannot lose.
- An ISO available to your account in the **Select ISO** list. If the list is empty or does not contain the image you need, open a ticket and ask Noiz to make it available.
- The network details for the VPS: its IP address, subnet mask, gateway and nameservers. You will need to type these into the new system by hand. They are shown in the panel and in your welcome email.
- A working browser for the VNC console. See [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/).
## Read This Before You Start
A manual ISO install is not the same job as an automatic reinstall, and the differences catch people out afterwards rather than during.
- **Networking is not configured for you.** The automatic reinstaller injects the VPS network settings into the new system. A manual install does not, so the server will very likely come up with no working network at all. You configure the IP address, gateway and DNS by hand from the console during or immediately after the install. Have those details open in another tab before you begin.
- **SSH may not be installed.** Minimal installer profiles frequently leave out the SSH server. If you finish the install, reboot and find you cannot connect, the usual cause is that there is nothing listening on port 22 yet. Install and enable the SSH server from the VNC console.
- **Only the console works until networking does.** Everything between starting the installer and getting the network up happens over VNC. Treat the VNC console as your lifeline, not as a fallback.
- **Record every password you set.** You are creating this system from scratch, so the root password is whatever you type into the installer. Nothing else knows it.
- **The disk will usually appear as `/dev/vda`** rather than `/dev/sda`, because the virtual disk is presented over virtio. That is normal. If the installer claims it cannot find any disk at all, it is missing virtio storage drivers, which is common with Windows and some older or minimal Linux images.
## Step 1: Attach the ISO and Change the Boot Order
The VPS boots from its hard disk by default. To run an installer you have to attach the ISO and tell the VPS to look at the virtual CD drive first.
1. Log in to your Virtualizor end-user panel.
2. From the left-hand menu, click **List VPS**. 
3. Hover over the row for the VPS you want to install. The row highlights. Click the **Manage** icon on that row. 
4. Click **Settings** and choose **VPS Configuration**. 
5. Change **Boot Order** to **(1) CD Drive (2) Hard Disk**. 
6. Under **Select ISO**, choose your ISO from the drop-down list. Make sure **VNC** is enabled, leave the remaining options alone, then click **Submit**. 
Both changes have to be saved together. An ISO attached with the boot order still on hard disk first will simply boot the old operating system, and a CD-first boot order with no ISO attached will drop the VPS to a boot failure screen. If you want console access on a VPS that is otherwise fine, use [How to Enable or Disable APIC, ACPI and VNC in Virtualizor](/virtualizor/how-to-enable-or-disable-apic-acpi-and-vnc-in-virtualizor/) instead of touching the boot order.
## Step 2: Restart the VPS and Open the Console Immediately
The next part is a race, and it is the step people most often have to repeat.
1. Restart the VPS by clicking the **Reboot** icon. 
2. Click **VNC** straight away, without waiting for the reboot to finish. 
3. A pop-up appears. Click **HTML5 VNC Client**. 
**Why the hurry:** most installer images show a **Press any key to boot from CD** prompt that lasts only a few seconds. Miss it and the VPS falls through to the hard disk and boots the old system, or hangs on a blank screen. If that happens, nothing is broken. Reboot and try again, with the console already open.
**If the ISO does not appear to attach on a reboot**, stop the VPS completely and then start it again rather than rebooting. A full power cycle is the reliable way to make a virtual machine pick up newly attached media, and it is what the Virtualizor documentation recommends.
## Step 3: Work Through the Installer
From here you are inside the operating system's own installer, and the steps belong to that operating system rather than to Virtualizor. The pattern is the same across nearly all of them.
1. At the boot prompt, press any key when asked, then choose the install option. Menus commonly offer something like **Install** alongside **Test this media** or a live session. Select the install entry and press **Enter**.
2. Answer the language, keyboard and timezone questions.
3. At the storage step, choose manual or custom partitioning. This is the whole reason for doing the install this way, so do not accept the automatic layout unless you have changed your mind about needing a custom one.
4. Set the root password and create any user accounts.
5. If the installer offers a software selection, include the SSH server. It saves a console-only recovery session later.
6. Let the installation finish, then reboot when prompted.
**Console quirks worth knowing.** The HTML5 console passes keystrokes straight to the virtual machine, so some browser and operating system shortcuts are intercepted before they reach the server. Copy and paste between your desktop and the console is limited, which matters when you are typing a long partition path or a complex password. Graphical installers are also slower and jerkier over VNC than a text-mode installer, so if the image offers a text or minimal install mode, it is usually the smoother choice.
**If VNC disconnects**, click **Connect** to reconnect. Disconnections are common at the moment the installer switches graphics mode or when the VPS reboots, and they do not interrupt the installation itself. The install keeps running on the server whether or not your browser is watching.
## Step 4: Set the Boot Order Back to Hard Disk
Do not skip this. It is the single most common mistake with a manual install.
1. Go back to **Settings** and then **VPS Configuration**.
2. Change **Boot Order** back to **(1) Hard Disk (2) CD Drive**.
3. Detach the ISO if the option is available, then click **Submit**.
4. Reboot the VPS and confirm it comes up into the newly installed system.
Leave the boot order on CD first and the VPS starts the installer again on every single boot instead of the system you just installed. That is confusing at the best of times and genuinely dangerous the day an unattended reboot happens and someone assumes the server is broken and reinstalls it.
## Step 5: Bring the Server Back Online
A freshly installed system is a blank machine on your IP address. Before you call the job done:
- Configure the static IP address, subnet mask, gateway and nameservers from the console, then confirm the server can reach the internet.
- Install, enable and start the SSH server if the installer did not, and check you can log in over SSH from your own machine.
- Apply all pending security updates before exposing anything to the public internet. A machine installed from an older ISO is behind on patches from the moment it boots.
- Configure a firewall. A default install typically has nothing filtering traffic.
- Restore your data and reinstall your control panel or application stack.
## Troubleshooting
**Symptom**: the VPS boots the old operating system instead of the installer. Either the boot prompt timed out before you pressed a key, or the boot order did not save. Recheck **VPS Configuration**, then stop and start the VPS with the console already open.
**Symptom**: the **Select ISO** drop-down is empty. No ISO has been made available to your account. Open a ticket with the image you need.
**Symptom**: the VNC console is blank or black. Give it a moment, since the screen stays blank between the reboot and the installer starting. If it stays blank, confirm VNC is enabled in **VPS Configuration**, then click **Connect** to reconnect.
**Symptom**: the installer reports that no disk was found. The image is missing virtio storage drivers. Load them during setup, which is a standard step for Windows installs, or use an image that includes them.
**Symptom**: the install finished but the server has no network. Expected, and normal for a manual install. Configure the IP address, gateway and DNS by hand from the VNC console.
**Symptom**: SSH refuses the connection after a successful install. The SSH server is probably not installed or not enabled. Install it and enable it at boot from the console, and check the new system's firewall is allowing port 22.
**Symptom**: the panel's root password reset does not work on the new system. Panel-side password resets rely on a recognisable standard disk layout. Unusual, encrypted or heavily customised layouts can defeat them, which is another reason to write down the password you set during the install.
## Related Guides
- [How to Reinstall an OS Using the Virtualizor Automatic OS-Reinstaller](/virtualizor/how-to-reinstall-an-os-using-the-virtualizor-automatic-os-reinstaller/)
- [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/)
- [How to Enable or Disable APIC, ACPI and VNC in Virtualizor](/virtualizor/how-to-enable-or-disable-apic-acpi-and-vnc-in-virtualizor/)
- [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/)
## Need a Hand?
If the ISO you need is not in the list, the installer cannot see the disk, or the VPS will not boot into the new system afterwards, open a support ticket from your [Noiz client area](https://www.noiz.co.za). The support team can check the host node, confirm what the virtual machine is actually booting from and get the console back for you. If you would rather not run the install yourself, ask and Noiz will handle it.
# How to Reboot or Restart a VPS in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-reboot-or-restart-a-vps-in-virtualizor/
A reboot is the first thing most people reach for when a VPS starts misbehaving, and it is usually the right call after a kernel update, a stuck service or a configuration change that needs a clean start. This guide shows you both ways to restart a VPS on Noiz: from the Virtualizor end user panel, and from inside the server over SSH. It also explains the part that matters most and is almost never spelled out, which is the difference between a graceful restart and a forced reset, and why reaching for the wrong one can cost you data.
**Last reviewed:** 27 July 2026, against the current Virtualizor release. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor: List VPS (end user panel)](https://www.virtualizor.com/docs/enduser/list-vps)
- [Virtualizor: Manage VPS (end user panel)](https://www.virtualizor.com/docs/enduser/manage-vps)
- [Virtualizor Enduser API: Restart VM](https://www.virtualizor.com/docs/enduser-api/restart-vm)
- [Linux manual page: shutdown(8)](https://man7.org/linux/man-pages/man8/shutdown.8.html)
## Prerequisites
- An active VPS on Noiz, and the Virtualizor end user panel login that Noiz issued with it. The panel normally answers on port `4083`, for example `https://your-server-hostname:4083`.
- For the SSH method: the VPS IP address, a working SSH client and root access (or an account with `sudo`).
- If you cannot recall your panel password, reset it first: [How to Change the Password of Your Virtualizor Account](/virtualizor/how-to-change-your-virtualizor-account-password/).
## Graceful Restart Versus Forced Reset
Both actions end with the server coming back up, so they look interchangeable. They are not.
- **A graceful restart** is issued from inside the operating system, normally with `shutdown -r now`. The kernel tells every running service to stop in an orderly sequence. Databases flush their write buffers to disk and close their tables, web servers finish serving in-flight requests, mail queues are written out, and file systems are unmounted cleanly before the machine goes down. This is the safe default and the one you should use whenever you can reach the server.
- **A forced reset**, sometimes called a hard reset or a power cycle, cuts the virtual machine off without warning. It is the equivalent of pulling the power lead out of a physical server. Nothing gets a chance to finish.
**What a forced reset actually risks.** Anything sitting in memory and not yet written to disk is lost. In practice that means recent database writes can disappear, MySQL or MariaDB may run crash recovery on the next boot (which on a large InnoDB dataset can take minutes, not seconds), file systems can come back dirty and trigger a lengthy consistency check, and files that were half written are left truncated. Uploads, session data and cache files are the usual casualties. In the worst cases a service refuses to start at all until you clear a stale lock file or repair a table by hand.
**Where the Virtualizor controls sit.** The buttons in the panel act on the virtual machine from the outside, at the hypervisor, rather than from inside the guest operating system. Depending on the virtualisation type and whether the guest is listening for ACPI power events, a panel **Restart** may not give your services time to shut down cleanly. Treat the panel as the fallback for when SSH is unreachable, not as the everyday reboot button.
**Do not confuse Restart with Power Off.** The same Virtualizor screen also offers **Power Off**, which is unambiguously a hard cut with no shutdown sequence at all. It is not a faster way to reboot. If you need to stop a VPS rather than restart it, use the shutdown options described in [How to Forcefully or Gracefully Shut Down the VPS in Virtualizor](/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/), and bring it back with [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/).
## How to Restart a VPS From the Virtualizor Panel
Use this route when SSH is unreachable, when the server is unresponsive, or when you simply do not have a terminal to hand.
1. Log in to your Virtualizor end user panel.
2. In the left sidebar, click **List VPS**. Newer Virtualizor builds group this under **Virtual Servers** and label it **List All**, but it is the same page. 
3. Find the VPS you want to restart. Hover over its row and the line highlights, then click the **Manage** icon on that line. If you only have one VPS on the account, Virtualizor may take you straight to its management page. 
4. On the management page, click the **Restart** icon in the row of power controls at the top right. Check the hostname and VPS ID on screen before you click, because it is easy to restart the wrong server when you manage several. 
5. Confirm the action if you are prompted, then wait. Virtualizor displays a success message once the instruction has been carried out.
**The gotcha most people hit:** the confirmation message means Virtualizor accepted and issued the restart, not that your operating system has finished booting and your sites are back. The panel status can read *Running* while the guest is still working through its boot sequence. A small Linux VPS is usually reachable again within 20 to 60 seconds; allow considerably longer if a file system check runs after an unclean shutdown, if the server has a large database to recover, or if it runs Windows.
## How to Restart a VPS Over SSH
This is the preferred method whenever the server still answers, because the shutdown is handled by the operating system itself.
1. Connect to the VPS with your SSH client, replacing the address with your own: `ssh root@192.0.2.10`
2. Issue the reboot: `shutdown -r now` If you are logged in as a normal user rather than root, prefix it with `sudo`. Without root privileges systemd refuses the request and reports that interactive authentication is required. On systemd distributions `reboot` and `systemctl reboot` do the same job.
3. Your SSH session will drop immediately, often with a broken pipe or connection closed message. That is the expected result of a successful reboot, not an error.
4. Wait, then reconnect and confirm the machine really did restart: `uptime -p who -b`
### Useful Variations
- **Give other users warning.** `shutdown -r +5 "Rebooting for a kernel update"` schedules the restart five minutes out and broadcasts the message to anyone logged in. Handy on a shared development box.
- **Cancel a scheduled restart.** `shutdown -c` calls off a pending timed shutdown.
- **Check whether a reboot is actually needed.** On Debian and Ubuntu, the presence of the file `/var/run/reboot-required` after updates means a restart is pending. On RHEL-family systems, `needs-restarting -r` tells you the same thing. Rebooting a production server for no reason is avoidable downtime.
- **Confirm your services come back on their own.** A reboot only restores what is enabled at boot. Check with `systemctl is-enabled nginx` (substituting your own service) and enable anything that is not, or you will find the server up and the website still down.
## Troubleshooting
**Symptom: the VPS shows as running but the website is unreachable.** The machine booted, a service did not. Connect over SSH and check the state with `systemctl status nginx` or `systemctl --failed`, then enable and start whatever is missing.
**Symptom: SSH is refused for a minute or two after the reboot.** The boot sequence has not reached the SSH daemon yet. Wait 30 seconds and try again before assuming something is broken.
**Symptom: `shutdown -r now` appears to hang and the server never goes down.** A process is refusing to terminate and is blocking the shutdown. This is exactly the case the panel exists for: use the Virtualizor **Restart** control instead, accepting the risk described above.
**Symptom: Virtualizor reports that the operation could not be completed.** The VPS may be suspended, locked or mid-task (a backup or migration will block power actions). Wait for any running task to finish and try again. If the error persists, open a ticket with Noiz rather than repeatedly forcing the action.
**Symptom: the server takes many minutes to come back after a forced reset.** It is almost certainly running a file system consistency check or database crash recovery. Do not reset it again, as interrupting recovery is how a slow boot turns into a damaged one. Watch what it is doing on the console instead: [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/).
## Related Articles
- [How to Forcefully or Gracefully Shut Down the VPS in Virtualizor](/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/)
- [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/)
- [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/)
- [How to Change the Password of Your Virtualizor Account](/virtualizor/how-to-change-your-virtualizor-account-password/)
If your VPS does not come back after a restart, or you are not sure whether a forced reset is safe in your situation, open a support ticket from your Noiz client area before you try again. The Noiz team can reach the console and the hypervisor directly and will get the server back up without risking your data.
# How to Reinstall an OS Using the Virtualizor Automatic OS Reinstaller
Source: https://docs.noiz.ie/virtualizor/how-to-reinstall-an-os-using-the-virtualizor-automatic-os-reinstaller/
Virtualizor's automatic OS reinstaller rebuilds your VPS from a ready-made operating system template in a few minutes, with no ISO upload, no rescue media and no console work. It is the fastest way to get back to a clean server when an installation has gone wrong, when you want to move from one distribution to another, or when you are handing the machine on to a new project. This guide covers the automatic reinstaller in the Virtualizor end-user panel on your Noiz VPS: what it does, what it destroys, and what you must have in hand before you click the button.
**Warning: a reinstall permanently destroys every file on the VPS.** Reinstalling does not repair, upgrade or refresh the existing system. It formats the disk and writes a brand new operating system over it. Websites, databases, mailboxes, configuration files, SSH keys, TLS certificates, cron jobs and control panel data are all gone the moment the reinstall starts, and there is no undo and no cancel. **Take a verified backup and copy it off the VPS before you go any further.** If the server is already broken and you are reinstalling in order to recover, stop: reinstalling will destroy the data you are trying to recover. Use Virtualizor's Rescue Mode to pull the data off first, or open a ticket with Noiz support.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its end-user panel. This guide is written for Noiz VPS hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor: Re-Install OS (end-user)](https://www.virtualizor.com/docs/enduser/re-install-os/)
- [Virtualizor: Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps/)
- [Virtualizor: End-user backup](https://www.virtualizor.com/docs/enduser/enduser-backup/)
- [Virtualizor: Rescue Mode](https://www.virtualizor.com/docs/enduser/rescue-mode/)
## Prerequisites
- Your Virtualizor end-user panel address and login, sent by Noiz with your VPS details. This is the VPS control panel, not the Noiz client area.
- A current backup that you have copied off the VPS and confirmed you can open.
- A decision on which distribution and version you want, taken before you start. Changing your mind afterwards means reinstalling again.
- A record of anything you will need to rebuild: web server configuration, database dumps, DNS records, firewall rules, licence keys and SSH public keys.
## Before You Start: Take a Backup
This is the step people skip and then regret. Virtualizor gives you a backup icon on the VPS Management page with an option to take a backup immediately, and it lists any backups already held. Run one, then treat it as a starting point rather than a safety net.
A few points worth being firm about:
- **Copy the important data off the VPS yourself.** Pull database dumps, site files and mail down over SFTP to a machine you control. Backups that only exist inside the platform you are about to reformat give you fewer options than you think.
- **Check the backup opens.** An archive you have never extracted is a hope, not a backup. Extract it somewhere and look inside before you reinstall.
- **Dump databases properly.** Copying raw MySQL or PostgreSQL data directories from a running server produces files that often will not import cleanly. Use the database's own dump tool.
- **Save your licences and keys.** Control panel licences, commercial plugin keys and API credentials are frequently tied to the installation and need reissuing after a rebuild. Find out now, not afterwards.
If the VPS will not boot and the data on it still matters, do not reinstall. Enable Rescue Mode instead, which boots the VPS into a small recovery system and lets you mount the original disk and copy files off it. Reinstalling is for when you have accepted the loss of everything currently on the disk.
## How to Reinstall the Operating System
The reinstall lives on the VPS Management page in the end-user panel. Depending on the Virtualizor build running on your node, the section is labelled **Install** or **OS Re-Install**. The controls behind it are the same in both, and the screenshots below still map cleanly onto the current panel.
**1**. Log in to your Virtualizor control panel.
**2**. From the left side panel, click on **List VPS**.

**3**. Hover your mouse over the appropriate VPS, and that line will be highlighted. Then click on the **Manage** icon in the highlighted line. If you run more than one VPS, check the hostname and IP address in that row carefully before you continue. There is no confirmation later that tells you which server you picked.

**4**. Click on the **Install** tab, labelled **OS Re-Install** in newer Virtualizor builds.

**5**. Under **Reinstall OS**, select the appropriate OS. If it has more than one version, select the appropriate version. Only templates that are present on the node your VPS runs on appear in this list, so it is normal for it to be shorter than the full catalogue of distributions Virtualizor supports.

**6**. In the password field, enter the password or click on the key icon to generate a random one. Save it in a safe place, and then click on **Reinstall**. This becomes the root password on the newly installed system, and it is the only credential you will have to get back in, so record it before you click. If a **Format Primary Disk Only** option is shown, it limits the wipe to the first disk attached to the VPS and leaves any secondary disks untouched. That is useful when your data lives on a separate volume, but it is not a substitute for a backup.

**7**. A confirmation box will prompt. Click **OK** to proceed. This is the point of no return: the disk is formatted as soon as you confirm, and the job cannot be stopped part way through.

OS reinstallation usually takes 5 to 10 minutes. Larger templates, Windows images and busy nodes can take longer. Leave the page open and let the progress indicator finish rather than reloading or navigating away.
## After the Reinstall
What survives a reinstall is the VPS itself: its IP addresses, its resource allocation, its entry in your Noiz billing, and its place in the panel. What does not survive is everything that was on the disk. Expect to deal with the following:
- **Your SSH client will refuse to connect.** The new installation generates new SSH host keys, so your client sees a changed fingerprint and warns about a possible impersonation attempt. That warning is correct and expected here. Clear the stale entry with `ssh-keygen -R your.vps.ip.address` and connect again.
- **You log in as `root` with the password you set at step 6.** Any user accounts, sudo rules and authorised SSH keys from the old system are gone. Re-add your public key and disable password authentication again if that was your previous setup.
- **Firewall rules are back to the template defaults.** Whatever hardening you had applied no longer exists. Put your firewall rules back before you expose any service to the internet, and do it in the same session, not next week.
- **Control panels, web servers, databases and mail are not there.** If your VPS ran a control panel, install it fresh and reapply its licence. Restore data only after the panel and services are running and configured.
- **TLS certificates need reissuing.** Private keys were on the wiped disk. Request new certificates once the web server is answering on the domain again.
- **DNS usually needs no change.** The IP address normally stays with the VPS across a reinstall, so your records keep pointing to the right place. Confirm the IP in the panel before assuming it, and if it has changed, update your DNS and allow for propagation.
## Troubleshooting
**Symptom: the distribution or version you want is not in the list.** The reinstaller can only use OS templates already loaded on the node hosting your VPS. Open a ticket with Noiz support and ask whether the template can be added, or install from an ISO instead, which lets you supply your own image and control the partitioning.
**Symptom: the reinstall seems stuck well past 15 minutes.** Connect to the VPS console over VNC and look at what is on screen. An installer waiting on a prompt, a template still being written, or a boot loop all look identical from the panel, and the console tells you which one you are looking at.
**Symptom: SSH reports "REMOTE HOST IDENTIFICATION HAS CHANGED".** This is the expected result of a reinstall, not a sign of a problem. Remove the old host key from your known hosts file with `ssh-keygen -R your.vps.ip.address`, then reconnect and accept the new fingerprint.
**Symptom: the root password is rejected.** Retype it manually rather than pasting, in case a trailing space or a character your keyboard layout renders differently crept in. If it still fails, set a new root password from the Virtualizor panel and try again with something free of ambiguous characters.
**Symptom: data is still present after the reinstall.** If **Format Primary Disk Only** was ticked, secondary disks attached to the VPS are deliberately left alone. That is working as designed. Mount the secondary disk on the new system to reach that data.
**Symptom: you reinstalled and then realised you needed something off the old disk.** There is no recovery path once the format has run. Restore from the backup you took beforehand. This is the reason the backup step is not optional.
## Related Articles
- [How to Manually Install/Reinstall an OS Using Virtualizor for a Customized Installation](/virtualizor/how-to-manually-install-or-reinstall-an-os-from-an-iso-in-virtualizor/), for when you need a distribution or a partition layout the automatic reinstaller does not offer.
- [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/), for watching an install run or reaching a VPS that will not accept SSH.
If you are unsure whether a reinstall is the right fix, or you need data recovered from a VPS that will not boot, open a ticket with Noiz support before you reinstall. Once the format has started, the options narrow to whatever backup you took first.
# How to Set a Self Shutdown, Start, or Reboot Timer for Your VPS in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-set-a-self-shutdown-start-or-reboot-timer-for-your-vps-in-virtualizor/
Virtualizor can perform a power action on your VPS for you at a date and time you choose, without you being logged in. This is called a **self shutdown** timer, and despite the name it is not limited to shutting down: the same form schedules a start, a stop, a restart or a hard power off. This guide shows you how to set one from the Virtualizor end user panel on your Noiz VPS, and covers the two things that catch people out: the clock the timer runs against, and the fact that a timer fires once and then leaves the VPS wherever it put it.
**Last reviewed:** 27 July 2026, against the current Virtualizor end user panel release. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor: Manage VPS (end user panel)](https://www.virtualizor.com/docs/enduser/manage-vps/)
- [Virtualizor: List VPS](https://www.virtualizor.com/docs/enduser/list-vps/)
- [Virtualizor: Self Shutdown reference](https://www.virtualizor.com/docs/enduser-api/self-shutdown/)
## Prerequisites
- An active VPS on your Noiz account.
- Your Virtualizor end user panel login. If you are not sure where to sign in, see [How to Log In to the Virtualizor VPS Control Panel](/virtualizor/how-to-log-in-to-the-virtualizor-vps-control-panel/).
- A decision on what the timer should do and when. Read the warning further down before you point one at a live server.
## Set the Timer
### Step 1: Log in to Virtualizor
Sign in to your Virtualizor VPS control panel.
### Step 2: Open the VPS list
In the left side panel, click **List VPS**.

### Step 3: Manage the VPS
Hover over the row for the VPS you want to schedule. The row highlights and the action icons become available. Click the **Manage** icon on that row.

If you have more than one VPS, check the hostname and IP address on the row before you click. Scheduling a shutdown against the wrong server is an easy mistake to make from a list view.
### Step 4: Open Self Shut Down
On the VPS management page, click **Self Shut Down**.

### Step 5: Choose the time and the action
Fill in the **Date**, **Hour** and **Minute**, choose the **Action** you want carried out, then click **Submit**.

Virtualizor confirms once the timer is saved. The schedule is held by the host node, not inside your VPS, so it still fires if the guest operating system is busy, hung or powered off.
## What Each Action Does
- **Start**: boots a VPS that is currently powered off. Useful as the second half of a pair, for example stop at 23:00 and start at 06:00.
- **Stop** (shut down): asks the guest operating system to shut down cleanly. This relies on the guest responding to the ACPI power signal.
- **Restart**: a reboot, equivalent to clicking restart by hand at that moment.
- **Power off**: cuts the virtual power immediately, with no chance for the guest to flush writes or close databases. Treat it the same way you would treat pulling the plug on a physical machine, and reserve it for a VPS that is already unresponsive.
For the manual equivalents of these actions, see [How to Start or Boot Your VPS in Virtualizor](/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/), [How to Force or Gracefully Shut Down a VPS in Virtualizor](/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/) and [How to Reboot or Restart a VPS in Virtualizor](/virtualizor/how-to-reboot-or-restart-a-vps-in-virtualizor/).
## Before You Point a Timer at a Production VPS
**The classic mistake is a forgotten timer.** Somebody sets a shutdown for a one-off maintenance window, the maintenance finishes early, and nobody clears the schedule. Days later the VPS goes down in the middle of the working day and the outage looks like a hardware fault. There is no confirmation prompt at the moment the timer fires and no warning email beforehand, so nothing tells you it is coming.
Protect yourself with three habits:
- Set a calendar reminder for the same date and time you enter in Virtualizor, so a human is watching when it fires.
- If the plan changes, delete the timer straight away rather than leaving it to fire harmlessly. See [How to Delete the Self-Shutdown Timer in Virtualizor](/virtualizor/how-to-delete-the-self-shutdown-timer-in-virtualizor/).
- Re-open **Self Shut Down** after saving and confirm the stored date, time and action read back the way you intended. To adjust one, see [How to Edit the Self-Shutdown Timer in Virtualizor](/virtualizor/how-to-edit-the-self-shutdown-timer-in-virtualizor/).
## Things Worth Knowing
- **The time is server time, not your time.** Virtualizor carries the action out at the time specified on the server hosting your VPS. If you are working from a different time zone to the node, convert first. Get this wrong and the action lands hours away from where you expected it.
- **A timer is one-off, not recurring.** Virtualizor schedules a single action at a single moment. If you need a nightly restart, schedule it inside the guest operating system with cron or a systemd timer instead, so the job is repeatable and lives with the server.
- **Nothing brings the VPS back on its own.** After a stop or a power off, the VPS stays down until you start it manually or a second timer with the **Start** action fires. If the window is meant to be temporary, schedule both halves.
- **A clean shutdown needs a co-operative guest.** The stop action signals the guest through ACPI. If ACPI is disabled for the VPS, or the guest has crashed, the signal is ignored and the VPS keeps running. Test a manual shutdown once before you trust an unattended one.
- **Applications do not know a timer exists.** Databases, queue workers and long-running jobs get whatever notice the guest gives them and no more. Stop application services yourself in the run-up to a scheduled stop if data consistency matters.
## Troubleshooting
**Symptom**: the scheduled time passed and nothing happened. Check the clock first, since the schedule runs on server time rather than your local time. Then re-open **Self Shut Down** and confirm the timer is still stored. A timer saved against a different VPS in the list is the other common cause.
**Symptom**: the stop action fired but the VPS is still online. The guest did not act on the ACPI shutdown signal. Confirm ACPI is enabled for the VPS and that the guest shuts down cleanly when you trigger it by hand. As a last resort the power off action will bring it down regardless, at the cost of an unclean stop.
**Symptom**: the VPS went offline with no explanation. Check for a forgotten timer before assuming a fault. Open **Self Shut Down** for that VPS and look at what is stored there.
**Symptom**: the **Self Shut Down** option is not visible. The available features depend on your VPS product and the permissions set on the account. Open a support ticket with Noiz and the option can be checked for you.
## Need a Hand?
If you would rather Noiz scheduled the maintenance window, or a timer has taken a production server offline and you need it back, open a support ticket from your Noiz client area with the VPS hostname and the time the action was meant to run. Noiz can inspect the schedule on the host node and bring the VPS back up for you.
# How to Start Your VPS in Rescue Mode Using Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-start-your-vps-in-rescue-mode-using-virtualizor/
Rescue mode is the tool you reach for when your VPS will not boot, when a configuration change has locked you out, or when a filesystem problem is stopping the operating system from starting normally. This guide shows you how to switch it on from the Virtualizor Enduser Panel on your Noiz VPS, what actually happens when you do, and how to get at your data once you are in.
The product is called **Virtualizor** (not "Virtualizer"); you may also see it referred to simply as the VPS control panel in your Noiz welcome email.
**Last reviewed:** 27 July 2026, against the current Virtualizor release and its Enduser Panel. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor Docs: Rescue Mode](https://www.virtualizor.com/docs/enduser/rescue-mode)
- [Virtualizor Docs: Manage VPS](https://www.virtualizor.com/docs/enduser/manage-vps/)
- [Virtualizor Docs: Enduser Panel](https://www.virtualizor.com/docs/enduser/)
## What Rescue Mode Actually Does
This is the part most guides skip, and it is the part that saves you an hour of confusion.
Rescue mode does **not** repair your VPS, and it does not boot your operating system in a reduced state. Instead, Virtualizor boots your VPS from a small, separate, Debian-based rescue system held on the host. Your own disk is left untouched and is simply attached to that rescue system, so you can mount it and work on it as an ordinary block device.
Two consequences follow from that, and both catch people out:
- **Your sites, mail and services stay offline for as long as rescue mode is on.** Nothing from your installed operating system is running. Rescue mode is a maintenance window, not a fallback that keeps you serving traffic.
- **The password you set is the rescue system's root password, not your VPS root password.** You are logging in to a different machine that happens to have your disk plugged into it. Your own root password is irrelevant here, which is exactly why rescue mode works when you have lost or broken it.
## Prerequisites
- Your Virtualizor Enduser Panel login, from your Noiz VPS welcome email.
- An SSH client, or access to the VNC console if SSH will not connect. See [How to Access Your VPS via the VNC Console in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/).
- A KVM-based or Xen-based VPS. Virtualizor supports rescue mode on KVM, Xen HVM and Xen PV. If the **Rescue Mode** option does not appear on your Manage VPS page, your VPS runs a virtualisation type that does not offer it, and Noiz support can boot a rescue environment for you instead.
- Somewhere to copy data to, if recovery rather than repair is the goal.
## Enable Rescue Mode
### 1. Log in to the Virtualizor Enduser Panel
Use the panel address and credentials issued with your VPS.
### 2. Open the VPS list
From the left side panel, click **List VPS**.

### 3. Open the VPS you want to rescue
Hover over the appropriate VPS so its row is highlighted, then click the **Manage** icon on that row.

### 4. Open the Rescue Mode tab
On the Manage VPS page, click **Rescue Mode**.

### 5. Set a rescue password and enable
Enter a password, then choose **Enable Rescue Mode**. Treat this as a real credential: it grants root on a machine that has your entire disk attached to it. Use a long, unique password rather than something you will type twice and forget.

Allow a few minutes for the change to take effect. The very first time rescue mode is used on a VPS, Virtualizor has to fetch the rescue template, so three to five minutes is normal; later switches are quicker.
## Get In and Reach Your Data
Once rescue mode is active, connect over SSH to the same IP address as always, as `root`, using the rescue password you just set. If SSH does not connect, use the VNC console instead.
You are now on the rescue system, so your own filesystem is not mounted yet. List the attached block devices first:
```
lsblk
```
Identify your VPS's root partition in that output, then mount it. Device naming varies by virtualisation type and partition layout, so use what `lsblk` actually shows you rather than copying a device name from a guide:
```
mkdir -p /mnt/vps
mount /dev/vda1 /mnt/vps
ls /mnt/vps
```
Your files are now under `/mnt/vps`. On some container-based VPS types Virtualizor mounts the original disk at `/mnt` for you, so check there before mounting anything by hand.
A few practical notes for the work itself:
- **Copy before you repair.** If the data matters, pull it off the server first with `scp` or `rsync` from your own machine, then start editing configuration files. A rescue session is the wrong time to discover that your fix made things worse.
- **Editing configuration is the common case.** Undoing a bad `/etc/fstab` line, a broken SSH server config or a firewall rule that locked you out is usually a one-line edit under `/mnt/vps/etc`.
- **Resetting a lost root password** is done with `chroot /mnt/vps` followed by `passwd`, so that the change is written into your own system rather than the rescue one.
- **Unmount cleanly** with `umount /mnt/vps` before you disable rescue mode, so nothing is left half-written.
## Turn Rescue Mode Off Again
Rescue mode stays on until you switch it off, and your VPS stays offline the whole time. When the work is done, return to the same **Rescue Mode** tab and choose **Disable Rescue Mode**, then let the VPS boot normally and confirm your services are back.
Full steps are in [How to Disable Rescue Mode in Virtualizor](/virtualizor/how-to-disable-rescue-mode-in-virtualizor/).
## Troubleshooting
**Symptom: Virtualizor says no actions are allowed.** Most VPS actions are deliberately blocked while rescue mode is active. Click the **Reload this page** icon to refresh the panel; the full action set returns once rescue mode has been disabled.
**Symptom: SSH refuses to connect with a host key warning.** This is expected, and it is not an attack. The rescue system is a different machine with a different SSH host key, so your client flags the mismatch. Remove the stale entry on your own computer with `ssh-keygen -R your.vps.ip.address` and connect again. You will see the same warning in reverse when you disable rescue mode and your real system comes back.
**Symptom: SSH does not respond at all.** Give it the full three to five minutes on a first use. If it still will not connect, reach the rescue system through [the VNC console](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/), which does not depend on networking inside the VPS at all.
**Symptom: the password is rejected.** Remember that rescue mode wants the password you typed on the Rescue Mode screen, not your usual VPS root password. If in doubt, disable rescue mode, then enable it again with a freshly set password.
**Symptom: mount reports the filesystem is already mounted or in use.** The disk may already be attached at `/mnt`. Run `lsblk` and `mount | grep /mnt` to see what is currently in place before mounting again.
**Symptom: websites and email are down while you work.** That is rescue mode behaving correctly, because your own operating system is not running. Plan the session accordingly and disable rescue mode as soon as the repair is complete.
## Need a Hand?
If your VPS will not boot even after rescue mode, or you are not confident working on a broken filesystem, open a ticket from your Noiz client area and the support team will take a look with you. If your VPS is on a Noiz managed plan, ask support to handle the rescue and repair rather than working through it yourself.
# How to Start or Boot Your VPS in Virtualizor
Source: https://docs.noiz.ie/virtualizor/how-to-start-or-boot-your-vps-in-virtualizor/
If your VPS is offline, you can power it back on yourself from the Virtualizor end user panel. No support ticket is needed for a routine start. This guide shows you where the control lives, what to expect while the machine boots, and what to check when a VPS refuses to stay running.
Virtualizor and other panels use several words for the same action. **Start**, **Boot** and **Power On** all mean the same thing here: bringing a stopped virtual machine back to life from cold.
**Last reviewed:** 27 July 2026, against the current Virtualizor release. This guide is written for Noiz hosting and is kept current against Virtualizor. It complements, and does not replace, the official Virtualizor documentation linked below.
### Official Documentation Reference
- [Virtualizor End User documentation](https://www.virtualizor.com/docs/enduser/)
- [Virtualizor: Manage VPS (End User panel)](https://www.virtualizor.com/docs/enduser/manage-vps/)
## Prerequisites
- An active Noiz VPS with Virtualizor end user panel access.
- The panel address, username and password supplied with your VPS details. Virtualizor's end user panel listens on port `4083` over HTTPS by default, so the address usually looks like `https://yourserver.example.com:4083`.
- A VPS that is genuinely stopped rather than suspended. A suspended VPS will not start until the suspension is lifted, and the panel will tell you so.
## Start the VPS
### Step 1: Log in to Virtualizor
Log in to your Virtualizor control panel with the credentials Noiz issued for the VPS. These are separate from your Noiz client area login.
### Step 2: Open the VPS list
In the left side panel, click **List VPS**. This page shows every virtual machine on your account along with its current power state, so it is also the quickest way to confirm that the VPS really is offline rather than unreachable for some other reason.

### Step 3: Open the VPS you want to start
Hover your mouse over the row for the appropriate VPS. The line will highlight. Click the **Manage** icon in that highlighted row to open the management screen for that machine.

If you have more than one VPS, check the hostname and IP address in the row before you click. Starting the wrong machine is harmless, but starting the wrong one while you are troubleshooting another will cost you time.
### Step 4: Click Start
On the top right of the management screen, click the **Start** icon. The panel queues the power-on task and the status indicator switches to online once the hypervisor has brought the machine up.

## What to Expect After Starting
- Virtualizor reports the VPS as online as soon as the virtual machine is powered on. That is not the same as the VPS being ready to use.
- The operating system then boots and starts its own services. Allow a few minutes before you expect SSH, a web server, or a mail service to answer.
- If the VPS was previously powered off hard rather than shut down cleanly, the filesystem may run a consistency check on the next boot. That can add several minutes on a large disk, and it is normal.
- Test with a ping to the VPS IP address first, then SSH. If ping answers but SSH does not, the machine is up and a service inside it is still starting or has failed.
## Troubleshooting
**Symptom: the Start icon is greyed out or missing.** The VPS is already running, or your account does not have power control for that machine. Check the status shown on the **List VPS** page first.
**Symptom: the VPS starts and immediately stops again.** This is almost always something inside the virtual machine rather than the panel. The usual causes are a full disk, a corrupted or half-finished kernel update, or a boot order that is pointing at an empty virtual CD or ISO instead of the disk. Watch the boot messages on the console to see which.
**Symptom: nothing happens when you click Start.** Refresh the page and check the status again. Power tasks are queued, so a busy node can take a moment to act. If the state does not change, the VPS may be suspended.
**Symptom: the panel says the VPS is suspended.** A suspended VPS cannot be started from the end user panel by design. Suspensions are applied for account or abuse reasons and are lifted by Noiz, not by the panel. Open a support ticket.
**Symptom: the VPS is online in Virtualizor but you cannot reach it.** The virtual machine is running and the problem is inside it: a firewall rule, a network configuration change, or a service that failed to start. Use the VNC console to log in directly and look, since VNC does not depend on the VPS network being healthy. See [How to Access VPS via VNC in Virtualizor](/virtualizor/how-to-access-your-vps-via-the-vnc-console-in-virtualizor/).
## Related Power Controls
- [How to Forcefully or Gracefully Shut Down Your VPS in Virtualizor](/virtualizor/how-to-force-or-gracefully-shut-down-a-vps-in-virtualizor/)
- [How to Reboot or Restart Your VPS in Virtualizor](/virtualizor/how-to-reboot-or-restart-a-vps-in-virtualizor/)
Use **Restart** rather than **Power Off** followed by **Start** whenever the VPS is still responsive. A restart asks the operating system to close down cleanly first, which avoids the filesystem check and the risk of losing unwritten data.
## Need a Hand?
If your VPS will not start, keeps stopping on its own, or comes up without its services, open a ticket from the Noiz client area with the VPS hostname and the time the problem started. Noiz can inspect the hypervisor side of the machine and confirm whether the fault sits with the node or inside your operating system.
# Debunking Common WordPress Security Myths
Source: https://docs.noiz.ie/wordpress/debunking-common-wordpress-security-myths/
This guide separates WordPress security fact from fiction. A handful of persistent myths lead site owners to spend their effort in the wrong places: bolting on measures that do little, while neglecting the few that genuinely protect a site. Here you will find the four most common WordPress security myths named plainly, the reality behind each, and then the small set of measures that actually reduce your risk. It is written for Noiz clients who run their own WordPress site, and it focuses on the application layer, the part you control from inside WordPress, because the server and network layer is hardened for you at the hosting level. This article deliberately names categories of tool rather than endorsing any single plugin, and several of the measures it recommends are built into WordPress itself.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Hardening WordPress (WordPress Developer Resources)](https://developer.wordpress.org/advanced-administration/security/hardening/): the official, layered guide to reducing risk, covering updates, strong credentials, file permissions and more.
- [Roles and Capabilities (WordPress Documentation)](https://wordpress.org/documentation/article/roles-and-capabilities/): the built-in user roles (Administrator, Editor, Author, Contributor, Subscriber) and exactly what each can do.
- [Enabling auto-updates for plugins and themes (WordPress Documentation)](https://wordpress.org/documentation/article/plugins-themes-auto-updates/): how to switch on automatic updates from the dashboard, a feature built into WordPress core since version 5.5.
- [WordPress Backups (WordPress Developer Resources)](https://developer.wordpress.org/advanced-administration/security/backup/): the official guidance on what a complete, restorable backup consists of and how often to take one.
- [Two-Factor (WordPress Plugin Directory)](https://wordpress.org/plugins/two-factor/): the community-maintained two-factor authentication plugin, the closest thing to an official implementation while 2FA is not yet in core.
- [State of WordPress Security in 2026 (Patchstack)](https://patchstack.com/whitepaper/state-of-wordpress-security-in-2026/): independent research on where WordPress vulnerabilities actually come from, cited for the figures in this guide.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an Administrator.
- A recent, restorable backup of your site (files and database) before you change any settings, roles or plugins.
- An understanding that this guide covers the application layer. Server and network hardening is handled at the hosting level and is described briefly near the end.
## First, Where the Risk Actually Lives
Almost every WordPress security myth survives because people misjudge where the danger comes from. So it is worth being precise before tackling the myths one by one.
Independent security research that tracks WordPress vulnerabilities across the whole ecosystem tells a consistent story. In 2025, over eleven thousand new WordPress vulnerabilities were catalogued, and roughly nine in ten of them were found in **plugins**, with most of the remainder in **themes**. WordPress core itself accounted for only a small handful of issues in the entire year, all of them rated low priority. A decade ago plugins were blamed for about half of WordPress vulnerabilities; that share has since climbed to more than nine in ten. The lesson is not that WordPress is dangerous. It is that the risk sits in the extra code you add to it, and in weak passwords and out-of-date software, far more than in WordPress itself.
Two other findings from that research shape everything below. First, nearly half of the vulnerabilities disclosed in 2025 had **no fix available** from the developer at the moment they became public, which is why choosing well-maintained components and keeping your list short matters so much. Second, exploitation is **fast and automated**: a meaningful share of newly disclosed flaws were being attacked within hours of disclosure, and the majority within a week. Attackers are not hand-picking sites; they are running scripts against the entire internet.
Keep that picture in mind. It is the thread that runs through all four myths.
## Myth 1: "WordPress Is Inherently Insecure"
This is the myth that WordPress, because it is so common and so often mentioned in reports of hacked sites, must be a fundamentally insecure platform.
**The reality.** WordPress powers over 40% of all websites, so it is both the biggest target and the most visible one; when any site on it is compromised, it is a WordPress story. But core WordPress is developed by a dedicated security team, is reviewed by a very large community, and ships security fixes promptly. As the figures above show, core is responsible for a tiny fraction of the vulnerabilities found each year. When a WordPress site is compromised, the cause is overwhelmingly one of a short list of things that have nothing to do with core being weak: an outdated plugin or theme, a plugin that was poorly written to begin with, a guessable or reused password, or an outdated version of WordPress that the owner never updated. Blaming "WordPress" for these is like blaming the car for a driver who never serviced it and left the doors unlocked. The platform gives you the tools to run a secure site; the myth is that the platform itself is the problem.
## Myth 2: "Security Through Obscurity Keeps Attackers Out"
This myth holds that hiding things is a security strategy: move the login page to a secret address, rename or hide the `wp-admin` area, change the database table prefix, and strip the WordPress version number out of your pages, and attackers will not find you.
**The reality.** Obscurity is a thin curtain, not a lock. Automated attacks do not read your home page and politely give up when they cannot see a version number; they fire known exploits at every site they can reach and see what sticks. A hidden login URL can be rediscovered, a renamed admin path can be found, and none of it patches the actual vulnerability an attacker is aiming at. The genuine danger of this myth is the **false confidence** it creates: an owner who has "hidden" their login often believes the job is done and skips the measures that would really have protected them.
There is a fair, narrow point buried in the myth. Measures like changing the login URL or limiting who can reach `wp-admin` can reduce the sheer volume of automated login noise hitting your site, which is a real and welcome benefit. Treat that as tidying, not defence. Obscurity is at best a thin extra layer on top of real controls, and it is never a substitute for keeping software updated, using strong authentication, and limiting who has access. If a measure only works while a secret stays secret, it is not protecting you.
## Myth 3: "My Site Is Too Small to Be Worth Attacking"
This is perhaps the most comforting myth and the most dangerous: the belief that a small business site, a personal blog or a low-traffic shop is beneath a hacker's notice, so security can wait.
**The reality.** Almost no attack on a WordPress site is a person deciding you are interesting. Attacks are **automated and indiscriminate**. Bots crawl the entire internet looking for any site running a vulnerable plugin, a weak password or an out-of-date version, and they neither know nor care how small you are. As noted above, newly disclosed flaws are often exploited within hours, at machine speed and enormous scale.
Small sites are attacked for what they can be turned into, not for the content they hold. A compromised site is valuable as a place to send spam email, to host phishing pages or malware, to inject hidden links that manipulate search rankings, to redirect your visitors to scam pages, or simply as one more machine in a network used to attack others. Your visitor numbers are irrelevant to any of those uses. "Too small to target" confuses being uninteresting to a human with being invisible to a script, and scripts are the only thing scanning you.
## Myth 4: "I Installed a Security Plugin, So I'm Covered"
This myth treats a security plugin as a switch: install one, and the site is now secure and needs no further thought.
**The reality.** A reputable security plugin is a useful layer. It can add a firewall, limit login attempts, scan for malware and warn you about known vulnerabilities, and there is nothing wrong with running one. But it is one layer, not a force field, and believing otherwise is where the harm comes in. A security plugin cannot save a site that is running an abandoned plugin with a public, unpatched vulnerability, and it cannot protect an Administrator account whose password is `password123` and is reused on a site that has already been breached. It closes some doors while the fundamentals leave others wide open.
Two further points puncture this myth. First, a security plugin is itself code with deep access to your site, and like any plugin it can contain vulnerabilities of its own; it is not a category that is magically immune. Second, paying for a premium plugin does not buy you safety. Independent research has found that paid components actually carried **around three times more known-exploited vulnerabilities** than free ones, partly because closed, paid code receives less independent scrutiny. A security plugin earns its place alongside the fundamentals below. It does not replace them, and it must be kept updated like everything else.
## What Actually Works: The Four Fixes That Matter
Strip away the myths and WordPress security comes down to a small number of high-value habits. None of them is exotic, and most are built into WordPress itself. If you do only these four things well, you will be ahead of the large majority of sites that get compromised.
### 1. Keep Everything Updated
This is the single highest-value security measure there is, and it directly answers the reality behind every myth above: most compromises exploit a flaw for which a fix already existed and was never applied. Keep **WordPress core, every plugin, every theme** and, where you can influence it, **PHP** current.
You do not need a plugin for this, because updating is built into WordPress. Core has installed minor and security releases automatically since version 3.7. Since version 5.5 you can switch on automatic updates for individual plugins and themes, and for major core releases too, directly from the dashboard: the **Automatic Updates** column on **Plugins > Installed Plugins** and the equivalent on **Appearance > Themes** let you enable them one item at a time. Turning on automatic updates for anything you are confident will not break your site is a sensible default. For plugins and themes where an update might change behaviour, review and apply updates promptly by hand instead. Either way, the gap between a fix being released and you applying it is exactly the window attackers race to exploit, so make it short.

A short, well-maintained plugin list makes this far easier. Every plugin and theme you remove is one fewer thing to keep patched and one fewer potential way in. Auditing your plugins and deleting anything unused or abandoned is a security measure in its own right.

### 2. Strong, Unique Passwords and Two-Factor Authentication
The login form is the front door, and weak or reused passwords are how a large share of sites are entered without any exploit at all. Two habits close this off almost entirely.
First, use a **strong, unique password** for every account, especially every Administrator account. Unique is the operative word: a password reused from another service that has been breached is already in attackers' hands, no matter how long it is. A password manager makes this effortless by generating and remembering a different long password for each account, so you never have to. WordPress itself nudges you here, suggesting a strong random password whenever you create or edit a user.
Second, switch on **two-factor authentication (2FA)** for your administrator-level accounts. With 2FA, a stolen or guessed password is no longer enough on its own, because logging in also requires a second, changing code from a device only you hold. This is the single most effective defence against automated login attacks and password reuse. As of mid-2026, 2FA is not yet part of WordPress core, though a proposal to bring it in is under active discussion, so for now you add it with a reputable plugin. The community-maintained Two-Factor plugin is the closest thing to an official implementation and supports authenticator apps that generate time-based codes (TOTP), emailed one-time codes and single-use backup codes, with passkeys and hardware keys (WebAuthn) available through a companion. Pair 2FA with a limit on failed login attempts, which many security plugins provide, so that automated password guessing is stopped early.
One related good habit: if you connect apps, mobile clients or services to your site, do not hand them your main password. WordPress has **application passwords** built in, letting you issue a separate, revocable password for each connected app, so you can cut one off without changing your own login.
### 3. Least-Privilege User Roles
Not everyone who touches your site needs the keys to all of it, and handing out Administrator access freely is one of the most common self-inflicted risks. WordPress has a capable permissions system built in, with five roles on a standard single-site install: **Administrator** (full control of the site), **Editor** (manage and publish anyone's posts and pages), **Author** (write and publish their own posts), **Contributor** (write but not publish) and **Subscriber** (read and manage their own profile only). A sixth role, Super Admin, exists only on Multisite networks.
The principle is least privilege: give each person the **least powerful role** that still lets them do their job. A guest writer needs Author or Contributor, not Administrator. A person who only manages content across the site needs Editor, not Administrator. Reserve Administrator for the small number of people who genuinely maintain the site, because every Administrator account is a complete set of keys, and every extra one is another account whose compromise means the compromise of your whole site.

Two supporting habits matter as much as the roles themselves. Give people **their own named accounts** rather than sharing one login, so access can be traced and removed per person. And review your user list regularly, **removing accounts** for people who have left or plugins you no longer use; a forgotten Administrator account belonging to a former contractor is a live risk that quietly sits there until someone finds it.
### 4. Reliable, Tested Backups
Backups are not a way to prevent a compromise; they are what turns a disaster into an inconvenience when one happens anyway. Even a perfectly maintained site can be hit by a newly discovered flaw for which no fix yet exists, and, as noted earlier, nearly half of disclosed vulnerabilities have no patch available on the day they go public. A good backup is your guaranteed way back.
A useful backup has three properties. It is **complete**, covering both your files and your database, because one without the other cannot rebuild the site. It is **kept separately** from the live site, so that whatever damages the site does not take the only copy with it. And, most overlooked of all, it is **tested**: a backup you have never actually restored is a hope, not a plan, and the moment of a live emergency is the worst possible time to discover it does not work. Noiz keeps server-level backups of your hosting as a safety net, but you should also keep and understand your own application-level backups that you can restore yourself, whether through your hosting tools or a reputable backup plugin. Take them on a schedule that matches how often your site changes, and periodically restore one to a staging copy to prove it works.
## Where Server Hardening Fits
Everything above is the application layer: the part of security you own and control from inside WordPress. There is a second layer beneath it, the **server and network**, covering the operating system, the web server, encrypted connections (TLS), firewalling and isolating sites from one another. On Noiz hosting that layer is hardened and maintained for you, so your attention is best spent on the application-layer measures in this guide, which are the ones attackers most often exploit and the ones no host can apply on your behalf.
It is worth understanding the split, because a myth of its own is that "the host will protect me from everything". Your host secures the server; you secure the WordPress application, its plugins and themes, its users and its passwords. For a practical, ordered list of those application-layer actions, work through the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/), which turns the fundamentals above into concrete steps.
## Quick Myth-to-Fact Recap
- **"WordPress is insecure."** Core is one of the most reviewed and promptly patched platforms there is; the risk lives in add-ons, weak passwords and outdated software, not in core.
- **"Hiding things keeps me safe."** Obscurity is a thin curtain that reduces noise at best; it patches nothing and breeds false confidence. Rely on updates, strong auth and least privilege.
- **"I'm too small to target."** Attacks are automated and indiscriminate; your size is irrelevant to a script, and a small site is valuable to abuse for spam, malware and redirects.
- **"A security plugin covers me."** It is one helpful layer, not a force field; it cannot save a site that neglects the fundamentals, and paid does not mean safer.
## Troubleshooting
- **Symptom**: you enabled two-factor authentication and then lost access to your phone or authenticator app. This is exactly what backup codes are for, so save them somewhere safe the moment you set 2FA up. If you have no backup codes and are locked out, Noiz support can help you regain access; disabling the 2FA plugin at the file level is a last resort best done with support.
- **Symptom**: after enabling automatic updates, an update changed how your site looks or behaves. Test major or unfamiliar updates on a staging copy first, and keep automatic updates for the components you are confident about while applying the riskier ones by hand. A recent backup lets you roll back if an update goes wrong.
- **Symptom**: you downgraded a user's role and they can no longer do part of their job. Roles are deliberately tiered; move the person up one level to the least powerful role that covers their actual tasks, rather than jumping straight to Administrator.
- **Symptom**: you suspect a site has already been compromised, for example unexpected admin accounts, strange redirects or spam pages. Do not simply install a security plugin and assume it is cleaned; a compromise needs proper investigation and, often, a restore from a known-good backup. Open a ticket with Noiz support straight away.
If you are unsure which of these measures your site already has in place, or you would like help enabling two-factor authentication, tightening user roles or setting up backups you can trust, open a support ticket with the Noiz support team. Include your domain and mention whether you have a staging copy available. On managed plans the Noiz support team can put these fundamentals in place for you and keep them current.
# Fix Contact Form 7 Not Working With All-In-One Security (AIOS) in WordPress
Source: https://docs.noiz.ie/wordpress/fix-contact-form-7-not-working-with-all-in-one-security-aios-in-wordpress/
If Contact Form 7 stops working on your WordPress site, hangs after a visitor clicks **Send**, or fails with a server error, the cause is often the All-In-One Security (AIOS) plugin blocking WordPress REST API requests. The submit button spins, the message never sends, and no clear error appears to the visitor. This guide explains why that happens and gives you two ways to fix it while keeping your firewall in place.
**Last reviewed:** 27 July 2026, against All-In-One Security (AIOS) **5.4.9** (latest stable) and Contact Form 7. This guide is written for Noiz hosting and is kept current against both plugins. It complements, and does not replace, the official plugin documentation linked below.
### Official Documentation Reference
- [All-In-One Security (AIOS) on WordPress.org](https://wordpress.org/plugins/all-in-one-wp-security-and-firewall/)
- [Contact Form 7 official documentation](https://contactform7.com/)
- [WordPress REST API Handbook](https://developer.wordpress.org/rest-api/)
## Prerequisites
- Administrator access to your WordPress dashboard.
- Both **All-In-One Security (AIOS)** and **Contact Form 7** installed and active.
- Optional, for diagnosis: the ability to enable `WP_DEBUG` in `wp-config.php`.
## Why the form hangs
Contact Form 7 submits messages through the WordPress REST API rather than a classic form post. When AIOS has **Disallow unauthorized REST requests** switched on, it only allows REST calls from logged-in users. A visitor filling in your contact form is not logged in, so their submission is blocked before it reaches the form handler. The button keeps spinning and the message is never delivered.
- **The error is hidden.** Current AIOS versions reject the blocked call with a `403` response, which the form does not surface to the visitor. On the front end the form simply appears stuck.
- **Turn on debugging to confirm it.** Set `WP_DEBUG` to `true` in `wp-config.php` and reproduce the submission. The blocked REST request (often recorded as a `500` in the PHP error log) confirms the REST API restriction is the culprit rather than a mail or SMTP fault.
## Two ways to fix it
Both fixes live on the same AIOS screen. In your WordPress dashboard, go to **WP Security > Firewall**, open the **PHP rules** tab, then choose **WP REST API** from the *Rules* list on the left. The two controls you need are on this page.

### 1. Whitelist the Contact Form 7 route (recommended)
This is the safer fix because it keeps the REST API firewall switched on and only permits the one route your contact form needs. Contact Form 7 registers its own REST route, so it appears automatically in the AIOS list as `contact-form-7`; you do not add it by hand.
1. On the **WP REST API** page, scroll to the **Whitelist REST routes** section.
2. Switch the **contact-form-7** toggle on.
3. Save your changes.
4. Reload your site and submit the contact form to confirm the message now sends.
Whitelisting a route allows it for everyone, including logged-out visitors, which is exactly what a public contact form requires. Everything else stays protected by the firewall. If `contact-form-7` is not listed, make sure the plugin is active and up to date, then reload the AIOS page so its routes are re-registered.
### 2. Turn off the REST API block (fallback, less secure)
If the whitelist option is unavailable or you need a quick fix, you can switch the firewall rule off entirely. This allows all REST requests again, so treat it as a fallback rather than the preferred option.
1. On the same **WP REST API** page, find **Disallow unauthorized REST requests**.
2. Switch it off so unauthorised REST access is no longer blocked.
3. Save your changes.
4. Test your contact form to confirm it is working again.
## Verify the fix
After applying either fix, submit a real test message and confirm the success notice appears and the email arrives. If the form still hangs after whitelisting the route, check for a second security or firewall layer (for example a caching or bot-protection plugin) that may also be blocking REST calls, and confirm Contact Form 7 mail is configured correctly.
If your site runs on a Noiz managed WordPress or hosting plan, open a support ticket from your Noiz client area and the team can apply and verify this change for you.
# How to Accept Payments on Your WordPress Site
Source: https://docs.noiz.ie/wordpress/how-to-accept-payments-on-your-wordpress-site/
This guide shows you how to take real money from visitors on your WordPress site: a one-off card payment, a donation, a booking deposit, or a recurring subscription, without turning your website into a full online shop. It explains the pieces involved (a payment processor, a checkout, and usually a small plugin), how to pick a processor that actually suits a South African or Irish business, how to keep card details off your server so the security burden stays small, and how to tell when a heavyweight store platform such as WooCommerce is more than you need. The words for this vary: a payment processor is also called a payment gateway or a merchant provider, a one-off charge is a single or single-payment transaction, and a repeating charge is a subscription, recurring payment or membership. The advice here applies whichever labels you meet, and it deliberately describes what a good setup must do rather than pushing any one plugin or provider.
One thing to clear up before you start, because it confuses people. This guide is about collecting money *from your own visitors* on your own WordPress site. That is a completely separate matter from paying your Noiz hosting invoice, which you do in the Noiz client area using the payment options offered there. The checkout you build on your WordPress site has nothing to do with how you pay Noiz.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress, payment-processor and PCI documentation linked below. It is general guidance on accepting payments, not legal, tax or financial-compliance advice; where those matter to your business, confirm your obligations with a qualified adviser.
### Official Documentation Reference
- [WordPress Plugin Directory (WordPress.org)](https://wordpress.org/plugins/): where you find and vet the payment and payment-form plugins referred to in this guide, with ratings, active-install counts and last-updated dates.
- [Stripe Checkout and Payment Links (Stripe Docs)](https://docs.stripe.com/payments/checkout): how a hosted, processor-run checkout collects card details so they never reach your own site.
- [PayPal Checkout (PayPal Developer)](https://developer.paypal.com/docs/checkout/): how PayPal's hosted buttons and checkout flow work for one-off and recurring payments.
- [Strong Customer Authentication (Stripe Docs)](https://docs.stripe.com/strong-customer-authentication): why European cards trigger an extra verification step, and how a modern checkout handles it for you.
- [PCI DSS Document Library (PCI Security Standards Council)](https://www.pcisecuritystandards.org/document_library/): the current card-industry security standard (PCI DSS v4.0.1) and the self-assessment questionnaires that apply to small merchants.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an administrator, so you can install a plugin or add a payment block.
- Your site is served over **HTTPS** (its address begins `https://` and shows a padlock). This is not optional for taking payments, and Noiz hosting supports free SSL certificates so every site can meet it.
- A business email address and, for most processors, some business or identity details to open a merchant account. You do not need this before reading, but you will need it before you can accept a live payment.
## First Decision: Do You Actually Need a Shop?
The most expensive mistake at this stage is reaching for a full e-commerce platform when you only need to take a payment. WooCommerce and platforms like it are excellent, but they are *shops*: they bring a product catalogue, a cart, stock levels, shipping rules, tax tables, order management and a long tail of extensions. All of that is machinery you then have to configure, secure and keep updated. If you are not running a shop, it is weight you carry for nothing.
Ask yourself what you are really selling. If the honest answer is one of the following, you almost certainly do not need a store:
- A single product, service or digital download.
- Donations or "pay what you like" contributions.
- A booking deposit, consultation fee or invoice payment.
- A membership, course or subscription billed on a schedule.
- A handful of fixed-price items with no stock to track and nothing to ship.
For every one of those, a lighter tool does the job: a single **payment button**, a **payment form**, or a **hosted payment link**. Each is faster to set up, faster to load for your visitors, and far less to look after. A full store earns its keep only when you genuinely have a catalogue: many products, variations, stock to manage, shipping to calculate, coupons, and the rest. If in doubt, start light. It is easy to grow into a store later, and painful to strip one back.
## How an Online Card Payment Actually Works
Understanding the shape of a payment saves you from a great deal of confusion later, and it explains why the security side is simpler than it sounds.
Three parties are involved. There is your **visitor** with their card, there is your **WordPress site**, and there is a **payment processor**: the company that is actually licensed to move money between the visitor's bank and yours. Your site's job is not to handle the card. Its job is to hand the visitor over to the processor at the right moment, for the right amount, and to find out afterwards whether the payment succeeded.
The card details are collected by the processor, not by you, and this is the single most important idea in the whole guide. A well-built integration does this in one of three ways:
- **Hosted checkout or payment link (redirect).** Your visitor clicks, and their browser goes to a secure page hosted by the processor to enter their card, then returns to your site. The card never touches your server at all. This is the simplest and safest option and often needs no plugin.
- **Embedded fields (iframe).** The card fields appear on your own page, but they are actually served from the processor inside a secure frame, so the numbers still go straight to the processor and bypass your server. This looks seamless while keeping the card off your site.
- **Raw card handling on your own server.** Your site collects and transmits the card number itself. Avoid this. It drags you into the heaviest security obligations and there is no good reason for a small site to take it on.
In the safe methods, the processor turns the card into a harmless **token**, a reference it uses to take the money, and that token is all your site ever sees. Because the card details never reach your WordPress install or Noiz's servers, there is nothing sensitive there for an attacker to steal, and your own security duties shrink to the lightest tier. Keep that principle in mind and most of the later advice follows naturally.
## Choosing a Payment Processor
The processor is the decision that matters most, and it is one where advice written for a United States audience will actively mislead a South African or Irish business. Choose on the criteria below rather than on which name you have heard of.
### The South African Reality (Read This Before You Pick)
Two things routinely trip up South African site owners:
- **Stripe does not offer standalone accounts to South African businesses.** Stripe is superb and widely written about, but a business registered in South Africa cannot simply open a Stripe account and settle in rand. Stripe's South African presence runs through its "extended network" via a partner processor it owns (Paystack). In practice, a South African merchant who wants Stripe-style card processing paid out in rand signs up with that local processor rather than with Stripe directly. If your business is registered in a country Stripe supports directly (Ireland among them), this does not apply to you and you can use Stripe as written.
- **PayPal in South Africa is built for money coming *in* from abroad.** You can receive PayPal payments in South Africa, but the balance is held in a foreign currency and you withdraw it to your local bank through a currency conversion. That makes PayPal excellent for selling to international customers and inefficient for selling to South Africans who just want to pay in rand, because the conversion eats into every sale.
The practical upshot: if most of your customers are South African and pay in rand, look first at processors built for the South African market, which settle directly to a local bank account in rand and offer the payment methods your customers actually use, including cards and instant bank transfer (EFT). If your customers are mostly international, a globally recognised processor at checkout is worth more. Many businesses end up offering one of each.
### A Comparison You Can Actually Use
Rather than ranking brands, weigh any processor you are considering against these questions. The answers, taken together, point clearly to the right choice for *your* business.
- **Can your business even open an account with it?** Check your country is supported for a settling account, not just for paying. This is the question that eliminates Stripe direct for South African merchants, as above.
- **What currency does it pay you in?** If you sell in rand, a processor that settles in rand to a local bank avoids conversion losses on every transaction. A processor that settles in a foreign currency is only sensible if your customers are paying in that currency too.
- **Which payment methods do your customers use?** Cards are universal, but South African buyers often expect instant EFT and mobile options, and offering the method people prefer measurably reduces abandoned checkouts.
- **Does it support the kind of payment you need?** Some processors do one-off charges beautifully but handle recurring billing poorly, or vice versa. If you need subscriptions, confirm that up front (see the next section).
- **How does it integrate?** Prefer a hosted checkout, hosted payment link or embedded (iframe) fields, all of which keep card data off your site. Treat any option that wants your server to handle raw card numbers as a reason to look elsewhere.
- **What does it cost, and when do you get paid?** Compare the per-transaction fee, any monthly fee, and the payout delay (some pay out next day, others weekly). For low volumes, a provider with no monthly fee usually wins.
- **Is it trusted at the point of payment?** Visitors abandon checkouts they do not recognise or trust. A familiar, professional-looking payment step converts better than a cheaper one that looks improvised.
Whichever you choose, you will connect it to WordPress with a small plugin (the processor almost always publishes an official one, or names a recommended partner plugin). The plugin is just the bridge; the processor is doing the real work.
## Setting Up One-Off Payments
For a single price, a donation or an invoice, you have two clean routes. Pick whichever fits how much you want to keep inside WordPress.
### Route A: A Hosted Payment Link (Often No Plugin at All)
Most modern processors let you create a **payment link** from inside their own dashboard: you set an amount (or let the payer choose), and the processor gives you a web address that opens a ready-made, secure checkout page. You then simply add that link to a button on your WordPress page.
1. In your processor's dashboard, create a payment link for the amount and description you want, and copy the address it gives you.
2. Edit the WordPress page or post where you want the button. Add a **Buttons** block, type the label (for example `Pay now` or `Donate`), and paste the payment link as its destination.
3. Publish, then click the button yourself to confirm it opens the processor's checkout with the right amount.
This route is the lightest possible: nothing sensitive runs on your site, there is little to maintain, and it is ideal for occasional payments, invoices and donations. Its limit is that the payment happens on the processor's page rather than yours, and it offers less control over the look and over what happens next.
### Route B: A Payment Form or Button Plugin
When you want the payment to feel part of your site, or you want to collect a little information alongside it, install a dedicated payment-form or payment-button plugin. This is a different tool from a full shop: it adds a single form or button, not a catalogue.
1. Choose a plugin from the [WordPress Plugin Directory](https://wordpress.org/plugins/) that officially supports your chosen processor. Favour one that is actively maintained, tested against current WordPress, well reviewed, and widely installed, then install and activate it under **Plugins > Add New Plugin**.
2. Connect it to your processor by pasting in the keys (sometimes called API keys or a client ID) from your processor's dashboard. Start with the **test** keys, not the live ones.
3. Create a payment form or button (a fixed price, a "name your amount" field, or a short form with a few extra fields), set the currency to the one you settle in, and place it on a page using the block or shortcode the plugin provides.
4. Test the whole thing in test mode before switching to live keys (covered under testing, below).
If you are on a managed Noiz plan and would rather not install and wire up a plugin yourself, the Noiz support team can do the setup for you once you have opened your merchant account with the processor. You would still hold the processor account and its keys; Noiz simply connects it to your site.
## Setting Up Recurring Payments and Subscriptions
Charging the same person every month (a membership, a course, a subscription box, a retainer) is a genuinely different job from a one-off charge, and it has two traps worth knowing about before you begin.
### Let the Processor Own the Schedule
The safe way to do recurring billing is to let the *processor* manage the subscription. You define a plan (amount, interval, any free trial) in the processor's dashboard, and a subscription-capable plugin creates and links that plan to your WordPress content, for example unlocking a members' area while the subscription is active. The processor then charges the saved card automatically on schedule, using the token it stored on the first payment. Your site never re-handles the card. Confirm, before you commit, that both your processor *and* your plugin explicitly support recurring billing; not all do, and retro-fitting it is painful.
### European Cards and Strong Customer Authentication
If any of your customers are in Europe, their first payment will usually trigger an extra verification step (a bank prompt on their phone, or a code). This is **Strong Customer Authentication**, required by European rules, and it is a feature, not a fault: it cuts fraud and chargebacks. A modern hosted checkout handles it for you and sets up the subscription so that later automatic charges do not need the customer present. This is one more reason to use the processor's current checkout rather than an older, hand-rolled card form.
### The Renewal Gotcha: WordPress Cron on a Quiet Site
Here is a Noiz-specific point that catches subscription sites out. Many subscription plugins lean on **WordPress's built-in scheduler** (often called wp-cron) to do their housekeeping: retrying a failed renewal, expiring a lapsed membership, sending a reminder. The catch is that this scheduler only runs when someone visits your site. On a busy site that is constant and fine. On a quiet membership site, hours can pass with no visitor, the scheduler does not fire, and renewals or expiries run late.
The dependable fix is to drive the scheduler from a **real server cron job** instead of relying on visitor traffic. On Noiz hosting you can add a scheduled task in your hosting control panel that pings your site's scheduler at a fixed interval (every fifteen minutes is a common choice), which makes renewals fire like clockwork regardless of how quiet the site is. The exact screen depends on your platform, the Plesk panel on the South African servers, DirectAdmin in Ireland, or ISPConfig, but each has a scheduled-tasks or cron section for this. If you are on a managed plan, ask the Noiz support team to set this up; it is a small change that prevents a whole class of "my subscriptions did not renew" problems.
## Checkout Security and PCI Basics
Taking card payments comes with a security standard attached: **PCI DSS**, the Payment Card Industry Data Security Standard, currently at version 4.0.1. Every business that accepts cards is bound by it. That sounds daunting, but for a small WordPress site the burden is small *provided you follow one rule*, and most of this section is really just consequences of that rule.
**The rule: never let card details touch your server.** Use a hosted checkout, a payment link, or embedded processor fields, exactly the safe methods described earlier, so that card numbers go straight from the visitor's browser to the processor. When card data never lands on your site, you fall into the lightest compliance tier (a short self-assessment questionnaire known as SAQ A) rather than the heavy obligations that apply to anyone handling raw card numbers. This single choice is the difference between a five-minute form and a security project.
Around that rule, a handful of straightforward measures keep your checkout trustworthy:
- **Serve the whole site over HTTPS.** Not just the checkout page: modern browsers and processors expect the entire site encrypted, and Noiz hosting includes free SSL certificates so there is no reason not to.
- **Confirm payments from the processor, not from the browser.** A visitor reaching your "thank you" page does not prove they paid; they might have closed the tab, or reached it by accident. Every serious processor can send your site a **webhook**, a direct server-to-server message confirming the payment really succeeded. Make sure your plugin uses it, so access or fulfilment is granted on the confirmed payment, never on the redirect alone.
- **Keep the payment page lean.** The newer parts of PCI DSS, which became effective through 2025, focus on the scripts running on payment pages: unexpected third-party code on a checkout is exactly how card-skimming attacks work. Do not load chat widgets, analytics extras, advertising pixels or decorative scripts on the page where the payment happens. Fewer scripts on that page means less risk and one less thing to justify.
- **Keep everything updated.** WordPress core, your payment plugin and every other plugin. An out-of-date plugin is the most common way a site is compromised, and a compromised site around a checkout is the worst place for it to happen. This sits inside the broader routine covered in the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/), which you should treat as the companion to this guide.
- **Protect the admin account.** A strong, unique administrator password and, ideally, two-factor login. Whoever holds the WordPress admin can change where your money goes, so guard it accordingly.
## Testing Before You Go Live
Never point a new checkout at real cards without testing it first. Every reputable processor gives you a **test** or **sandbox** mode with fake card numbers that behave like real ones without moving any money.
1. With your plugin still on the processor's **test** keys, run a full payment using the processor's published test card details. Confirm the amount, currency and description are all correct.
2. Check that *your side* reacts properly: the order or record appears, the confirmation email sends, and any members' area or download actually unlocks. This is where webhook problems show up, so test it deliberately.
3. For a subscription, force a failed renewal in test mode if the processor allows it, and confirm your site handles the failure the way you expect (a warning, a grace period, or loss of access).
4. Only when all of that works, swap the test keys for the **live** keys, and make one small *real* payment to yourself. Confirm the money reaches your account, then refund it from the processor's dashboard. That single live-and-refund test catches the mistakes that test mode cannot.
## Troubleshooting
- **Symptom**: the payment button or checkout does nothing, or the browser warns the connection is not secure. Your site is not fully on HTTPS. Confirm the address shows a padlock; if not, ensure your SSL certificate is active for the whole site. Noiz hosting provides free SSL, and the Noiz support team can enable it if you are unsure.
- **Symptom**: customers are charged but the order does not appear, or a membership does not unlock. Your site is relying on the browser redirect instead of the processor's confirmation. Enable and test the processor's webhook so fulfilment happens on the confirmed payment. Also check that the webhook address the processor is calling matches your live site.
- **Symptom**: you cannot open a Stripe account for your South African business. This is expected; Stripe does not offer standalone South African accounts. Use a processor built for the South African market that settles in rand, or the partner route through Stripe's extended network. See "The South African Reality" above.
- **Symptom**: money arrives but is worth less than expected. You are likely settling in a foreign currency and losing value on conversion, common with a foreign-currency PayPal balance. If you sell mainly in rand, switch to a processor that pays out in rand to a local bank account.
- **Symptom**: subscription renewals fire late, or lapsed members keep their access. Your site is depending on visitor-triggered scheduling on a quiet site. Set up a real server cron job in your hosting panel to run the WordPress scheduler on a fixed interval, as described under recurring payments, or ask Noiz support to configure it.
- **Symptom**: European customers say the payment "asks for extra confirmation" or fails without it. That is Strong Customer Authentication working as intended. Make sure you are using the processor's current hosted checkout, which presents that step and completes the payment; an older custom card form may not handle it.
If you would like help choosing a processor that fits where your customers are and how you want to be paid, wiring a payment form into your site, setting up reliable subscription renewals, or checking that your checkout keeps card details off your server, open a support ticket with the Noiz support team. Tell them what you are selling, whether it is one-off or recurring, and where most of your customers are based, and they will point you to a setup that suits your business rather than a generic template.
# How to Add a New Category in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-add-a-new-category-in-wordpress/
Categories are how WordPress groups your posts into topics. This guide shows you how to add a new category, what each field on the form actually controls, and the small decisions (slug and parent) that are awkward to change once posts and links exist. A post can belong to more than one category, and categories can be nested, so a little planning at this stage saves tidying up later.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Posts Categories Screen](https://wordpress.org/documentation/article/posts-categories-screen/) (every field on the screen, in detail)
- [Settings Permalinks Screen](https://wordpress.org/documentation/article/settings-permalinks-screen/) (where the `/category/` part of your archive URLs is set)
## Prerequisites
- A WordPress site and your admin login details. If you are not sure where to sign in, see [How to login to WordPress (Admin Dashboard)](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- An account with the **Administrator** or **Editor** role. Authors and Contributors can assign existing categories to their posts but cannot create new ones.
## Categories or tags?
Both group posts, but they behave differently and they are not interchangeable:
- **Categories** are hierarchical, so one category can sit under another. Every post must have at least one, and WordPress falls back to **Uncategorized** if you do not choose one. Treat them as the table of contents for your site.
- **Tags** are flat, optional, and much more granular. Treat them as the index at the back of the book.
A good rule of thumb: if you would put it in the site menu, it is a category. If it only makes sense as a keyword, it is a tag.
## Add a new category
1. Log in to your WordPress dashboard.
2. In the sidebar menu, go to **Posts** and click **Categories**. 
3. Fill in the **Add New Category** form on the left of the screen: 
- **Name** is the label people see, for example `Computers`. Use the wording you want shown in menus and on the archive page.
- **Slug** is the URL-safe version of the name. Leave it blank and WordPress generates one from the name (lower case, spaces turned into hyphens, accents stripped). Fill it in yourself when you want something shorter or cleaner than the name would produce.
- **Parent Category** stays on **None** for a top-level category. Choose an existing category here to make the new one a sub-category of it.
- **Description** is optional. Many themes print it at the top of the category archive page, and several SEO plugins use it as the archive meta description, so it is worth a sentence rather than leaving it empty.
4. Click **Add New Category**.
The category appears in the list on the right straight away, and it is immediately available in the **Categories** panel of the post editor. Its archive page lives at `https://yourdomain.com/category/your-slug/` (replace `yourdomain.com` and `your-slug` with your own).
## Choosing the slug and parent carefully
These two fields are the only part of the form that is genuinely difficult to change later.
- **The slug becomes a public URL.** Renaming it after posts are published breaks any existing link to that archive, including links from search results, newsletters and social posts. Pick it once, keep it short, and use hyphens rather than underscores. If you must change it later, put a redirect in place from the old path to the new one.
- **Nesting shows up in the URL too** when your permalink structure includes the category, so a sub-category of a sub-category produces long, unhelpful addresses. One level of nesting is usually plenty for a blog.
- **A slug cannot clash with an existing page or post slug.** If it does, WordPress silently appends a number, for example `news-2`. Check the Slug column in the list after saving.
- **The `/category/` prefix is site-wide**, not per category. Change it once under **Settings** > **Permalinks** in the **Category base** field if you want something different.
## Put posts into the new category
Creating a category does not move anything into it. Assign posts in whichever way suits the job:
- **One post:** open it in the editor and tick the category in the **Categories** panel in the right-hand sidebar. You can also create a category on the fly from there with **Add New Category**, which is quicker mid-write but gives you no control over the slug.
- **A handful of posts:** go to **Posts** > **All Posts**, hover a row and click **Quick Edit**, then tick the category.
- **Many posts at once:** on the same screen, tick the posts, choose **Edit** in the **Bulk actions** list, click **Apply**, then tick the category. Note that bulk edit only *adds* categories, it never removes the ones already set.
## Make it the default category
If most new posts belong in your new category, set it as the fallback so you stop seeing **Uncategorized**. Go to **Settings** > **Writing** and choose it under **Default Post Category**. WordPress will not let you delete whichever category is currently the default, which is why **Uncategorized** normally has to be renamed or replaced rather than removed.
## Troubleshooting
**Symptom: the Categories menu item is missing.** Your user role is below Editor, or a plugin has hidden the menu. Sign in with an Administrator account and check **Users** > **All Users** for the role assigned to you.
**Symptom: "A term with the name provided already exists with this parent."** A category (or a tag, since both share the same underlying storage) already uses that name at that level. Give it a different name, or pick a different parent.
**Symptom: the saved slug is not the one you typed.** Something else on the site already claims it, so WordPress added a suffix. Choose a more specific slug and save again.
**Symptom: the category archive page returns a 404.** Either the category has no published posts yet, or the permalink rules need rebuilding. Open **Settings** > **Permalinks** and click **Save Changes** without altering anything, which flushes and rewrites the rules.
**Symptom: the new category does not show in the site menu.** WordPress menus are built manually. Add it under **Appearance** > **Menus** (or in the site editor if your theme is block-based); it will not appear on its own.
## Related reading
- [How to Manage WordPress Categories the Right Way](/wordpress/how-to-manage-wordpress-categories-the-right-way/)
- [How to Delete Categories in WordPress](/wordpress/how-to-delete-categories-in-wordpress/)
- [How to Delete an Uncategorized Category in WordPress](/wordpress/how-to-rename-the-default-uncategorized-category-in-wordpress/)
## Need a hand?
If your dashboard does not look as described above, or a category archive is still not behaving after a permalink flush, open a support ticket from your Noiz client area and the team will take a look at the site.
# How to Add a New WordPress Admin User via phpMyAdmin
Source: https://docs.noiz.ie/wordpress/how-to-add-a-new-wordpress-admin-user-via-phpmyadmin/
If you are locked out of your WordPress dashboard and cannot use the normal password-reset email, you can create a brand-new administrator account directly in the database using **phpMyAdmin**. This is the standard lockout-recovery method: it works even when you have lost the only admin login, when the reset email never arrives, or when a plugin or theme has broken the login form. Once the new admin exists, you sign in with it and repair the site from the dashboard as normal.
This guide is written for any WordPress site hosted with Noiz. You reach phpMyAdmin from your hosting control panel (Plesk on the South African platform, DirectAdmin on the Irish platform), or from the database manager in whatever panel your plan provides.
**Last reviewed:** 27 July 2026, against WordPress **6.8**. This guide is written for Noiz hosting and is kept current against WordPress and phpMyAdmin. It complements, and does not replace, the official WordPress documentation linked below.
**Does the MD5 trick still work on current WordPress?** Yes. WordPress 6.8 changed the default password-hashing algorithm to bcrypt, but for backward compatibility WordPress still accepts a plain `MD5` hash on login and silently upgrades it to the modern hash the first time the new user signs in successfully. That is why the phpMyAdmin method below continues to work on the latest releases.
### Official Documentation Reference
- [WordPress: Resetting Your Password](https://wordpress.org/documentation/article/reset-your-password/) (see the phpMyAdmin section)
- [WordPress: Database Description](https://wordpress.org/documentation/article/database-description/) (the `wp_users` and `wp_usermeta` tables)
- [phpMyAdmin documentation](https://docs.phpmyadmin.net/)
## Prerequisites
- Access to **phpMyAdmin** for the site's database, through your Noiz hosting control panel.
- The **database name** and the **table prefix** used by the WordPress install. Both are set in the site's `wp-config.php` file (look for `DB_NAME` and `$table_prefix`). The default prefix is `wp_`, but many installs use a custom prefix such as `wpxy_` for security.
**Important:** throughout this guide the examples use the default `wp_` prefix. If your install uses a different prefix, substitute it everywhere, including inside the `meta_key` values in the later steps. Using the literal text `wp_` when your real prefix is different is the single most common reason this procedure fails.
## Add the User to the wp\_users Table
1. Open **phpMyAdmin**.
2. Select your database from the left-hand list (for example **wp\_example**, the primary database for the WordPress installation).
3. Select the **wp\_users** table. If you have a custom database prefix, this will be **yourprefix\_users**.
4. Click the **Insert** tab at the top of the phpMyAdmin menu.
5. Fill in the new user data: You can leave the remaining fields (`user_url`, `user_activation_key`) blank.
- **ID**: enter any ID number that is not already used in the table, and note it down because you need it in the later steps. If you prefer, leave this field blank so MySQL auto-assigns the next value, then check the inserted row to see which ID it received.
- **user\_login**: the username this admin will log in with.
- **user\_pass**: the raw password the user will log in with. **Critical:** set the **Function** dropdown to the left of this field to **MD5**. If you skip this, phpMyAdmin stores your plain text instead of a hash and the password will never be accepted.
- **user\_nicename**: the author slug (for example `your-name`).
- **user\_email**: the email address for this user.
- **user\_registered**: set a valid date and time in the format `2026-07-22 09:00:00`. Leaving this at the zero default can trip a strict MySQL mode and cause the insert to fail, so it is worth filling in.
- **user\_status**: set this to `0`.
- **display\_name**: the name shown publicly (for example `Your Name`).
6. Click the **Go** button at the bottom of the page to insert the row.
7. If phpMyAdmin shows a query confirmation page, click **Go** again. You should see a green success banner. A red error at the bottom means the user was not inserted; read the message (usually a duplicate ID or a missing required field) and correct it.
### Add the wp\_capabilities Row in wp\_usermeta
This row is what actually gives the new account the administrator role. Without it, the login works but WordPress reports that you do not have permission to do anything.
1. From the left-hand table list, click **wp\_usermeta**.
2. Click the **Insert** tab at the top of the phpMyAdmin menu.
3. Fill in the following fields (leave **umeta\_id** blank so it auto-assigns):
- **user\_id**: use the same **ID** you set in step 5 above.
- **meta\_key**: `wp_capabilities`. If your prefix is custom, this must be `yourprefix_capabilities`, not the literal `wp_capabilities`.
- **meta\_value**: `a:1:{s:13:"administrator";b:1;}`
4. Click **Go** to insert the row, then **Go** again on any confirmation page. You should see a green success banner.
### Add the wp\_user\_level Row in wp\_usermeta
1. Still inside the **wp\_usermeta** table, click the **Insert** tab again.
2. Fill in the following fields:
- **user\_id**: use the same **ID** as before.
- **meta\_key**: `wp_user_level` (again, match your real prefix if it is not `wp_`).
- **meta\_value**: `10`
3. Click **Go** to insert the row, then **Go** again on any confirmation page. You should see a green success banner.
You should now be able to log in to your WordPress site at `/wp-login.php` with the new admin username and password.
## After You Regain Access
- Go to **Users** in the WordPress dashboard and open your new account, then set a fresh password from there. Doing this re-hashes the password with WordPress's modern algorithm and removes the temporary MD5 value.
- If this account was only ever an emergency route in, delete it (or demote it) once the original login is working again.
- Review why you were locked out in the first place: a broken plugin or theme, a corrupted `.htaccess`, or a compromised admin account are the usual causes.
## Troubleshooting
- **The password is rejected at login:** the **Function** dropdown was not set to **MD5** when you inserted the row, so plain text was stored. Edit the `wp_users` row, re-enter the password, and set the function to **MD5** before saving.
- **You can log in but see "You do not have sufficient permissions" or no admin menu:** the `meta_key` values used the literal `wp_` prefix instead of your real table prefix, or the `wp_capabilities` row is missing. Confirm your prefix in `wp-config.php` and check both `wp_usermeta` rows.
- **Red error when inserting into wp\_users:** most often a duplicate **ID** (the primary key already exists) or an empty required field such as `user_registered`. Read the error text and adjust the offending field.
- **The wp\_capabilities value looks wrong after saving:** the serialized string is length-sensitive. It must be exactly `a:1:{s:13:"administrator";b:1;}`, including the `13`, which is the character count of the word `administrator`.
If you are still stuck, contact the Noiz support team and Noiz can do this for you. Please note that if you are not on a managed WordPress plan, this recovery work may be billable.
# How to Bulk Delete Posts in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-bulk-delete-posts-in-wordpress/
Deleting posts one at a time is fine for a handful. When you are clearing out a demo site, stripping an imported blog back to its useful articles, or wiping hundreds of spam or scraped posts left behind by a compromised plugin, you need the bulk route. This guide shows you how to move many WordPress posts to the Trash at once, how to permanently remove them afterwards, and the two traps that catch most people: the "select all" checkbox that quietly only selects the current page, and the fact that deleting a post does not delete the images that were attached to it.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Posts Screen](https://wordpress.org/documentation/article/posts-screen/) for the full reference on the post list, its filters and its bulk actions.
- [Administration Screens](https://wordpress.org/documentation/article/administration-screens/) for how Screen Options and the list tables behave across the dashboard.
- [Editing wp-config.php](https://developer.wordpress.org/advanced-administration/wordpress/wp-config/) for the `EMPTY_TRASH_DAYS` constant that controls how long trashed posts are kept.
- [WordPress Backups](https://wordpress.org/documentation/article/wordpress-backups/) if you want the background on why a snapshot before a mass deletion is not optional.
## Prerequisites
- Access to the WordPress dashboard as an **Administrator** or **Editor**. Authors can only bulk delete their own posts, and Contributors cannot delete published posts at all. If you cannot get in, see [How to login to WordPress (Admin Dashboard)](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A current backup of the site database. Bulk deletion is fast, silent and irreversible once the Trash is emptied.
- A clear idea of which posts are going. Deleting only one post? Use [How to Remove a Post in WordPress](/wordpress/how-to-delete-a-post-in-wordpress/) instead.
## Take a Backup First
There is no undo for an emptied Trash. WordPress does not ask you to confirm a bulk action either: the moment you click **Apply**, every selected post moves, no dialogue, no second chance. Take a full backup of the site files and database before you start.
Noiz hosting accounts include scheduled backups, and you can trigger an on demand snapshot from your hosting control panel before a big clear out. Doing that takes a minute and turns an irreversible mistake into a restore.
## Move Posts to the Trash in Bulk
Deleting a post in WordPress is a two stage process. The first stage moves posts to the Trash, where they are hidden from the site but still recoverable. The second stage empties the Trash and removes them from the database for good. This section covers stage one.
1. Log in to the WordPress dashboard at `https://yourdomain.com/wp-admin/`, replacing `yourdomain.com` with your own domain.
2. In the left hand menu, go to **Posts** and click **All Posts**.

3. Tick the checkbox in the header row of the table, immediately to the left of the **Title** column. That selects every post currently shown on the page. To select only some posts, leave that one alone and tick the individual checkboxes instead.

4. Open the **Bulk actions** dropdown above the list, choose **Move to Trash**, and click **Apply**.

WordPress reloads the list and shows a notice along the lines of "24 posts moved to the Trash", with an **Undo** link next to it. That Undo link only survives until you navigate away or reload, so if you have just made a mistake, click it now rather than reading on.
The **Bulk actions** dropdown and the **Apply** button appear twice, once above the list and once below it. They do the same thing. If your list is long, the pair at the bottom saves a scroll.
### The Select All Trap
This is the single most common surprise. The header checkbox selects everything *on the current page*, not everything in your blog. WordPress shows 20 posts per page by default, so on a site with 800 posts you have selected 20 and left 780 behind, and the confirmation message reading "20 posts moved to the Trash" is easy to skim past.
To handle a larger batch in one pass:
1. Click **Screen Options** at the top right of the Posts screen.
2. Set **Number of items per page** to a higher figure, then click **Apply**.
3. Tick the header checkbox again. It now covers everything on the enlarged page.
Do not simply type a huge number here. Every post on the page is rendered by PHP and then processed in a single request when you apply the bulk action, so an extreme value can exhaust the PHP memory limit or run past the maximum execution time and hand you a blank page or a 500 error part way through the deletion. Around 100 to 200 items per page is a sensible working figure on standard hosting. Repeat the pass a few times rather than trying to clear thousands in one request.
### Delete Only a Subset of Posts
Trashing everything is rarely what you actually want. Narrow the list first, then select all, and the header checkbox becomes precise instead of dangerous. The controls sit directly above the post list:
- **Status links** along the top (**All**, **Published**, **Drafts**, **Pending**, **Trash**) filter by post state. Clearing out abandoned drafts without touching anything live starts here.
- **All dates** filters to a single month. Useful when a plugin or an import injected posts on a known date.
- **All Categories** filters to one category. Pair this with [How to Manage WordPress Categories the Right Way](/wordpress/how-to-manage-wordpress-categories-the-right-way/) if the categories themselves need tidying afterwards.
- The **Search posts** box matches on title and content, which is the fastest way to isolate injected spam that shares a recurring phrase or link.
- Clicking the **Author** name in a row filters to that author, which is how you clear out everything a departed contributor or a rogue account published.
Apply a filter, confirm the count shown next to the status links looks right, then select all and apply **Move to Trash**. The filter stays applied when the page reloads, so you can work through page after page of the same filtered set.
## Permanently Delete the Posts
Posts in the Trash are still rows in your database. They no longer appear on the site, but they still count towards database size, and they are still recoverable, which may or may not be what you want.
1. On the **Posts** screen, click the **Trash** link in the row of status links at the top. It only appears when there is something in the Trash.
2. Click **Empty Trash** to permanently remove everything listed, or tick individual posts and choose **Delete permanently** from the **Bulk actions** dropdown to remove only those.
To recover something instead, hover over the post and click **Restore**. A restored post returns as a draft, not as a published post, so check its status and republish it if it was live.
Left alone, WordPress empties the Trash automatically after 30 days. That interval is set by the `EMPTY_TRASH_DAYS` constant in `wp-config.php`. Raising it gives you a longer safety net; setting it to `0` disables the Trash entirely, which means every delete becomes immediate and permanent. Setting it to `0` is a bad idea on any site with more than one editor.
## What Bulk Deleting Does Not Remove
This is where a "clean" site turns out not to be clean at all.
- **Images and other media stay behind.** WordPress treats attachments as their own post type, so deleting a post leaves every image, PDF and video it used sitting in the Media Library and on disk, still consuming your hosting quota. Clearing those out is a separate job: see [How to Clean Up Your WordPress Media Library](/wordpress/how-to-clean-up-your-wordpress-media-library/).
- **Old URLs start returning 404.** Anything indexed by a search engine or linked from elsewhere now leads nowhere. If the deleted posts had traffic or inbound links, set up 301 redirects to the closest surviving page rather than leaving a field of dead ends.
- **Categories and tags survive as empty terms.** They will show a post count of zero and can still appear in menus, widgets and archive pages. Delete the ones you no longer need.
- **Comments follow the post.** Comments attached to a trashed post go to the Trash with it and are permanently removed with it. There is no way to keep them.
- **The database does not shrink on its own.** Deleted rows leave gaps in the tables. A large clear out is a good moment to run an optimise pass on the database from your hosting control panel or phpMyAdmin.
- **Revisions go too.** Every stored revision of a deleted post is removed with it, which is usually the point, but worth knowing if you were relying on revision history.
## Clearing Out Hundreds or Thousands of Posts
The bulk action runs as a single PHP request. Every selected post has to be updated, its comments moved, its terms recounted and its caches cleared before the page can respond, so the work grows with the size of the selection rather than staying flat. Push it too far and PHP hits its time or memory limit mid job, leaving some posts trashed and some not, and returning a white screen or a 500 error with no useful message.
The reliable approach is boring and works every time:
- Set **Screen Options** to 100 or 200 items per page rather than the maximum.
- Run the bulk action, wait for the confirmation notice, then repeat.
- Emptying the Trash is the same kind of operation, so empty it in batches too instead of clearing 5,000 posts in one click.
- If a batch times out, reload the Posts screen before trying again and check what actually went through. Do not assume the whole batch failed.
If you are dealing with tens of thousands of posts, that is a database level job rather than a dashboard one, and running it as SQL against the correct tables and their relationship tables is safer than hammering the admin screen. Open a ticket and the Noiz team will handle it.
## Troubleshooting
**Symptom**: only 20 posts were deleted when you meant to delete all of them. The header checkbox selects the current page only. Raise **Number of items per page** in **Screen Options**, or repeat the bulk action page by page.
**Symptom**: **Move to Trash** is missing from the **Bulk actions** dropdown. Your account does not have the capability to delete those posts. Authors can only delete their own, and Contributors cannot delete published posts. Sign in as an Administrator or ask one to run it.
**Symptom**: nothing happens when you click **Apply**. Either no posts are selected, or **Bulk actions** is still on its default entry rather than **Move to Trash**. Both are easy to miss because WordPress reloads the page either way without an error.
**Symptom**: a blank page, a 500 error or a gateway timeout part way through a large deletion. The request exceeded the PHP execution time or memory limit. Reduce the batch size and try again. If it keeps happening on modest batches, a plugin is doing extra work on every post deletion, so deactivate plugins one at a time to find it.
**Symptom**: the **Trash** link is not shown at all. Either the Trash is empty, or `EMPTY_TRASH_DAYS` has been set to `0` in `wp-config.php`, which disables the Trash and makes every deletion immediate.
**Symptom**: posts reappear after you delete them. Something is recreating them. The usual culprits are an active import or feed importer plugin, a syncing service, or malicious code left behind after a compromise. Deleting the posts again will not fix it. Find and stop the source first.
**Symptom**: the site is slow or unreachable straight after a mass deletion. Term counts, sitemaps and caches are all being rebuilt. Give it a few minutes, then clear any page cache and regenerate the sitemap from your SEO plugin.
## Getting Help
If a bulk deletion has gone wrong, stop and do not run anything else. Open a ticket in the Noiz client area with the site domain, roughly how many posts were involved and the exact error text if there was one. On managed plans the Noiz team can restore from backup, run large deletions directly against the database where the dashboard cannot cope, and check whether posts that keep reappearing are the symptom of something worse than an untidy blog.
# How to Bulk Find and Replace Content in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-bulk-find-and-replace-content-in-wordpress/
This guide shows you how to find a piece of text, a link, or an image on your WordPress site and replace it everywhere at once, instead of opening and editing every post by hand. It is the tool you reach for after a rebrand (an old business name becomes a new one), after moving to a new domain, after switching your site from `http` to `https`, when a phone number or address that appears on dozens of pages changes, or when a single image used across the site needs swapping. The task goes by several names, including "search and replace", "find and replace", and "bulk replace"; they all mean the same thing. Because WordPress stores some of its settings in a special packed format called serialised data, a careless replacement can quietly corrupt a site, so this guide covers both the safe methods and the one trap you must avoid, and it shows you how to protect alt text and search rankings when you replace images.
**Last reviewed:** 27 July 2026, against WordPress **7.0.1** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [wp search-replace (WP-CLI command reference)](https://developer.wordpress.org/cli/commands/search-replace/): the official reference for the built-in command, including every flag used in this guide and its handling of serialised data.
- [wp-cli/search-replace-command (source and readme)](https://github.com/wp-cli/search-replace-command/): technical detail on how the command decodes serialised PHP and JSON, replaces the value, and re-encodes it with correct lengths.
- [Migrating WordPress (Advanced Administration)](https://developer.wordpress.org/advanced-administration/upgrade/migrating/): the official guidance on changing a site's URL and moving a site, including its warning about serialised data during a blanket search and replace.
- [Alt Text, alternative text for images (Accessibility Handbook)](https://make.wordpress.org/accessibility/handbook/content/alternative-text-for-images/): what alt text is for and how to write it, which matters when you replace images site-wide.
- [Search and replace plugins (WordPress.org plugin directory)](https://wordpress.org/plugins/search/search+replace/): the neutral directory listing where you can compare reputable, serialisation-aware plugins.
## Prerequisites
- Administrator access to your site. If you are not sure how to sign in, see [how to log in to the WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A fresh, tested backup taken immediately before any bulk change. This is not optional: a site-wide replace touches many rows at once, and a good backup is the difference between a five-minute fix and a rebuild.
- For the command-line method, SSH access to your hosting account with WP-CLI available. If your site is on a Noiz managed plan and you do not have shell access, the Noiz support team can run the command for you.
- The exact value you want to find, and exactly what to replace it with, written down. Precision matters: `http://yourdomain.com` and `https://yourdomain.com` are different strings.
## Understand the Serialised Data Trap Before You Start
WordPress keeps your posts and pages as readable text, which is easy to change. But a large amount of configuration is stored differently. Widget contents, theme options, plugin settings, page-builder layouts, menu items, and many custom fields are saved as **serialised data** in tables such as `wp_options` and `wp_postmeta`. Serialised data is a compact text format that records the exact length of every string it contains.
Here is why that matters. The address `http://oldsite.com` is stored inside serialised data as `s:18:"http://oldsite.com";`, where `s:18` declares "an 18-character string follows". If a blunt database replacement swaps that address for `https://newsite.com`, which is a different length, but leaves the `s:18` marker untouched, PHP later tries to read 18 characters, reads the wrong number, and the entire setting becomes unreadable. The damage is usually invisible at first. It only surfaces later, when a widget, a theme option, or a page-builder layout suddenly fails to load.
The lesson is simple: **never run a raw SQL `REPLACE()` query** (for example directly in phpMyAdmin) against columns that might hold serialised data. The safe tools in this guide do something a raw query cannot: they deserialise the data, make the replacement, then re-serialise it with the length markers corrected. That single difference is what keeps your site intact.
## Choose the Right Method
Pick the lightest method that fits the size of the job:
- **A few posts:** edit them directly in the block editor. This is built into WordPress and needs no plugin.
- **Site-wide, no command line:** use a reputable, serialisation-aware find-and-replace plugin.
- **Site-wide, with SSH:** use WP-CLI's built-in `wp search-replace` command. It is the safest and most capable option.
- **Raw SQL:** avoid it, except for a single column you are certain holds no serialised data, and only if you fully understand what that column contains.
## Method 1: Edit Directly in the Block Editor (Built In)
WordPress has no native, site-wide find-and-replace feature, but for a small, exact set of pages you do not need one. Open each post in the block editor, use your browser's own **Find** (press `Ctrl` and `F`, or `Cmd` and `F` on a Mac) to jump to the text, and edit the block by hand. This keeps you in full control and touches nothing else. It stops being practical beyond a handful of pages, at which point move to Method 2 or Method 3.
## Method 2: Use a Find-and-Replace Plugin (No SSH Needed)
When you need a site-wide change but do not have or want command-line access, a find-and-replace plugin is the practical route. Several exist in the WordPress plugin directory; the important thing is to choose one that clearly states it is **serialisation-aware** (it handles serialised data safely) and that offers a dry run or preview. Noiz does not endorse a particular plugin, so compare a few reputable options and read recent reviews before installing.
The general flow is the same whichever you choose:
1. Take a fresh backup first.
2. Install and activate the plugin.
3. Enter the exact text or URL to **find**, and exactly what to **replace** it with.
4. Select which database tables to include. Prefer the specific tables you actually need over an "all tables" option; a narrower scope is safer and faster.
5. Leave the `guid` column out of the replacement. The `guid` is a permanent identifier used by feed readers, not a link to update, and changing it causes problems (see the URL section below).
6. Run a **dry run** or preview first, and read the number of matches it reports. If the count is wildly higher or lower than you expected, stop and refine your search string before running for real.
7. Run the replacement, then review the site.
If the plugin exists only to perform this one job, deactivate and remove it afterwards to keep the site lean.
## Method 3: Use WP-CLI search-replace (Built Into WP-CLI)
The most reliable method of all is `wp search-replace`, a command built into WP-CLI. It understands serialised data natively, walks every table for you, and can preview its work before making any change. It needs SSH access to your hosting account. On a Noiz managed plan, if you do not have shell access, ask the Noiz support team to run the command.
Always preview with a dry run first:
```
wp search-replace 'old-text' 'new-text' --dry-run --report-changed-only
```
This walks the tables, decodes any serialised values, and reports exactly what it would change, without writing a single row. When the report looks right, run it for real and protect the `guid` column:
```
wp search-replace 'old-text' 'new-text' --skip-columns=guid
```
The flags you are most likely to use, in plain terms:
- `--dry-run`: preview only. Runs the whole operation and reports, but saves nothing.
- `--skip-columns=guid`: never rewrite the `guid` column. Use this on almost every real run.
- `--report-changed-only`: show only the fields that actually change, which makes the report far easier to read.
- `--precise`: force WordPress to use PHP rather than a raw database query for the replacement. It is slower but the most thorough for complex serialised data.
- `--recurse-objects`: also replace values inside serialised PHP objects. This is on by default; you would only pass `--no-recurse-objects` to turn it off.
- `--all-tables-with-prefix` or `--all-tables`: widen the search beyond the tables WordPress registers itself. Use these only when you know a custom or plugin table holds the value you are changing.
- `--regex`: match using a regular expression for advanced patterns. It is considerably slower, so reach for it only when a plain string will not do.
- `--export=changes.sql`: write the transformed data to an SQL file instead of touching the live database, so you can inspect it or apply it elsewhere.
As a belt-and-braces step, take a database snapshot you can restore instantly before the real run:
```
wp db export backup-before-replace.sql
```
## Replace URLs Across the Whole Site (Domain Change or HTTP to HTTPS)
Changing a URL everywhere is the most common bulk replace, and also the one most exposed to the serialised data trap, because themes, widgets, and page builders love to store full, absolute URLs. Handle it with care:
- Match the **full** URL, including the protocol. For an SSL switch, replace `http://yourdomain.com` with `https://yourdomain.com`. For a domain move, replace the old domain with the new one. (`yourdomain.com` is an example; use your real domain.)
- Use a serialisation-aware method (Method 2 or Method 3). Never do a URL change with a raw SQL replace.
- Always skip the `guid` column with `--skip-columns=guid`. The `guid` uniquely and permanently identifies each post to feed readers. If you rewrite it, subscribers can suddenly see every old post as brand new.
- Watch for variants. A URL can appear with and without `www`, as `http` or `https`, and with or without a trailing slash. Replace the most specific form, and repeat the run for each variant that genuinely exists on your site.
A typical WP-CLI run for an SSL switch looks like this:
```
wp search-replace 'http://yourdomain.com' 'https://yourdomain.com' --skip-columns=guid --dry-run
```
Remove `--dry-run` to apply it once the report looks correct. Note that the site's own **WordPress Address** and **Site Address** are set separately under **Settings** > **General**; a full domain move updates those two fields as well as the content.
## Replace Images Site-Wide Without Losing Alt Text or SEO
There are two very different jobs here, and confusing them is exactly where accessibility and search rankings get damaged. Decide which one you actually want before you touch anything.
### Option A: Swap the File, Keep the Same Address
If you want the same slot to show a new picture everywhere it appears, replace the underlying media **file** so that its URL, its media title, and its alt text all stay identical. Media-replace plugins are built for this, and some let you keep the original file name. Because nothing in your content markup changes, every link, every alt attribute, and your existing search rankings are preserved untouched. This is the SEO-safe choice. Afterwards, clear your caches and CDN, and if the new file has different dimensions, regenerate the thumbnails so the resized copies match.
### Option B: Point Content at a Different Image URL
If you instead find-and-replace one image URL with a different one across your posts, only the image source (the `src`) changes. Alt text is stored separately and is not carried along by the swap. The attachment's alt text lives in a field called `_wp_attachment_image_alt`, and a copy of it is written into each post's markup at the moment the image is first inserted. So a URL swap leaves the old alt attribute sitting in your content. That is fine if the new image means the same thing as the old one, but if the subject has changed, the description no longer matches the picture, which harms both accessibility and SEO. In that case you must update the alt text too.
Two gotchas catch people out:
- **Editing alt text in the Media Library does not reach back into old posts.** Those posts keep the copy of the alt text that was made when the image was inserted. Updating the Media Library only affects future insertions.
- **A careless replace on raw `` markup can strip the alt attribute entirely.** Target the image URL itself, not the surrounding tag, so you never accidentally delete the alt text.
Whichever option you use, run a dry run first and then spot-check a few real pages before you consider the job done.
## After Replacing: Verify and Clear Caches
- **Purge every cache.** Clear the object cache, the page cache, and any CDN. Old text or images very often persist only because a cache is still serving them.
- **Regenerate thumbnails** if you replaced image files whose dimensions changed, so the resized copies are rebuilt.
- **Re-save your permalinks** after a URL change: go to **Settings** > **Permalinks** and click **Save Changes** to refresh the rewrite rules.
- **Spot-check the serialised areas.** Look at the homepage, a couple of inner pages, a page built with your page builder, your widgets, and your menus. Those are the places most likely to reveal a problem, because they are where serialised data lives.
- **Search the live front end** for any leftover instances of the old value to confirm the change was complete.
## Troubleshooting
- **The report says zero replacements.** Your search string does not match exactly. Check the protocol (`http` versus `https`), `www` versus non-`www`, a trailing slash, or HTML-encoded characters. Copy the exact string from the source rather than typing it.
- **The site shows errors or a blank page after a raw SQL replace.** This is almost certainly serialised data corruption. Restore your backup, then redo the change with a serialisation-aware method (Method 2 or Method 3).
- **Some instances changed but others did not.** The untouched ones are usually inside serialised settings that a non-aware tool skipped, or they are being served from a cache. Re-run with a serialisation-aware method and then clear all caches.
- **Feed subscribers suddenly see every old post as new.** The `guid` column was changed. Restore the `guid` values from your backup, and never include `guid` in a replace again.
- **Images still show the old picture.** It is cached. Purge the page cache and CDN, then hard-refresh your browser.
- **Alt text is missing or wrong after an image swap.** Re-enter the alt text in the affected posts, and set it in the Media Library for future insertions. Remember that old posts keep the alt text embedded at insert time.
- **Far too many things changed.** Your match was too broad. Scope the search to the full, specific string (include the protocol and the domain), and run a dry run again before applying.
If you would rather not run a site-wide change yourself, the Noiz support team can take a verified backup and carry out a safe, serialisation-aware search and replace for you. Open a support ticket with the exact text or URLs to change, note whether it involves your domain or your images, and a technician will make the change and confirm the result.
# How to Change Your WordPress Database Password
Source: https://docs.noiz.ie/wordpress/how-to-change-your-wordpress-database-password/
This guide shows you how to change the password on the database that your WordPress site uses, safely, on your Noiz hosting. There is a catch that trips up almost everyone who tries it: the database password lives in two places that must always agree, and if you change one without the other your site stops loading and shows the message **"Error establishing a database connection."** This article explains where those two places are, walks you through changing the password in your hosting panel (or in phpMyAdmin), shows you how to update WordPress to match, and helps you recover if the site does go dark. It is written for Noiz clients who run their own WordPress site, using generic example names such as `yourdomain.com` that you replace with your own.
Two things are worth saying up front, because they save a lot of confusion. First, the database password is *not* the password you type to log in to WordPress; those are completely separate, and changing one never touches the other. If you are actually trying to regain access to `wp-admin`, you want a different guide, linked below. Second, the official documentation tells you what each database setting is, and the database software documents the command that changes a user password, but neither spells out the one thing that matters most here: that the two must be changed together, in quick succession, or the site breaks. That gap is exactly what this guide fills.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress and database documentation linked below.
### Official Documentation Reference
- [Editing wp-config.php (Advanced Administration Handbook)](https://developer.wordpress.org/advanced-administration/wordpress/wp-config/): the full reference for the configuration file that holds your database credentials, including the database constants and every optional setting around them.
- [Common WordPress errors (Advanced Administration Handbook)](https://developer.wordpress.org/advanced-administration/wordpress/common-errors/): the official write-up of "Error establishing a database connection", which is the exact symptom of a password mismatch.
- [How to install WordPress (Advanced Administration Handbook)](https://developer.wordpress.org/advanced-administration/before-install/howto-install/): describes the database name, user, password, and host that WordPress needs, and the possible values `DB_HOST` can take.
- [ALTER USER (MySQL 8.4 Reference Manual)](https://dev.mysql.com/doc/refman/8.4/en/alter-user.html): the canonical syntax for changing a database user's password from SQL, which is the command behind the phpMyAdmin route and applies equally to MariaDB.
## Prerequisites
- Access to your Noiz hosting control panel. Noiz runs **Plesk** on the South African platform (neo.noiz.co.za), **DirectAdmin** on the Ireland platform, and **ISPConfig**. The panel is where you change the database user's password and where you reach phpMyAdmin.
- A way to edit `wp-config.php`: either an SFTP client with your SFTP credentials, or the File Manager built into your panel.
- A copy of `wp-config.php` saved to your own computer first, so you can put the original back instantly if anything goes wrong.
- A quiet moment. There is a short window during this change when your site cannot reach its database, so pick a low-traffic time and set aside a few uninterrupted minutes.
- If you are on a **managed Noiz plan**, you can skip the hands-on steps entirely and ask the Noiz support team to change the database password and update WordPress to match for you.
## Two Passwords, One Match: What You Are Actually Changing
WordPress keeps all of its content, settings, and users in a database, and it connects to that database as a specific **database user** with a password. That single password exists in two separate places, and the whole of this task is about keeping them identical:
- **On the database server.** The user account (for example `youracct_wpuser`) has a password recorded against it inside MySQL or MariaDB. This is the real password, the one the database checks.
- **Inside WordPress.** Your site stores the same password in plain text in a file called `wp-config.php`, on the line `define( 'DB_PASSWORD', '...' );`. Every time a page loads, WordPress reads this value and offers it to the database to prove it is allowed to connect.
When both hold the same string, WordPress connects and your site works. The moment they differ, the database rejects the connection and WordPress cannot load a single page. That is why you can never change just one of them: changing the password on the database server without updating `wp-config.php` (or the reverse) is precisely what produces **"Error establishing a database connection"**. The fix is not to change the password twice or reinstall anything; it is simply to make the two agree again.
## This Is Not Your WordPress Login Password
It is easy to conflate the two passwords a WordPress site has, so it is worth being precise. The **database password** is what this guide changes: an infrastructure credential that only your server and `wp-config.php` ever see, and that no visitor or editor ever types. The **WordPress login password** is what you and your users type on the `wp-login.php` screen to reach the dashboard; it is stored, hashed, inside the database rather than in a file.
They are fully independent. Changing the database password does not log anyone out of WordPress and does not alter any user's login. Changing a WordPress login password does not touch the database credential and will not fix or cause a connection error. If your real goal is to get back into the admin area, changing the database password will not help you, and you should instead follow [how to reset a WordPress admin password via phpMyAdmin](/wordpress/how-to-reset-a-wordpress-admin-password-via-phpmyadmin/). Come back here only when it is genuinely the database connection credential you need to rotate.
## Why You Might Change the Database Password
There are a handful of legitimate reasons to rotate this credential, and knowing which one applies to you sets the urgency:
- **After a security incident.** If your site has been compromised, or you suspect the database credentials have leaked, changing this password is a core part of locking the attacker out, alongside the wider steps in the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/).
- **When someone with access leaves.** If a developer or agency who once held your database credentials no longer works with you, rotating the password ensures the old copy they hold stops working.
- **It was weak or shared.** A password that was set to something guessable during a rushed install, or that has been emailed around, is worth replacing with a strong, unique one.
- **Routine hygiene.** Some people rotate infrastructure credentials on a schedule as good practice. It is not required, but there is nothing wrong with it if done carefully.
Whichever applies, the mechanics below are identical. Choose a strong replacement, ideally a long random string from a password manager, and read the note on special characters in Step 3 before you generate it.
## Before You Start: The One Rule That Prevents a Broken Site
Everything that goes wrong with this task comes from doing the two halves too far apart, so plan them as a single, quick operation:
- **Have `wp-config.php` open and ready to edit before you change anything.** The goal is to change the database password and update the file within seconds of each other, not to change the password and then wander off to find your SFTP client.
- **Accept that there is a brief window.** On a normal single-password setup there is no way to avoid a short moment where the site cannot connect, because for that instant the two copies disagree. Doing the steps back to back keeps that window down to seconds. A truly seamless rotation would need the database's dual-password feature, which shared hosting panels do not expose, so the practical answer is to pick a quiet time rather than to chase zero downtime.
- **Keep a backup of `wp-config.php`.** If you mistype the new password in the file, restoring your saved copy and re-doing the edit is faster than guessing.
- **If the panel offers to generate the password, capture it immediately.** Some panels show a generated password only once. Copy it the instant it appears, because you will need to paste that exact string into `wp-config.php` in Step 3.
## Step 1: Find Your Current Database Details
Open `wp-config.php` from your site's root folder (the same folder that contains `wp-admin` and `wp-content`) and look near the top for the four database lines:
```
define( 'DB_NAME', 'youracct_wpsite' );
define( 'DB_USER', 'youracct_wpuser' );
define( 'DB_PASSWORD', 'the-current-password' );
define( 'DB_HOST', 'localhost' );
```
Note down the **database name** and, especially, the **database user**: that user is the account whose password you are about to change, and you need to change the password on the right one. On Noiz shared hosting the user name usually carries your account prefix, for example `youracct_wpuser` rather than plain `wpuser`, so copy the full name exactly as the file shows it. The `DB_HOST` value, almost always `localhost`, tells you the host part of the account, which matters for the SQL route in Step 2. Leave the file open; you will edit the `DB_PASSWORD` line in Step 3.
## Step 2: Change the Password on the Database User
This is the first of the two halves. The reliable place to do it on Noiz shared hosting is your hosting panel, because the panel changes the password on the database user directly and with the right privileges. phpMyAdmin can do it too, but on shared platforms your phpMyAdmin login often lacks the permission to alter a user's password, so try the panel first.
### In your hosting panel (recommended)
- **Plesk** (South African platform, neo.noiz.co.za): open **Databases**, find the database and expand its **User Management**, then select the database user. Use **Change Password** (or the password field on the user), enter your new password, and save.
- **DirectAdmin** (Ireland platform): open **MySQL Management**, select the database, then the database user, and use the option to **modify** or set a new password for that user. Enter it and save.
- **ISPConfig**: database users are managed separately from databases, so go to **Sites**, open **Database Users**, and click the user your site uses. Type the new password into the **Database password** field (or use the **Generate Password** link), confirm it in **Repeat Password**, and save the record.
Whichever panel you use, if there is a strength meter, aim for a long, strong password. As soon as you save, the database will only accept the new password, so your site is now effectively offline until you complete Step 3. Move straight on.
### The phpMyAdmin or SQL alternative
If you prefer to work in phpMyAdmin, open it from your panel. Where your login has the privilege, the **User accounts** tab lists the database users; find the row for your user at its host, choose **Edit privileges**, and use the **Change password** section to set the new value. The equivalent single command, which you can run on the **SQL** tab, is:
```
ALTER USER 'youracct_wpuser'@'localhost' IDENTIFIED BY 'your-new-strong-password';
```
Two details decide whether this works. The **host part** (`'localhost'` above) must match how the user was actually created; if the account exists as `youracct_wpuser@localhost` and you target a different host, you change the wrong account, or none at all. Match it to your `DB_HOST` from Step 1. Second, on shared hosting your phpMyAdmin login frequently does not have the rights to alter another user, so this command may return an access-denied error, in which case the panel route above is the answer. The same `ALTER USER` statement works on both MySQL and MariaDB, so it does not matter which your site runs on.
## Step 3: Update DB\_PASSWORD in wp-config.php to Match
This is the second half, and it must follow immediately. In the `wp-config.php` you left open, change only the password on the `DB_PASSWORD` line to the exact string you just set on the database user:
```
define( 'DB_PASSWORD', 'your-new-strong-password' );
```
Leave `DB_NAME`, `DB_USER`, and `DB_HOST` untouched; only the password changed. Keep the single quotes around the value, and paste the new password exactly, with no stray spaces before or after it inside the quotes. Save the file, and if you edited a local copy over SFTP, upload it back to the server so the live file is the one you changed. The instant WordPress reads a `DB_PASSWORD` that matches the database again, the site comes back.
**A gotcha worth knowing before you pick the password.** The value sits inside single quotes in a PHP file, so a password that itself contains a single quote (`'`) or a backslash (`\`) will break the file unless you escape those characters, and an unescaped one typically produces a blank white page or a syntax error rather than a clean message. The simplest way to avoid the whole problem is to choose a strong password made of letters, digits, and safe symbols that excludes the single quote and the backslash. Length and randomness give you the security; those two particular characters buy you nothing but trouble here.
## Step 4: Verify the Site and Your Login
Do not assume it worked; confirm it. Visit `https://yourdomain.com` in a fresh browser tab (or a private window, to sidestep any cached copy) and check that the site loads normally rather than showing the connection error. If it loads, the two passwords match and the change is complete.
Then confirm the human side is unaffected: go to `https://yourdomain.com/wp-admin` and log in as usual. Your WordPress username and login password are unchanged by this task, so you should get straight in exactly as before; the general guide to [logging in to the WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) covers this if anything looks off. A site that loads on the front end and lets you log in to the back end is your proof that the rotation is done and nothing else was disturbed.
## Troubleshooting
- **Symptom**: **"Error establishing a database connection"** after the change. The two passwords do not match. Re-open `wp-config.php` and compare the `DB_PASSWORD` value character for character against what you set on the database user. The usual culprits are a mistyped or partly-pasted password, an accidental space inside the quotes, or an edited local file that was never uploaded back to the server. Correct the file to match and the site returns.
- **Symptom**: the site is still down and you cannot tell which copy is wrong. Set the password on the database user again in your panel to a fresh known value, then paste that same value into `DB_PASSWORD` and save. Re-setting both ends to one string you are sure of removes the guesswork.
- **Symptom**: a blank white page or a PHP syntax error instead of the connection message. This points at the file itself, not the credential, and most often means the password contains a single quote or backslash that is breaking the PHP, or a quote around the value was deleted. Restore your backup of `wp-config.php` and redo the edit with a password that avoids those characters.
- **Symptom**: you changed the password but the wrong site, or another site, broke. More than one site or user can share a database user. Confirm from each site's `DB_USER` which sites rely on the user you changed, and update every one of their `wp-config.php` files to the new password.
- **Symptom**: phpMyAdmin refuses to change the password, or you cannot see a **User accounts** tab. On shared hosting your database login usually lacks that privilege by design. Use your hosting panel to change the password instead, or ask Noiz support.
- **Symptom**: the connection error briefly appeared and then cleared on its own after you finished. That is normal and expected: it was the short window between the two halves. As long as the site is stable now, no action is needed.
## When to Ask Noiz Support
Changing a database password is quick once you understand it, but it is unforgiving of a half-finished edit, and the whole reason you are doing it, often a security scare, is a poor time to be wrestling with a downed site. If you are on a **managed Noiz plan**, the simplest path is to open a ticket and ask the Noiz support team to rotate the database password and update `wp-config.php` to match; support can do both ends in one motion and confirm the site is back before closing the ticket. If you are self-managing and the site will not come back after your change, contact the Noiz support team with your domain, which platform your account is on, and the exact error you see (a screenshot is ideal), and a technician can compare the two passwords, correct the mismatch, and rule out any deeper cause such as a database user that has lost its privileges.
# How to Change Your WordPress Display Name and Nickname
Source: https://docs.noiz.ie/wordpress/how-to-change-your-wordpress-display-name-and-nickname/
Your WordPress **display name** is the name the public sees. It appears as the author byline on posts, next to your comments, in author archive pages and in the greeting on the admin bar. By default WordPress sets it to your login username, which means a fresh install quietly publishes your username on every post you write. This guide shows you how to change it on a WordPress site hosted with Noiz, and explains the one step that trips most people up: you cannot type a display name directly, you have to set a **Nickname** first.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress: Users Profile Screen](https://wordpress.org/documentation/article/users-your-profile-screen/)
- [WordPress: Users Screen (editing other accounts)](https://wordpress.org/documentation/article/users-screen/)
- [WordPress: Roles and Capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
- [WordPress Developer Reference: wp\_update\_user()](https://developer.wordpress.org/reference/functions/wp_update_user/)
## Prerequisites
- A WordPress site on your Noiz hosting account.
- Login details for the WordPress dashboard at `yourdomain.com/wp-admin` (replace `yourdomain.com` with your own domain).
- Any role can change its own display name. To change someone else's, you need the **Administrator** role.
## Why a Display Name That Differs From Your Username Is Worth Setting
Signing in to WordPress needs two things: a username and a password. If the display name still matches the login username, every published post hands out half of that pair to anyone who reads the site, and automated login attempts are the single most common form of unwanted traffic a WordPress site receives.
Setting a distinct display name removes the most obvious source of that leak. It is not a security control on its own, and it does not replace a strong password or two-factor authentication, but it costs nothing and it stops the username being published in the byline of every article. It also lets you publish under a proper name such as "Jane Smith" rather than `jsmith82`, which simply reads better.
## Step 1: Log In to the WordPress Dashboard
Go to `yourdomain.com/wp-admin` and sign in.
## Step 2: Open Your Profile
In the left-hand Dashboard menu, go to **Users** and click **Profile**.

If you are an administrator changing a different account, go to **Users** and then **All Users** instead, and click **Edit** under the account you want. The fields from this point on are identical.
## Step 3: Set a Nickname
Scroll down to the **Name** section and find **Nickname**. Enter the name you want to publish under.

This step is not optional and it is the part people skip. The **Display name publicly as** control in the next step is a drop-down, not a text box, and it can only offer values that already exist on your profile: your username, your first name, your last name, the two combined in either order, and your nickname. If you want a display name that is none of those, the nickname field is where you create it.
Nickname is a required field, so it can never be left empty. On a new account it is pre-filled with the username, which is exactly what you are here to change.
## Step 4: Choose It Under "Display name publicly as"
Open the **Display name publicly as** drop-down and select your new nickname.

If the new nickname is not listed in the drop-down, save the page first with **Update Profile**, then reload the profile screen. The new value will be there.
## Step 5: Save
Scroll to the bottom of the page and click **Update Profile**. WordPress confirms with a "Profile updated" notice at the top of the screen.
Open your site in a new browser tab and check a post byline to confirm the change is live.
## What Changing the Display Name Does Not Do
This is the part the official documentation leaves implicit, and it matters if your reason for changing the name was privacy rather than presentation.
- **It does not change your login username.** WordPress deliberately makes `user_login` read-only, and there is no supported way to edit it from the dashboard. If you genuinely need a different username, create a new account with the Administrator role, log in as that account, then delete the old one and choose **Attribute all content to** the new user when WordPress prompts. Your posts move across intact.
- **It does not change your author archive URL.** Author pages sit at `yourdomain.com/author/{slug}/`, and that slug is a separate field derived from the original username. Changing the display name leaves it untouched, so the old username can still be read from the URL. Changing the slug requires either a plugin built for it or a direct database edit.
- **It does not rename you on existing comments.** WordPress stores the author name on each comment record at the moment the comment is posted, so comments you left before the change keep showing the old name. Post bylines, by contrast, are rendered from your live profile and update immediately.
- **It does not change your email address or your avatar.** Avatars are keyed off the email address on your profile, not the display name.
## Troubleshooting
**Symptom**: The new nickname does not appear in the **Display name publicly as** drop-down. The drop-down is built when the page loads. Click **Update Profile** to save the nickname, reload the profile screen, and the option will be available.
**Symptom**: You saved the profile but the site still shows the old name. This is almost always caching. Clear your WordPress caching plugin, clear any CDN cache in front of the site, then reload the page with a hard refresh. Check the page in a private browsing window to rule out your own browser cache.
**Symptom**: The byline still shows the username even though the profile is correct. Some themes and page builders print the username or the account's first name rather than the display name. Test with one of the default WordPress themes active to confirm, then raise it with the theme author.
**Symptom**: There is no **Profile** entry in the **Users** menu, or the whole Users menu is missing. Your role does not have the capability, or a membership or security plugin is hiding the menu. Ask an administrator on the site to make the change for you.
**Symptom**: You cannot reach `/wp-admin` at all. That is a login or site availability problem rather than a profile one. Confirm the site loads on the front end first, then reset your WordPress password using the **Lost your password?** link on the login screen.
## Need a hand?
If you are on a managed Noiz plan and would rather have the change made for you, or you need help tightening up WordPress logins more broadly, contact the Noiz support team through the client area and the team will assist.
# How to Change a WordPress Account Password
Source: https://docs.noiz.ie/wordpress/how-to-change-a-wordpress-account-password/
If you can still log in to your WordPress site, the quickest and safest way to change your password is from the dashboard itself. You do not need a reset email, database access or your hosting control panel. This guide shows you how to change your own password, how an administrator changes someone else's, and what WordPress does behind the scenes once the new password is saved.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Documentation: Users > Your Profile screen](https://wordpress.org/documentation/article/users-your-profile-screen/)
- [WordPress Documentation: Users screen](https://wordpress.org/documentation/article/users-screen/)
- [WordPress Documentation: Resetting your password](https://wordpress.org/documentation/article/reset-your-password/)
## Prerequisites
- You can still sign in to the WordPress dashboard. See [How to Log In to the WordPress Dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) and [How to Find Your WordPress Login URL](/wordpress/how-to-find-your-wordpress-login-url/).
- A password manager or another safe place to store the new password before you save it.
- To change *another* user's password, an account with the **Administrator** role.
If you cannot log in at all, this is not the article you need. Use [How to Reset a WordPress Admin Password via phpMyAdmin](/wordpress/how-to-reset-a-wordpress-admin-password-via-phpmyadmin/) instead.
## Change Your Own WordPress Password
**1.** Log in to the WordPress dashboard.
**2.** In the left-hand menu, go to **Users** and click **Profile**.

If your account is not an administrator, WordPress hides the **Users** menu and shows a single **Profile** item in the sidebar instead. Click that. Either route opens the same screen, and you can always reach it directly at `https://yourdomain.com/wp-admin/profile.php` (replace `yourdomain.com` with your own domain).
**3.** Scroll down to the **Account Management** section and click **Set New Password**.

WordPress generates a strong random password and displays it in the box, along with a strength meter. You can type over it with a password of your own, but if the meter reads **Weak** or **Very weak** WordPress will make you tick **Confirm use of weak password** before it lets you save. Do not do that on a live site. A generated password stored in a password manager is the better answer, because you never have to type it.
**4.** Copy the password to a safe place, then scroll to the bottom and click **Update Profile**.
Two things about this step catch people out. The password is only shown in plain text on this screen, so copy it *before* you save. And nothing at all changes until you click **Update Profile**. Closing the tab at this point leaves the old password in force.
## Change Another User's Password as an Administrator
Administrators can reset any account on the site without knowing the current password:
1. Go to **Users** > **All Users**.
2. Hover over the account you want and click **Edit**.
3. Scroll to **Account Management** and click **Set New Password**.
4. Copy the generated password, then click **Update User**.
WordPress emails the account holder to say their password was changed, but it does not email them the new password. Send it to the user over a channel that is not the site itself, and ask them to change it again once they are in. Better still, use **Send Reset Link** in the same section where it is available, so the user sets a password you never see.
## What Happens After the Password Changes
- **Other sessions are signed out.** Any other browser, phone or device signed in to that account is logged out. You stay signed in on the browser you used to make the change. If you only want to clear other devices without changing the password, use **Log Out Everywhere Else** in the **Sessions** row of the same profile screen.
- **A notification email goes out.** WordPress sends a "password changed" notice to the account's email address, and to the site administrator's address. If that email never arrives, the site's outbound mail is not working, which is worth fixing before you rely on password reset links.
- **Application passwords survive.** Application passwords, used by mobile apps and API integrations, are separate credentials and are not revoked when you change your login password. If you are changing the password because the account may have been compromised, go to **Application Passwords** on the same profile screen and revoke everything you do not recognise.
- **Saved logins go stale.** Browser-stored passwords, backup plugins and staging copies that use the same credentials will keep offering the old password. Update them so failed logins do not trigger your security plugin's lockout rules.
## Troubleshooting
**Symptom**: The **Set New Password** button does nothing. This is almost always a JavaScript error from a plugin or theme conflict. Open your browser console, or temporarily switch to a default theme with plugins disabled, and try again.
**Symptom**: You save the profile and the password is unchanged. Check for a warning at the top of the screen. WordPress refuses the save if the two password fields do not match, and it will not accept a weak password unless the confirmation box is ticked.
**Symptom**: You are logged out immediately after saving. Some security plugins force a fresh login after any credential change. Sign back in with the new password. If the new password is rejected, the save did not complete, so use the database reset route linked above.
**Symptom**: The new password is rejected at the login screen even though it saved. Check that a security plugin has not locked your IP address after earlier failed attempts, and confirm you are logging in to the right site if you run a staging copy on the same domain.
**Symptom**: You cannot reach the profile screen because two-factor authentication is failing. See [How to Set Up Two-Factor Authentication (2FA) in WordPress with All-In-One Security (AIOS)](/wordpress/how-to-set-up-two-factor-authentication-2fa-in-wordpress-with-all-in-one-securit/) for recovery options.
## Good Practice
Change the password from the dashboard whenever you suspect it has been shared, reused elsewhere, or typed on a machine you do not control. Give every person who works on the site their own account rather than sharing one login, so a password change never locks out three other people at once. For a wider hardening pass, work through the [WordPress Security Checklist](/wordpress/wordpress-security-checklist/).
If you are locked out of your WordPress site entirely, or you think an account has been compromised, open a ticket from your Noiz client area. Noiz support can help you regain access and review the site for anything left behind.
# How to Clean Up Your WordPress Media Library
Source: https://docs.noiz.ie/wordpress/how-to-clean-up-your-wordpress-media-library/
This guide shows you how to clean up a WordPress media library that has quietly grown out of control: removing images you no longer use, cutting the pile of resized copies WordPress and your theme generate for every upload, and in doing so reclaiming disk space and making your backups smaller and quicker. The media library is the collection of everything you have uploaded, and behind the scenes each of those uploads is stored not as one file but as several. Over a few years, that folder often becomes the single largest thing on your hosting account, which is why a tidy-up pays off in real, measurable ways. This article is written for Noiz clients who run their own WordPress site. It names categories of tool, and mentions specific plugins only as examples of a category, never as recommendations, because the right approach depends on how your site was built.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Media Library screen (WordPress Documentation)](https://wordpress.org/documentation/article/media-library-screen/): the full reference for the grid and list views, the media filters, and bulk deletion.
- [Settings Media screen (WordPress Documentation)](https://wordpress.org/documentation/article/settings-media-screen/): every option under **Settings > Media**, including the image size fields and the year and month upload folders.
- [big\_image\_size\_threshold (WordPress Developer Reference)](https://developer.wordpress.org/reference/hooks/big_image_size_threshold/): the filter behind the 2560 pixel "big image" scaling and the `-scaled` files it produces.
- [wp media regenerate (WP-CLI Command Reference)](https://developer.wordpress.org/cli/commands/media/regenerate/): the command that rebuilds and cleans up thumbnails after you change your image sizes.
- [Media plugins (WordPress Plugin Directory)](https://wordpress.org/plugins/tags/media/): the directory's media tag, where you can compare cleanup and optimisation plugins by last-updated date, compatibility, and active installs.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an **Administrator**. Viewing, filtering, and deleting media, and changing image sizes, all need administrator rights.
- **A recent, restorable backup taken immediately before you start.** Deleting media is permanent, and the tools in this guide act in bulk, so a backup is not optional here. It is the one thing that lets you undo a mistake.
- Optional, for the measuring and command-line parts: access to your files over SFTP or your hosting panel's File Manager, and SSH access if you want to use WP-CLI. Managed-plan clients can ask the Noiz support team to run these steps instead.
## Why Your Media Library Grows Faster Than You Think
Before deleting anything, it helps to understand where the bulk actually comes from, because the answer surprises most people and it changes how you clean up. When you upload a single image, WordPress does not store one file. It stores the original and then generates a set of smaller, resized copies so it can serve an appropriately sized image in different places without shrinking your huge original every time.
On a standard WordPress 7.0.2 install, uploading one large photo typically produces the original plus copies at the built-in sizes: a cropped **thumbnail** (150 by 150 pixels), a **medium** size (up to 300 pixels), a hidden **medium\_large** size (768 pixels wide), and a **large** size (up to 1024 pixels). If the original is big enough, WordPress adds two more, at 1536 and 2048 pixels on the long edge, for high-resolution screens. That is already six or seven files from one upload.
Then two more multipliers stack on top:
- **Your theme and plugins register their own extra sizes.** A theme might add a "hero" size, a "blog card" size, and a "gallery thumbnail" size; a slider or portfolio plugin adds a few more. Every one of these is generated for every image you upload, whether or not that image is ever shown at that size. It is entirely normal for a single upload to become ten to fifteen files on disk on a feature-rich site.
- **The original is kept even when it is never served.** Since WordPress 5.3, any image whose longest side is over 2560 pixels is automatically scaled down to a 2560 pixel `-scaled` copy, and that scaled copy is what your pages use. The full-resolution original, straight off a modern phone or camera and often several megabytes, stays on the server forever even though visitors never load it. Multiply that by every photo you have ever uploaded and you have found where a lot of the space went.
This is the real story behind a bloated media library, and it means there are two separate jobs to do. One is removing images you genuinely no longer use, files and all. The other, which people usually forget, is trimming the number of resized copies made per image, so that every future upload, and optionally every past one, stops carrying sizes nothing on your site displays.
## Measure First, So You Know What You Are Fixing
It is worth taking a reading before and after, both to prove the cleanup was worth it and to decide how hard to work at it. The folder to look at is `wp-content/uploads`, which holds every media file and all those generated sizes. On almost every WordPress site it is the single largest folder, and this matters beyond raw disk usage: every file in it is copied into every backup you take, so a bloated uploads folder makes each backup larger and slower to create and to restore. Trimming it is one of the most effective ways to keep both your hosting storage and your backups lean.
To see its size on Noiz hosting, open your hosting panel's File Manager, browse to your site's `wp-content` folder, and check the reported size of the `uploads` folder, or connect over SFTP and look at the same folder in your client. If you have SSH access, the quickest reading is:
```
du -sh wp-content/uploads
```
Note the figure. Comparing it against the total size of your hosting account tells you at a glance whether media is your storage problem, or whether the space is going somewhere else such as a database, a cache, or old backups stored inside the site.
## Step 1: Audit What You Actually Have
Start inside WordPress, at **Media > Library**. Switch to the list view using the icon at the top left, since it shows more detail per item than the grid. The single most useful control here is the media type dropdown, which includes an **Unattached** option. Selecting it filters the library down to items that are not recorded as belonging to any post or page.

### Understand the "Unattached" Trap Before You Trust It
It is tempting to treat everything in the Unattached list as safe to delete. Resist that, because "unattached" and "unused" are not the same thing, and confusing them is the classic way people delete images that are still live on their site. WordPress marks an image as attached only to the one post or page it was first uploaded to. That leaves a great many genuinely used images looking unattached, including:
- Your site logo, favicon, and any images set in the theme customiser or theme options.
- Images placed through a page builder or block patterns, which frequently do not create the attachment link.
- An image reused on a second page after being uploaded to a first, or inserted from the library rather than uploaded fresh.
- Header and background images, and images used in widgets or menus.
So the Unattached filter is a useful shortlist of *candidates*, not a delete list. Treat it as "images to investigate", and confirm each one is truly unused before removing it. The same caution applies twice over to the automated scanners covered next.
## Step 2: Remove Unused Images Safely
There are two honest ways to do this: by hand, which is safe but slow, and with a scanning plugin, which is fast but needs care. Which you choose depends on how many images you have and how your site was built.
### By Hand, for Small Libraries and Obvious Culprits
For a modest library, or to clear out clearly redundant items such as an old logo, duplicate uploads, or leftovers from a redesign, deleting by hand is the safest route because you look at each image before it goes. In the media library, use **Bulk Select**, tick the items you have confirmed are unused, and choose **Delete Permanently**. The important thing to know, and the reason this is clean rather than messy, is that deleting an attachment this way removes the original file and every generated size along with it. You do not need to hunt down the thumbnail copies yourself; WordPress tracks them and removes the whole set.
A useful habit before deleting anything you are unsure about: click the image, use **Copy URL to clipboard** from its details, and paste that URL into your browser to open the file directly. Then search your own site for where it might appear. If nothing genuinely references it, it is a safe removal.
### With a Scanning Plugin, for Large Libraries
When you have thousands of images, checking each by hand is impractical, and a media cleanup plugin becomes worthwhile. Tools in this category (Media Cleaner is one well-known example, offered here only to illustrate the type) scan your posts, pages, and often your theme and settings to build a list of media that appears to be referenced nowhere, so you can review and delete it in bulk. Used carefully, they reclaim a lot of space quickly. Used carelessly, they are the fastest way to break a site, so a few rules matter:
- **Take a fresh backup immediately before running one**, separate from your routine backups. This is the single most important precaution in the whole guide.
- **Understand what the scanner cannot see.** No scanner reliably detects images referenced inside page-builder data, custom fields, serialised theme options, sliders, galleries, or hard-coded into CSS or template files. Anything it cannot parse, it may wrongly flag as unused. On a site heavy with a visual builder, this false-positive risk is real.
- **Use the safety net.** The better tools move "unused" files to a trash or quarantine area first rather than deleting outright, and let you empty it later once you have confirmed nothing broke. Always prefer that mode, keep the quarantine for a week or two, and browse your site thoroughly before emptying it.
- **Work in batches and check as you go**, rather than deleting everything the scanner offers in one click.
## Step 3: Trim the Surplus Thumbnail Sizes
Removing unused images tackles half the problem. The other half is the number of resized copies made for the images you keep. If your theme registers sizes you never display, every upload is quietly wasting space, and this compounds over time.
### Set Sensible Built-in Sizes
Under **Settings > Media** you control the three core sizes: **Thumbnail** (with an option to crop to exact dimensions), **Medium**, and **Large**. If your theme never uses one of these, setting its width and height to `0` stops WordPress generating it for future uploads. Do not do this blindly, though: many themes and galleries rely on the thumbnail and medium sizes, so change one, upload a test image, and check your site still looks right before committing.

### Find and Retire Sizes You Never Use
The hidden extra sizes are usually the ones added by your theme and plugins, and they are not shown on the Settings screen. To see the complete list of sizes actually registered on your site, the clearest tool is WP-CLI over SSH:
```
wp media image-size
```
This prints every registered size with its dimensions and crop setting, revealing exactly what is being generated per upload. Sizes left behind by a theme or plugin you have since removed are prime candidates to retire. You can deregister an unwanted size with a small snippet in a child theme or a site-specific plugin, for example:
```
add_action( 'init', function () {
remove_image_size( 'unwanted-size-name' );
} );
```
Replace `unwanted-size-name` with the size's registered name from the list above. If you are not comfortable editing code, a managed-plan client can ask the Noiz support team to do this, or a reputable media plugin can toggle sizes on and off through a settings screen instead.
**The gotcha that catches everyone here:** changing or removing a registered size only affects images uploaded *from that point on*. It does nothing to the thousands of copies already sitting in your uploads folder. Those old files stay exactly where they are until you take the next step.
## Step 4: Regenerate Thumbnails After Changing Sizes
Whenever you add, resize, or remove an image size, or switch to a theme with a different set of sizes, your existing images are left with the old copies: some now missing, some now surplus. Regenerating rebuilds each image's set of copies to match your current sizes, and this is also the step that finally deletes the old, no-longer-registered copies you retired in Step 3, reclaiming their space.
### The Command-Line Way (Fastest and Cleanest)
If you have SSH access, WP-CLI is by far the most reliable tool, because it processes every image in one pass and, by default, deletes the outdated copies as it goes. From your site's root folder:
```
wp media regenerate --yes
```
Two options are worth knowing. If you only want to create copies that are missing, without touching or rebuilding existing ones, add `--only-missing`, which is much faster on a large library. If old copies are linked from elsewhere and you would rather keep them, `--skip-delete` preserves them instead of removing them. To rebuild a single size across all images, use `--image_size`, for example `--image_size=large`. On a big library this is a heavy job, so it is best run when the site is quiet.
### The Plugin Way (No Command Line Needed)
If you do not have SSH access, a "regenerate thumbnails" plugin does the same job from inside the dashboard, working through your library in the background and rebuilding each image's sizes. It is slower than WP-CLI and heavier on the server while it runs, so start it when traffic is low. As with everything in this guide, take a backup first, and once regeneration is complete you can safely deactivate and remove the plugin. Managed-plan clients can simply ask the Noiz support team to run the regeneration for them.
## Step 5: Stop the Bloat From Coming Back
A one-off clean-up is worth much more if you also change the habits that caused it. A few settled practices keep the library lean for good:
- **Resize and compress before you upload.** A web page almost never needs an 8-megapixel, six-megabyte original. Exporting images at a sensible width and reasonable compression before uploading is the single biggest saving you can make, and it also removes those giant retained originals from the equation.
- **Keep only the sizes you actually use.** Having done the audit in Step 3, revisit it whenever you change theme, since a new theme brings a new set of registered sizes.
- **Consider modern image formats.** WordPress can work with WebP (supported since version 5.8) and AVIF (since 6.5), both of which produce markedly smaller files than JPEG or PNG at the same visual quality. Serving these, whether by uploading them directly or using an optimisation plugin that converts on the fly, shrinks both your storage and your page weight.
- **Mind the retained originals.** Remember that any upload over 2560 pixels keeps its full-size original on disk. Downsizing before upload sidesteps this entirely.
- **Delete media when you delete content.** WordPress does not remove an image when you delete the post that used it, so clearing out old campaigns or products is a good moment to remove their images too.
## Doing This on Noiz Hosting
Everything above happens inside WordPress, but the file-level and database work sits on your hosting account, and Noiz gives you a few ways to reach it. Your files, including the whole `wp-content/uploads` tree, are reachable either over SFTP with a client of your choice or through the File Manager built into your hosting panel, which is where you can check folder sizes and, if you ever need to, remove files by hand. Your site's database, where the media library records which files and sizes exist, is managed through phpMyAdmin from the panel. Direct file or database edits are an advanced, easy-to-get-wrong route, so treat them as a last resort behind a backup, and prefer the in-WordPress tools in this guide for day-to-day cleanup.
Because a smaller uploads folder directly means smaller, faster backups and more headroom on your plan, this is exactly the kind of maintenance the Noiz support team is glad to help with. Managed-plan clients can hand the whole job over: measuring the folder, taking the safety backup, running the regeneration, and retiring unused sizes.
## Troubleshooting
- **Symptom**: after a cleanup, images have vanished from pages and you see broken-image placeholders. A scanner or a manual delete removed a file that was still in use, most likely one referenced through a page builder, theme option, or custom field that the scanner could not read. Restore the affected files from the backup you took beforehand, or from the plugin's trash or quarantine if it has one, then rebuild your delete list more conservatively.
- **Symptom**: you deleted a lot of images but the uploads folder is barely smaller. The images you removed were probably small, while the space is held by a smaller number of very large retained originals, or by the many extra sizes your theme registers. Re-measure with the folder-size check, then work through Steps 3 and 4 to trim sizes and regenerate, which is where the big saving usually is.
- **Symptom**: you changed the image sizes under **Settings > Media** but nothing on disk changed. That is expected. Size changes apply only to future uploads until you regenerate; run Step 4 to update and clean up your existing images.
- **Symptom**: regeneration stalls, times out, or the site slows to a crawl while it runs. Rebuilding thousands of images is demanding. Use the WP-CLI method if you can, since it is lighter than the browser-based plugins, run it during quiet hours, and if using a plugin let it finish one batch before starting the next.
- **Symptom**: the Unattached filter lists images you are certain are on the site. That is normal and is not a fault. Attachment status only records the one post an image was first uploaded to, so reused, builder-placed, and theme images all appear unattached. Confirm actual usage before deleting rather than trusting the label.
- **Symptom**: the media library shows an image but the file will not open at its URL, or vice versa. The database record and the file on disk have drifted apart, often after a partial migration or a manual file deletion. A media cleanup plugin can usually detect and reconcile these orphans in either direction; if it cannot, open a support ticket.
If your media library is large, tangled with a page builder, or you would simply rather not risk deleting the wrong thing, open a support ticket with the Noiz support team. Include your domain and roughly how much space the uploads folder is using, and a technician can take the safety backup, audit the library, trim the surplus sizes, and regenerate your thumbnails so you get the storage and backup savings without the risk.
# How to Create a Custom WordPress Design Without Coding
Source: https://docs.noiz.ie/wordpress/how-to-create-a-custom-wordpress-design-without-coding/
This guide shows you how to design and customise the look of your WordPress site without writing any code. It covers the three practical routes open to a non-developer: the Site Editor that is built into WordPress itself, block-enhancement plugins that extend that editor, and standalone drag-and-drop page and theme builders. You will learn what each route can and cannot do, which one suits which job, and the trade-offs that matter most on shared hosting. "No-code design", "visual editing", "drag-and-drop" and "full site editing" all describe the same broad idea. This article is for anyone running WordPress on a Noiz hosting account who wants a custom design without hiring a developer or touching PHP, HTML or CSS.
A key point up front: a promotional email or blog post will often tell you that you "just need to install a plugin" to design your site. That is one option, and sometimes a good one, but it is not the only one and frequently not the leanest. Modern WordPress can build a completely custom design out of the box, with no extra plugin at all. Understanding all three routes lets you pick deliberately rather than by advertising.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Documentation: Site Editor](https://wordpress.org/documentation/article/site-editor/), the built-in visual editor for the whole site, available with block themes.
- [WordPress Documentation: Block themes](https://wordpress.org/documentation/article/block-themes/), how block themes differ from classic themes and what they unlock.
- [WordPress Documentation: Styles overview](https://wordpress.org/documentation/article/styles-overview/), global colours, typography and style variations for the whole site.
- [WordPress Documentation: Block Patterns](https://wordpress.org/documentation/article/block-pattern/), prebuilt block layouts you can drop in and edit.
- [WordPress Pattern Directory](https://wordpress.org/patterns/), a free library of ready-made section and page designs.
## Prerequisites
- Access to your site's admin dashboard. If you are not sure how to get there, see [How to login to WordPress (Admin Dashboard)](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A recent full backup, or a staging copy of the site, before you make sweeping design changes. Design work is easy to undo when you have a safety net and painful to undo when you do not.
- A rough idea of whether your current theme is a **block theme** or a **classic theme**, which decides whether the built-in Site Editor is available to you. The first section below shows you how to check.
## Three Ways to Design Without Code
Before opening any editor, it helps to know the three routes and roughly where each one fits. They are not mutually exclusive, but mixing them carelessly causes most of the trouble people run into.
- **Route 1: The built-in Site Editor.** Requires only a modern block theme, no extra plugin. It edits every part of the site (header, footer, page layouts, colours, fonts) visually. It is the leanest option, ships with WordPress, and produces the cleanest, fastest output. It is the natural first choice in 2026.
- **Route 2: Block-enhancement plugins.** These add extra blocks and design controls on top of the native editor rather than replacing it. You still work in the standard WordPress editor, just with more building blocks available. They keep most of the performance benefit of native blocks while adding flexibility.
- **Route 3: Page and theme builder plugins.** These are standalone drag-and-drop design environments that largely take over from the native editor. They are the most beginner-friendly for freeform layouts and come with large libraries of ready-made templates, at the cost of extra weight and a degree of lock-in. This is the "just install a plugin" route.
None of these is named or endorsed here as "the best". The right choice depends on how much you need to customise, how much you care about page speed, and whether you are comfortable depending on a third-party plugin for your entire design. Popular products exist in each category; treat any specific name you see elsewhere as one example among many, not a recommendation.
## Route 1: The Built-In Site Editor
Since the arrival of block themes, WordPress can design an entire site visually with nothing added. This is the feature originally launched as "Full Site Editing", and it is now simply the Site Editor. It is genuinely code-free, it is free, and it is built to modern web standards, so it is the route to try first.
### Check whether you have a block theme
The Site Editor only appears when a **block theme** is active. The quickest way to tell which kind of theme you have is the **Appearance** menu in your dashboard:
- If you see **Appearance > Editor**, you have a block theme and the Site Editor is available.
- If you see **Appearance > Customize** (the older Customizer) and no **Editor** entry, you have a classic theme. Classic themes are built from PHP templates and do not work with the Site Editor.
If you are on a classic theme and want the built-in editor, you can switch to a block theme from **Appearance > Themes > Add New** and filter by **Block Themes**. WordPress ships with a capable default block theme, so you always have at least one available. Switching themes changes your design, so do it on a test copy first, not on a live site your visitors are using.

### Reskin the whole site fast with Styles
The single highest-impact, lowest-effort change is global **Styles**. Open **Appearance > Editor**, then choose **Styles**. Here you set the colour palette, typography and spacing for the entire site in one place, and every block that uses those defaults updates at once. This is how you make a stock theme look like your brand in minutes rather than editing page by page.
Most modern block themes also ship several **style variations**, which are complete pre-designed colour and font combinations for the same theme. Trying a different variation reskins the whole site with a single click, and you can then fine-tune from there. The **Style Book** view lets you preview how every block type looks under your current styles before you commit, which saves a lot of clicking around the front end to check your work.
### Edit the structural parts: templates and template parts
A custom design is more than colours. In the Site Editor you edit the structural pieces too. **Templates** define the layout for a whole class of pages, for example the blog home, a single post, search results or the 404 page. **Template parts** are the reusable global areas, most commonly the **Header** and **Footer**, that repeat across many pages. Edit a template part once and the change flows to every page that uses it.
Everything here is built from the same blocks you already use to write posts, so there is nothing new to learn beyond where things live. Be aware of one thing that surprises people: because header and footer template parts appear on nearly every page, an edit there is site-wide, not limited to the page you happen to be viewing. WordPress warns you when you save that a change affects multiple templates, so read that save dialogue rather than clicking through it.
### Start from prebuilt patterns instead of a blank canvas
You rarely need to build a section from scratch. **Patterns** are ready-made arrangements of blocks, for example a hero banner, a pricing row, a testimonial grid or a call-to-action, that you drop into a page and then edit in place. Your theme bundles its own patterns, and the free [WordPress Pattern Directory](https://wordpress.org/patterns/) offers a large community library you can copy straight into the editor. The current default theme alone includes well over seventy patterns.
Patterns come in two flavours worth understanding. An ordinary (unsynced) pattern is a starting point: you insert it and edit your copy freely, and it does not affect anything else. A **synced pattern** (formerly called a reusable block) keeps a single master copy, so editing it updates every place it appears. Use synced patterns for things that must stay identical everywhere, such as a promotional banner, and unsynced patterns for one-off layouts.
### Build and edit pages inside the editor
Individual pages are edited in the same visual editor, whether you open them from **Pages** in the dashboard or from within the Site Editor. You add blocks, drag them into position, drop in patterns and adjust each block's settings in the sidebar. The **List View** (the layered-lines icon) shows the page as a tidy outline of its blocks, which is the sane way to select and reorder things once a layout gets busy. The **Command Palette**, opened with `Ctrl+K` on Windows or `Cmd+K` on a Mac, jumps you to any page, template or action without hunting through menus.
When you are happy with a design built this way, you can even export the theme with your changes baked in from the editor's **Tools > Export** option, which produces a downloadable theme zip. That is useful for reusing a design across sites or handing it to a developer later.
## Routes 2 and 3: Drag-and-Drop Builder Plugins
If the native editor does not give you the freeform control you want, or you specifically want a huge library of pre-designed full-page templates, a builder plugin fills the gap. This is the route the marketing emails push, and for some projects it is the right call.
### What builders add
Builder plugins fall into two broad groups. **Block-enhancement plugins** stay inside the native editor and simply add more blocks and controls, so they keep most of the performance and compatibility benefits of Route 1. **Full page and theme builders** replace the editing experience with their own canvas, often with pixel-level positioning, animations, pop-ups, and hundreds of importable page and full-website templates. The latter are the most forgiving for a complete beginner who wants to drag elements anywhere and see instant results, and they are how you build a custom design when your theme's own options run out.
### Choosing one, neutrally
There is no single "best" builder, and Noiz does not endorse a particular one. Sensible things to weigh before committing your whole site to one:
- **Output weight.** Ask whether it produces clean, lean markup or piles on wrapper elements and scripts. This is the difference between a fast site and a slow one, covered below.
- **Active development and support.** Your design depends on this plugin indefinitely, so pick one that is actively maintained and widely used. Installing any third-party plugin also widens your site's attack surface, so keep it updated and remove builders you have stopped using. The [WordPress Security Checklist](/wordpress/wordpress-security-checklist/) covers vetting and maintaining plugins safely.
- **What you actually need.** If you only want to restyle an existing theme, a block-enhancement plugin or plain Route 1 is usually enough. Reach for a full builder when you genuinely need freeform layouts the native editor cannot produce.
- **Never run two full builders at once.** Two page builders competing to render the same content is a classic cause of broken layouts and slow pages. Choose one and stick with it.
### The lock-in gotcha nobody mentions in the advert
This is the most important thing to understand before you commit to a full page or theme builder, and it is exactly what the promotional emails leave out. Many builders wrap your content in their own special codes (shortcodes) or store it in their own format. While the builder is active everything looks fine. The moment you deactivate or switch away from it, pages built with it can collapse into a wall of unreadable shortcodes or blank sections, because WordPress no longer knows how to render that builder's format.
The practical consequences: budget to keep that plugin more or less permanently, prefer builders that output standard WordPress blocks or clean HTML where you can, and always test a builder on a staging copy before rolling it out across a live site. Route 1 does not have this problem, because its output is native WordPress blocks that keep working even if you change themes.
## Performance Considerations on Shared Hosting
Design choices are also performance choices, and on shared hosting that matters directly to your visitors and your search rankings. The consistent finding across independent testing in 2026 is that native blocks are the lightest, and heavy full page builders are the heaviest.
The reason is straightforward. A full page builder typically loads its own CSS and JavaScript on every page, whether or not a given page uses those features, and wraps your content in many extra layers of markup. That inflates page size, enlarges the page structure the browser must process, and adds scripts that can delay how quickly the page becomes usable. All three work against your Core Web Vitals, the loading and responsiveness scores that affect both user experience and SEO. Native blocks and lean block-enhancement plugins, by contrast, ship far less code and produce cleaner pages.
This does not mean "never use a builder". It means: if speed is a priority, prefer Route 1 or a lightweight block plugin, and if you do use a full builder, pair it with sensible hosting-side measures. On Noiz hosting that means keeping your site on a current, supported PHP version, enabling caching, and keeping images optimised, since a heavy builder amplifies the cost of large unoptimised images. If you are not sure which PHP version your account is on or how to enable caching, the Noiz support team can point you to the right control for your plan.
## A Safe Workflow, Whichever Route You Pick
Redesigning the visible parts of a live site carries real risk of a visitor seeing a half-finished or broken page. A little discipline avoids that:
1. **Back up first.** Take a full backup, or work on a staging copy, before any large design change. This is your undo button when an experiment goes wrong.
2. **Experiment off the live site.** Try new themes, style variations and especially new builder plugins on a test copy, not on the site your customers are using. Switching themes or activating a builder changes what visitors see immediately.
3. **Make changes in small, saveable steps.** The Site Editor tracks revisions for global styles, so you can step back if a change does not land the way you hoped.
4. **Check the result on a phone.** Most visitors arrive on mobile. Preview your design at a narrow width before you consider it finished.
## Troubleshooting
- **There is no "Editor" under Appearance**: your active theme is a classic theme, so the Site Editor is not available. Switch to a block theme (on a test copy first) to unlock it, or use a builder plugin instead.
- **A colour or font change did not take effect everywhere**: you most likely edited a single block rather than the global Styles. Set site-wide colours and fonts under **Appearance > Editor > Styles** so every block inherits them, rather than styling blocks one at a time.
- **Editing the header changed every page**: that is expected. The header and footer are template parts shared across the whole site, so a change there is site-wide by design. Read the save dialogue, which lists exactly what your save will affect.
- **My pages show weird codes in square brackets, or blank sections, after disabling a plugin**: those are leftover builder shortcodes. The page was built with a page builder that is now inactive. Reactivate that builder to restore the design, or rebuild the affected pages in the native editor if you intend to move away from the builder.
- **The site got noticeably slower after installing a design plugin**: heavy builders add CSS and JavaScript to every page. Confirm you are not running two builders at once, enable caching, keep images optimised, and consider whether a lighter block-based approach would meet the same design goal.
- **The layout looks broken only on mobile**: check the block or section's responsive settings, and preview at a narrow width in the editor. A design that works on a wide screen can overflow on a phone if spacing or column settings are fixed rather than flexible.
If you get stuck, or you would like a second opinion on which route suits your project and plan before you commit, open a support ticket with the Noiz support team. Explain what your site is for and whether page speed is a priority, and the team can point you toward the lightest approach that gets you the design you want.
# How to Deactivate and Delete a WordPress Plugin
Source: https://docs.noiz.ie/wordpress/how-to-deactivate-and-delete-a-wordpress-plugin/
Plugins you no longer use are not harmless. Every installed plugin is code sitting on your Noiz hosting account, and an inactive one still ships whatever vulnerabilities it contains, still needs updating, and still appears in security scans. Clearing out the ones you have stopped using is one of the quickest wins available on any WordPress site.
This guide shows you how to switch a plugin off, and how to remove it from the server entirely. Those are two different actions with two very different consequences, and the difference is the part of this job people get wrong. Deactivating is reversible in one click. Deleting can take your settings and your content with it.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Documentation: Manage Plugins](https://wordpress.org/documentation/article/manage-plugins/)
- [WordPress Documentation: Plugins screen](https://wordpress.org/documentation/article/plugins-screen/)
- [WordPress Developer Handbook: Uninstall methods (what a plugin is allowed to delete)](https://developer.wordpress.org/plugins/plugin-basics/uninstall-methods/)
- [WP-CLI: wp plugin commands](https://developer.wordpress.org/cli/commands/plugin/)
## Prerequisites
- A WordPress site on your Noiz hosting account.
- A dashboard login with the **Administrator** role. No other role can manage plugins, and on a multisite network only a Super Admin can delete plugin files.
- A recent backup, if the plugin you are about to delete holds anything you care about. Deleting is not undoable from inside WordPress.
## Deactivate and Delete Are Not the Same Thing
Read this before you click anything, because the two words sit next to each other in the interface and do very different jobs.
**Deactivating** tells WordPress to stop loading the plugin. Its code stops running, its features disappear from the site, its menu items vanish from the dashboard, and its shortcodes stop rendering. Nothing is removed. The plugin files stay in place on the server and everything the plugin stored in the database stays exactly as it was. Reactivate it later and you pick up where you left off, with every setting intact. This is the safe, reversible action, and it is what you want when you are testing whether a plugin is causing a problem.
**Deleting** removes the plugin's folder and files from the server. The plugin is gone, and getting it back means installing it again from scratch. Whether your settings and content survive that depends entirely on how the plugin was written, which is covered in detail further down. WordPress will not let you delete an active plugin, which is why you always deactivate first.
A useful way to hold the two apart: deactivating changes what your site does, deleting changes what is on your server.
## Step 1: Log In to the WordPress Dashboard
Go to `https://yourdomain.com/wp-admin` (replace `yourdomain.com` with your own domain) and sign in with an administrator account.
If you cannot remember the dashboard password, you do not necessarily need to reset it. The WordPress management tooling in your Noiz control panel lists each installed site and offers a one-click login that signs you straight in as an administrator.
## Step 2: Open the Installed Plugins Screen
In the left-hand dashboard menu, click **Plugins**, then **Installed Plugins**.

The table that opens lists everything installed on the site, active or not. Active plugins have a shaded row and a blue bar down the left edge. Inactive ones sit on a plain white background.
Above the table are filter links: **All**, **Active**, **Inactive**, and, when relevant, **Update Available**, **Recently Active** and **Drop-ins**. The **Inactive** filter is the one worth clicking first if you are doing a tidy-up, because it shows you exactly the dead weight you are carrying.
## Step 3: Deactivate the Plugin
Find the plugin in the list and click **Deactivate**, which sits directly beneath the plugin's name.

The screenshots here use **Hello Dolly**, the small sample plugin that has shipped with WordPress for years. If your install does not have it, the steps are identical for any other plugin in the list.
The page reloads, the row turns white, and the links underneath the name change to **Activate** and **Delete**. The plugin has stopped running. Nothing has been removed.
Load the front of your site and check it before going any further. If the plugin was doing something visible, this is the moment you find out what depended on it.
## Step 4: Delete the Plugin
Only once the plugin is deactivated does the **Delete** link appear. Click it.

A browser confirmation dialogue asks whether you are sure. Confirm with **OK**. WordPress deletes the plugin's folder from `wp-content/plugins/` and the row disappears from the table.
That is the end of it. There is no trash, no undo, and no restore button. If you delete a plugin by mistake, you reinstall it, and whether your old settings come back depends on the next section.
## What Deleting Actually Leaves Behind
This is the part the interface does not explain, and it is the reason to think before confirming.
WordPress deletes the plugin's **files**. What happens to the plugin's **data** is entirely up to the plugin author, because WordPress simply calls the plugin's uninstall routine, if it has one, and lets it do as it pleases. There are three broad outcomes.
- **The plugin cleans up after itself.** A well-written plugin includes an uninstall routine that removes its own options, its custom database tables and its scheduled tasks. Delete it and it is genuinely gone. Reinstall it later and you start from a blank slate, with every setting back at its default.
- **The plugin leaves everything behind.** Many plugins deliberately keep their data so that reinstalling restores your configuration instantly. Convenient if you are troubleshooting, less convenient if you are trying to slim down a bloated database. Rows sit in `wp_options` and custom tables stay in place indefinitely.
- **The plugin takes your content with it.** This is the one that hurts. If a plugin created custom post types, and you have been putting real content into them, that content lives in the database as posts belonging to a post type that no longer exists once the plugin is gone. Form entries, gallery items, portfolio pieces, event listings, testimonials, product data from an e-commerce extension: all of it can become inaccessible or, if the plugin's uninstall routine is thorough, be deleted outright.
Some plugins offer a setting along the lines of "remove all data on uninstall", usually buried in an advanced or tools tab, and it is off by default. If you actively want the database cleaned, switch that on before you delete. If you want the data kept, make sure it is off.
The safe habit is simple. Before deleting a plugin that has been holding anything real, take a backup, and if the plugin has an export function, use it. A form plugin's entries and an e-commerce plugin's orders are worth exporting to CSV even if you are confident the deletion is clean.
## Deactivating Several Plugins at Once
To act on more than one plugin, tick the checkbox at the left of each row, choose **Deactivate** from the **Bulk actions** drop-down above the table, and click **Apply**. The same menu offers **Delete**, which becomes available once the selected plugins are inactive.
Bulk deactivation is genuinely useful when you are chasing a fault. Switch every plugin off at once, confirm the problem disappears, then reactivate them one at a time, checking the site after each. The plugin that brings the fault back is the culprit. Ticking the checkbox in the table header selects everything on the page, so be deliberate about it.
Bulk delete is a different matter. There is one confirmation for the whole batch, so a mis-ticked checkbox removes a plugin you needed. Delete in small batches, or one at a time.
## When You Cannot Reach the Dashboard
Occasionally a plugin breaks the site badly enough that `/wp-admin` will not load either, which leaves you unable to deactivate the thing that is causing it. You can still switch it off from outside WordPress.
Open **File Manager** in your Noiz control panel, or connect over SFTP, and browse to your site's `wp-content/plugins/` directory. Rename the offending plugin's folder, for example from `plugin-name` to `plugin-name-off`. WordPress can no longer find the plugin, so it deactivates it automatically on the next page load and the dashboard comes back.
Renaming `plugins` itself to `plugins-off` deactivates every plugin at once, which is the faster route when you do not yet know which one is at fault. Create an empty `plugins` folder afterwards, then put the originals back one at a time.
Once you are back in the dashboard, the plugin shows as inactive and you can delete it properly from there. Renaming a folder is a deactivation, not an uninstall, so the plugin's database rows are all still present.
## Doing It From the Command Line
If your Noiz plan includes SSH access and WP-CLI is available, run these from the site's root directory:
```
wp plugin list
wp plugin deactivate plugin-name
wp plugin delete plugin-name
```
Replace `plugin-name` with the plugin's folder slug, which is the value in the `name` column of `wp plugin list`. To switch everything off in one go while troubleshooting:
```
wp plugin deactivate --all
```
WP-CLI runs the plugin's uninstall routine on delete exactly as the dashboard does, so the same warnings about data apply. This route is worth knowing when the dashboard is unreachable, or when you are applying the same clean-up across several sites.
## Gotchas Worth Knowing
- **Deactivating does not stop the update nagging.** An inactive plugin still reports available updates and still shows in the update counter. That is by design, and it is a reminder that the code is still on the server. If you are not going to use it, delete it.
- **Inactive plugins are still a security concern.** The code is not executed by WordPress, but the files are reachable on the server and a vulnerability in a poorly written plugin file can sometimes be triggered directly. Unused plugins should be deleted, not just switched off.
- **Shortcodes do not disappear gracefully.** If the plugin provided a shortcode you used inside posts or pages, deactivating it leaves the raw shortcode text, such as `[contact-form-7 id="42"]`, visible to visitors. Remove those shortcodes from your content as part of the job.
- **Themes can depend on plugins.** Some themes require a specific plugin for their page builder, their demo content or their slider. Deactivating it can strip layouts back to plain text. Check the front of the site immediately after deactivating, not the following week.
- **Some plugins refuse to deactivate cleanly.** A plugin that another plugin depends on may warn you or block the action. Deal with the dependent plugin first.
- **Must-use plugins have no links at all.** Anything in `wp-content/mu-plugins/` appears under a **Must-Use** filter with no Deactivate or Delete option. Those are removed by deleting the file over SFTP or in File Manager. Do not remove one you did not put there without checking what it does first.
- **Deleting does not clear your cache.** If a caching plugin or a CDN sits in front of the site, visitors can keep seeing output from a plugin you have already removed. Purge the cache afterwards and reload with a hard refresh.
- **Scheduled tasks can outlive the plugin.** A plugin that registered WP-Cron events without cleaning up leaves those events queued. They fail harmlessly, but they clutter the schedule.
- **On multisite, network-activated plugins behave differently.** They are managed from the Network Admin plugins screen, and an individual site administrator cannot deactivate or delete them.
- **Deleting a plugin does not delete its uploads.** Files a plugin placed in `wp-content/uploads/` stay where they are. That is usually what you want, but it does mean disk usage may not drop as much as you expected.
## Troubleshooting
**Symptom**: There is no **Delete** link under the plugin. The plugin is still active. Click **Deactivate** first, and the **Delete** link appears in its place.
**Symptom**: **Plugins** is missing from the dashboard menu entirely. Either your account is not an Administrator, or the site has `DISALLOW_FILE_MODS` set in `wp-config.php`, which hides plugin management from everyone. Check with the site owner before changing it.
**Symptom**: Deletion fails with a permissions or file-system error. WordPress could not remove the folder, usually because of incorrect file ownership. The guide on [resetting WordPress file and directory permissions](/wordpress/how-to-reset-wordpress-file-and-directory-permissions/) covers the fix, or contact Noiz support and the team will correct the ownership for you.
**Symptom**: The plugin's settings pages are still in the dashboard menu after deactivating. That is a cached admin menu or a stale browser cache. Reload with a hard refresh. If it persists, another plugin is registering that menu.
**Symptom**: The site broke the moment you deactivated. Reactivate the plugin to get the site back, then work out what depended on it before trying again. This is exactly why deactivation exists as a separate, reversible step.
**Symptom**: You deleted a plugin and now content is missing. It was a custom post type belonging to that plugin. The posts are usually still in the database but unreachable without the plugin. Reinstall the same plugin, check whether the content reappears, and export it before deleting again. If the plugin's uninstall routine removed it, restore from a backup.
**Symptom**: You reinstalled a plugin and all your old settings came straight back, which you did not want. The plugin left its options in the database on uninstall. Look for a "remove all data" or "reset" option in the plugin's own settings, use that, then delete it again.
**Symptom**: Deleting a plugin made no difference to the fault you were chasing. Then the plugin was not the cause. Deactivate the rest in bulk and reintroduce them one at a time.
## Related Guides
- [How to Install a WordPress Plugin](/wordpress/how-to-install-a-wordpress-plugin/)
- [How to Manually Install a WordPress Plugin](/wordpress/how-to-manually-install-a-wordpress-plugin-from-a-zip-file/)
- [How to Forcefully Update or Reinstall a WordPress Plugin](/wordpress/how-to-force-reinstall-or-update-a-wordpress-plugin-without-losing-data/)
- [When to Replace an Outdated or Abandoned WordPress Plugin](/wordpress/when-to-replace-an-outdated-or-abandoned-wordpress-plugin/)
- [WordPress Security Checklist](/wordpress/wordpress-security-checklist/)
- [How to Fix Common WordPress Errors](/wordpress/how-to-fix-common-wordpress-errors/)
## Need a hand?
Removing a plugin is a two-click job right up until it takes content with it. If you are on a managed Noiz plan and would like a backup taken before a risky deletion, an inherited site's plugin list audited and trimmed, or content recovered after a plugin was removed too enthusiastically, contact the Noiz support team through the client area with your domain name and the team will assist.
# How to Delete Categories in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-delete-categories-in-wordpress/
Categories pile up quickly. A theme demo installs a handful, a plugin adds its own, someone creates a duplicate with a typo in the name, and before long the sidebar lists a dozen topics that nobody uses. This guide shows you how to delete a category in WordPress, what happens to the posts filed under it, and the two things worth checking before you click **Delete**, because term deletion has no trash and cannot be undone.
The short version: deleting a category never deletes posts. WordPress moves them somewhere else. Knowing exactly where is the difference between a tidy site and half an hour of hunting for content that appears to have vanished.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Documentation: Posts Categories screen](https://wordpress.org/documentation/article/posts-categories-screen/)
- [WordPress Documentation: Categories](https://wordpress.org/documentation/article/categories/)
- [WordPress Documentation: Settings Writing screen (where the default post category is set)](https://wordpress.org/documentation/article/settings-writing-screen/)
- [WP-CLI: wp term delete](https://developer.wordpress.org/cli/commands/term/delete/)
## Prerequisites
- A WordPress site on your Noiz hosting account. If you are not sure how to reach the dashboard, see [How to Log In to the WordPress Dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A login with the **Administrator** or **Editor** role. Authors and Contributors can tick existing categories on their own posts but cannot delete any.
- A current backup if the site is live and the category holds a lot of posts. Category deletion itself is safe, but the reassignment it triggers touches every post in that category at once.
## What Deleting a Category Actually Does
This is the part most guides skip, and it is the only part that can surprise you.
- **Posts are never deleted.** WordPress removes the category from each post and leaves the post itself published and untouched.
- **Posts left with no category at all are moved to the default.** WordPress requires every post to sit in at least one category, so if the category you deleted was a post's only one, that post lands in whichever category is set as **Default Post Category** under **Settings** then **Writing**. On most sites that is still **Uncategorized**.
- **Posts that had other categories simply lose one.** They keep the rest and are not touched by the default.
- **Child categories are promoted, not deleted.** If the category you delete has sub-categories, they survive and move up a level rather than disappearing with their parent.
- **The archive URL stops working.** The page at `https://yourdomain.com/category/the-slug/` (replace `yourdomain.com` and `the-slug` with your own) begins returning a 404 as soon as the category is gone.
- **There is no undo.** Categories do not go to the trash. A deleted category can only be recreated by hand, and recreating it does not restore the posts that were filed under it.
None of this is a reason to avoid deleting categories. It is a reason to glance at the **Count** column first, so you know how many posts are about to be reshuffled.
## Step 1: Log In to the WordPress Dashboard
Go to `https://yourdomain.com/wp-admin` and sign in with an Administrator or Editor account.
If the dashboard password has been mislaid, you do not have to reset it first. The WordPress management tooling in your Noiz control panel lists every installed site and offers a one-click login that signs you in as an administrator, so you can go straight to step 2 from there.
## Step 2: Open Posts and Then Categories
In the left-hand dashboard menu, hover over **Posts** and click **Categories**.

The screen splits into the **Add New Category** form on the left and the table of existing categories on the right. Before deleting anything, read across the row you have in mind:
- **Name** and **Slug**: the slug is the part that appears in the archive URL, so this tells you which public address is about to break.
- **Count**: how many published posts are currently filed there. Click the number to see exactly which posts they are. A count of `0` means the category is safe to remove with no side effects at all.
- **Indentation**: a category shown indented beneath another is a sub-category. Anything indented under the row you are deleting will be promoted to the top level.
## Step 3: Hover Over the Category and Click Delete
Move your mouse over the category you want to remove. A row of links fades in underneath the name: **Edit**, **Quick Edit**, **Delete** and **View**. The **Delete** link is red.
Click **Delete**. Your browser shows a confirmation dialogue warning that the item will be permanently removed and that the action cannot be undone. Confirm with **OK**.

The row disappears from the table immediately and the reassignment happens in the same moment. There is no progress bar and no second screen, even on a category holding hundreds of posts.
## Deleting Several Categories at Once
On a site inherited from someone else there is usually more than one category to clear out. The bulk action handles them in a single pass:
1. Tick the checkbox beside each category you want to remove. The checkbox in the header row selects everything currently listed.
2. Open the **Bulk actions** drop-down above the table and choose **Delete**.
3. Click **Apply**.
Bulk delete does not ask for confirmation, so check your ticks before clicking **Apply**. Every post that ends up category-less goes to the default category in one go, which on a large clear-out can leave a lot of content sitting in **Uncategorized**. If that is not what you want, move the posts first using the section below.
The default category is skipped silently if you tick it as part of a bulk selection, since WordPress will not delete it under any circumstances.
## Move the Posts Somewhere Sensible First
If the category you are deleting holds posts that belong somewhere specific, assign them before you delete rather than fishing them out of the default afterwards.
1. Go to **Posts** then **All Posts**.
2. Use the category filter above the list to show only the posts in the category you are about to delete, then click **Filter**.
3. Tick the posts you want to move, choose **Edit** from **Bulk actions** and click **Apply**.
4. Tick the correct category in the panel that opens and click **Update**.
Bulk edit can only add a category, never remove one, so the posts will briefly belong to both. Deleting the old category in the next step strips it from them and leaves the new one in place. That is the tidiest way to reorganise, and it means nothing touches the default category at all.
For a larger clear-out, see [How to Manage WordPress Categories the Right Way](/wordpress/how-to-manage-wordpress-categories-the-right-way/), which covers merging and restructuring rather than deleting one at a time.
## Why One Category Has No Delete Link
If a category shows **Edit**, **Quick Edit** and **View** but no **Delete**, and its row has no checkbox either, it is the site's default post category. WordPress hides the option rather than letting you remove the place it needs to file uncategorised posts.
The restriction follows the default setting, not the name. Set a different category as the default under **Settings** then **Writing**, and the old one becomes deletable straight away while the new default loses its own **Delete** link. The full walkthrough, including how to get rid of **Uncategorized** entirely, is in [How to Rename the Default Uncategorized Category in WordPress](/wordpress/how-to-rename-the-default-uncategorized-category-in-wordpress/).
## Deleting Categories From the Command Line
If your Noiz plan includes SSH access and WP-CLI is available, this is far quicker for bulk tidying. Run these from the site's root directory.
List the categories with their IDs and post counts:
```
wp term list category --fields=term_id,name,slug,count
```
Delete one by ID:
```
wp term delete category 12
```
Delete several at once:
```
wp term delete category 12 15 18
```
WP-CLI does not prompt for confirmation, and the same rules apply as in the dashboard: posts are reassigned to the default, children are promoted, and the default category itself cannot be removed. Take a database backup before a scripted clear-out on a live site.
## Gotchas Worth Knowing
- **The archive URL becomes a 404.** If the category has been live long enough to be linked from elsewhere or indexed by search engines, put a permanent redirect in place from the old path to whichever category now holds that content. The rule is in [How to Redirect a Page to Another Page or Website Using htaccess](/server-administration/how-to-redirect-a-page-to-another-page-or-website-using-htaccess/).
- **Menu entries are cleaned up, custom links are not.** A menu item added as a category object is removed automatically when the category goes. A menu item added as a **Custom Link** pointing at the same URL stays put and quietly leads to a 404. Check **Appearance** then **Menus**, or the navigation block in the site editor on a block theme.
- **Widgets and blocks referencing the category by ID stop working.** A category drop-down, a "recent posts from category X" block or a shortcode with the old ID will render empty rather than error, which is easy to miss. Load the front page after a clear-out and look for blank spaces.
- **Posts have not disappeared.** If content seems to go missing after a deletion, it is in the default category. Filter **Posts** then **All Posts** by that category to find it.
- **Tags are separate.** Categories and tags share the same underlying storage but are different taxonomies. Deleting a category leaves tags alone, and tags are managed under **Posts** then **Tags**.
- **WooCommerce product categories are separate too.** They live under **Products** then **Categories** and have their own default. Nothing you do on the post categories screen affects them.
- **Caches keep the old category alive.** A caching plugin, a server-side page cache or a CDN can carry on serving the deleted archive and the old sidebar list for a while. Purge the cache after deleting, then reload with a hard refresh.
- **Never delete categories directly in the database.** Removing rows from the term tables by hand leaves orphaned relationships and count values that no longer match reality, and if the deleted term was the default, WordPress starts recreating a fresh **Uncategorized**. Use the dashboard or WP-CLI so the cleanup runs properly.
- **On multisite, each site is independent.** Deleting a category on one site in a network changes nothing on the others.
## Troubleshooting
**Symptom**: There is no **Delete** link on the row. That category is the site's default. Set a different one under **Settings** then **Writing**, and the link appears.
**Symptom**: The **Categories** item is missing from the **Posts** menu. Your role is below Editor, or a plugin has hidden the menu. Sign in with an Administrator account and check the role assigned to you under **Users** then **All Users**.
**Symptom**: Hovering shows no links, or clicking **Delete** does nothing. The row actions rely on dashboard JavaScript, which a plugin conflict or a script error will break. Open the browser console to see the error, then deactivate plugins one at a time to find the culprit.
**Symptom**: The category is gone but still appears on the front of the site. A cache is serving an old copy. Purge every layer of caching in front of the site and hard refresh. If it persists, the category list you are looking at may be a hard-coded menu item rather than a live list.
**Symptom**: The **Count** column shows numbers that do not match reality after a clear-out. Term counts are stored, not calculated live, and can drift. Editing and updating any post in the affected category forces a recount, and WP-CLI can rebuild them all with `wp term recount category`.
**Symptom**: A category you deleted has come back. Either a plugin recreates it on load, or an import has run again. Check recently active plugins, and confirm the default post category setting still points at a real category.
**Symptom**: You deleted the wrong category. There is no undo. Recreate it with the same name and slug so the archive URL works again, then filter the default category under **Posts** then **All Posts** and bulk-edit the affected posts back into it. If the category held a lot of posts and you cannot tell which ones they were, restoring the database from a backup taken before the deletion is the only reliable route.
## Related Guides
- [How to Add a New Category in WordPress](/wordpress/how-to-add-a-new-category-in-wordpress/)
- [How to Rename the Default Uncategorized Category in WordPress](/wordpress/how-to-rename-the-default-uncategorized-category-in-wordpress/)
- [How to Manage WordPress Categories the Right Way](/wordpress/how-to-manage-wordpress-categories-the-right-way/)
- [How to Bulk Delete Posts in WordPress](/wordpress/how-to-bulk-delete-posts-in-wordpress/)
- [How to Remove Sample Posts, Pages and Comments From WordPress](/wordpress/how-to-remove-sample-posts-pages-and-comments-from-wordpress/)
## Need a hand?
Deleting a category is quick, but a category that has been live for years is usually linked from more places than you expect. If you are on a managed Noiz plan and would like the redirects put in place at the same time, or you want the category structure of an inherited site rebuilt properly without losing traffic, contact the Noiz support team through the client area with your domain name and the team will assist.
# How to Delete a Post in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-delete-a-post-in-wordpress/
Removing a post in WordPress is a two-stage job, and most people only ever do the first stage. Sending a post to the Trash takes it off your live site immediately but keeps it recoverable; emptying the Trash destroys it for good. This guide shows you how to remove a single published or draft post on a WordPress site hosted with Noiz, how to get one back when you change your mind, and the three things that catch people out afterwards: the media that stays behind, the URL that starts returning a 404, and the cached copy that keeps serving for a while.
If you need to clear out many posts in one go, use [How to Bulk Delete Posts in WordPress](/wordpress/how-to-bulk-delete-posts-in-wordpress/) instead. This article covers the single post case.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). The Trash workflow described here has been part of WordPress core since version 2.9 and behaves the same in the block editor and the classic editor. This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Posts Screen](https://wordpress.org/documentation/article/posts-screen/) for the full list of row actions on the All Posts list.
- [Trash](https://wordpress.org/documentation/article/trash/) for how the recycle bin works and what it retains.
- [Roles and Capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/) for which user roles are allowed to delete which posts.
- [wp-config.php: EMPTY\_TRASH\_DAYS](https://developer.wordpress.org/apis/wp-config-php/#empty-trash) if you want to change or disable the 30 day Trash retention.
## Prerequisites
- Access to your WordPress admin dashboard at `https://yourdomain.com/wp-admin`, replacing `yourdomain.com` with your own domain.
- A user account with permission to delete the post. An Administrator or Editor can delete anybody's posts. An Author can delete their own posts, published or not. A Contributor can only delete their own posts while they are still drafts or pending review.
- A recent backup if the post matters. Trash gives you a 30 day grace period by default, but that only helps if you notice the mistake inside 30 days.
## Send a Post to the Trash
1. Log in to your WordPress dashboard.
2. In the left-hand menu, go to **Posts** and click **All Posts**.

3. Find the post you want to remove. Hover your mouse over its title. A row of small links appears underneath it: **Edit**, **Quick Edit**, **Trash** and **View**. These only appear on hover, which is why they are easy to miss.
4. Click **Trash**.

WordPress reloads the list and shows a confirmation at the top of the screen reading **1 post moved to the Trash. Undo**. The post disappears from your live site straight away.
That **Undo** link is the fastest way to reverse a mistake, but it is only good for as long as you stay on that page. Reload or navigate away and it is gone, and you will need to restore the post from the Trash instead.
### Trashing a Post From Inside the Editor
If you already have the post open, you do not need to go back to the list. In the block editor, open the **Post** tab in the right-hand settings sidebar and click **Move to trash** at the bottom of the panel. In the classic editor, the **Move to Trash** link sits in the **Publish** box on the right. Either way the post is trashed immediately, with no confirmation prompt.
## Restore a Post From the Trash
1. Go to **Posts** and then **All Posts**.
2. Click the **Trash** link in the row of filters above the list. It only appears when there is something in the Trash, and the number in brackets tells you how many posts are in there.
3. Hover over the post you want back and click **Restore**.
A restored post returns with its original content, categories, tags, featured image, comments and permalink intact. What does not always come back is its published status: WordPress restores posts to **Draft** in many cases, so check the post and republish it if it needs to be live again.
## Delete a Post Permanently
Emptying the Trash is irreversible. There is no second recycle bin and no undo, so the only route back after this point is a backup restore.
1. Go to **Posts**, then **All Posts**, then click the **Trash** filter.
2. To destroy one post, hover over it and click **Delete Permanently**.
3. To destroy everything in the Trash at once, click **Empty Trash**.
Permanently deleting a post also removes its comments, its revision history and its custom fields. It does not remove anything from the Media Library.
You usually do not need to do this at all. WordPress empties the Trash by itself: any post that has been sitting in there for more than 30 days is deleted automatically the next time the site's scheduled tasks run.
### Changing or Disabling the 30 Day Trash
The retention period is set in `wp-config.php`. To shorten it to seven days, add this line above the `/* That's all, stop editing! */` comment:
```
define( 'EMPTY_TRASH_DAYS', 7 );
```
Setting the value to `0` switches the Trash off entirely. Every **Trash** link in the admin turns into **Delete Permanently**, and a single mis-click destroys a post with no way back. Noiz does not recommend it on any site with more than one author.
## What Happens After a Post Is Gone
### Its Media Stays in the Library
Deleting a post never deletes the images, PDFs or videos that were uploaded to it. They remain in **Media** and, more to the point, they remain publicly reachable at their direct file URL, for example `https://yourdomain.com/wp-content/uploads/2026/03/report.pdf`. If the post was removed because its contents were confidential or wrong, go to **Media** and delete the attachments as well. Nothing about removing the post hides them.
### Its URL Starts Returning 404
The moment a post is trashed, its address becomes a 404 Not Found for anyone following an old link, a bookmark or a search result. If the post had traffic or inbound links, that is a real loss and worth handling deliberately:
- **Redirect it** to the nearest equivalent page with a 301, using a redirection plugin or a rule in your site configuration. This is the right answer when the content moved or was replaced.
- **Set it to Private or Draft instead of deleting it.** Editing the post and changing its visibility to **Private** takes it off the public site while keeping it, the URL and the history available to logged in editors. This is often the better choice for content you are only removing because it is out of date.
- **Leave it as a 404** if the post was junk, spam or a test. Search engines will drop it from the index on their own over the following weeks.
### A Cached Copy May Keep Serving
If your site uses a caching plugin, or sits behind a CDN, the deleted post can carry on being served to visitors from the cache after it has left WordPress. Most caching plugins clear the relevant pages automatically when a post changes, but the site's home page, category archives and any CDN copy often lag. If the post is still visible on the live site after you trashed it, purge the site cache and the CDN cache, then check again in a private browsing window.
## Troubleshooting
**Symptom**: there is no **Trash** link when you hover over the post. Your user role does not have permission to delete that post. Contributors cannot delete a post once it has been published, and Authors cannot delete posts written by other people. Ask an Administrator or Editor on the site to remove it, or have your role changed.
**Symptom**: the row actions read **Delete Permanently** instead of **Trash**. The Trash has been disabled on the site with `define( 'EMPTY_TRASH_DAYS', 0 );` in `wp-config.php`. Anything you click there is destroyed immediately with no recovery. Change the value to a positive number of days to get the safety net back.
**Symptom**: there is no **Trash** filter above the posts list. The Trash is empty, so WordPress hides the link. It reappears as soon as something is in there.
**Symptom**: the post is still on the live site after being trashed. This is nearly always caching. Purge your caching plugin and your CDN, then reload in a private window. If it survives that, confirm you trashed the post rather than a copy of it, and check whether the content is also duplicated in a widget, a page builder template or a static home page.
**Symptom**: *Are you sure you want to do this?* appears when you click Trash. The security token on the page expired because the admin screen had been open for a long time. Go back, reload the posts list, and click **Trash** again.
**Symptom**: trashed posts keep coming back, or the Trash never empties itself. The site's scheduled task runner is not firing, which also affects scheduled publishing, backups and update checks. See [How to Disable wp-cron.php and Use a System Cron in WordPress](/wordpress/how-to-disable-wp-cronphp-and-use-a-system-cron-in-wordpress/).
## Related Articles
- [How to Bulk Delete Posts in WordPress](/wordpress/how-to-bulk-delete-posts-in-wordpress/) for clearing out several posts at once.
- [How to Remove Sample Comments and Posts From WordPress](/wordpress/how-to-remove-sample-posts-pages-and-comments-from-wordpress/) for tidying up a fresh installation.
- [How to Write and Publish Your First Blog Post in WordPress](/wordpress/how-to-write-and-publish-your-first-blog-post-in-wordpress/) for creating posts in the first place.
- [How to Manage WordPress Categories the Right Way](/wordpress/how-to-manage-wordpress-categories-the-right-way/) for keeping the rest of your content organised.
## Getting Help
If you have permanently deleted a post you needed, stop working on the site and open a ticket in the Noiz client area straight away, quoting the domain, the post title and roughly when it was deleted. On managed plans the Noiz team can check whether a backup taken before the deletion still holds the post, and the sooner you ask the more likely that is. Continuing to publish and edit in the meantime makes a clean restore harder.
# How to Delete a WordPress Theme
Source: https://docs.noiz.ie/wordpress/how-to-delete-a-wordpress-theme/
Every theme installed on your WordPress site is live PHP code sitting in `wp-content/themes`, whether it is active or not. Inactive themes still need updating, still take up disk space, and still count as attack surface if a vulnerability is published for one of them. Removing the themes you no longer use is one of the quickest security wins available to you.
This guide shows you how to delete a WordPress theme from the dashboard, explains exactly what deletion removes, and covers the two themes you should think twice about deleting.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
WordPress 7.0 refreshed the admin interface with a new "Modern" colour scheme, updated typography and smoother screen transitions, but no menus were moved and no settings were renamed. The screenshots below show the earlier styling; the menu paths, button labels and wording are the same in current WordPress.
### Official Documentation Reference
- [Appearance Themes Screen](https://wordpress.org/documentation/article/appearance-themes-screen/) for the full reference on the theme management screen.
- [Child Themes](https://developer.wordpress.org/themes/advanced-topics/child-themes/) for how parent and child themes depend on each other.
- [WordPress Backups](https://wordpress.org/documentation/article/wordpress-backups/) for backup approaches before you make destructive changes.
## Prerequisites
- Administrator access to the WordPress dashboard. See [How to Log In to the WordPress Dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A current backup of the site, or at minimum a copy of the theme folder. Theme deletion is permanent: there is no trash and no undo.
- The theme you want to delete must not be the currently active theme, and must not be the parent of the currently active theme.
## Why Unused Themes Are Worth Removing
- **Vulnerabilities do not care whether a theme is active.** A theme flaw is a flaw in files that exist on disk. Some theme vulnerabilities are exploitable through files that can be requested directly, without the theme ever being activated.
- **Inactive themes stop getting attention.** People update the theme they can see and forget the three they cannot. An old, unpatched theme sitting quietly for two years is a classic entry point.
- **Less to scan, less to back up, less to restore.** Fewer files means faster malware scans, smaller backups and quicker migrations.
- **Clarity.** When something breaks, a themes screen with two entries is far easier to reason about than one with nine.
## Before You Delete: What Actually Gets Removed
Deleting a theme through the dashboard removes the entire theme folder from `wp-content/themes`. Understand what that means before you click.
- **Any edits you made to the theme files are gone.** If someone edited the theme's PHP or CSS directly rather than using a child theme, those changes are deleted along with everything else. This is exactly why direct theme edits are a bad idea. See [How to Install a WordPress Theme Manually](/wordpress/how-to-manually-install-a-wordpress-theme-from-a-zip-file/) if you need to keep a copy of the folder first.
- **Your posts, pages, media and users are untouched.** Content lives in the database and the uploads folder, not in the theme.
- **Customiser settings survive in the database but become dormant.** WordPress stores each theme's settings separately. Reinstalling the exact same theme later usually brings those settings back; installing a different theme will not inherit them.
- **Menus and widget assignments reset.** Menus themselves remain, but the locations they were assigned to belonged to the deleted theme.
- **Premium themes need their original files again.** If the theme was purchased, make sure you can still download the ZIP and that your licence is valid before deleting it.
If you are unsure whether anything depends on the theme, take a backup first. On a Noiz managed plan you can ask Noiz support to take a restore point before you start.
## Delete a Theme From the WordPress Dashboard
**1.** Log in to the WordPress dashboard.
**2.** From the dashboard menu, go to **Appearance** and click **Themes**.

**3.** Hover your mouse over the theme you want to remove, then click **Theme Details**. The active theme is always shown first and does not offer a delete option, which is your safety net against removing the theme the site is running on.

**4.** In the theme details panel, click **Delete** in the bottom right corner, then confirm with **OK** in the browser prompt.

The theme disappears from the list and its folder is removed from the server. Repeat for each theme you no longer need.
## Which Themes to Keep
Do not empty the themes folder completely. Keep the following:
- **Your active theme.** WordPress will not let you delete it from this screen, and you should not delete it any other way either.
- **The parent theme, if you are running a child theme.** A child theme is only a set of overrides; it inherits templates and functions from its parent. Delete the parent and the child stops working immediately. On the Themes screen a child theme shows the parent name in its details panel, so check there if you are not certain.
- **One current default theme**, such as the latest Twenty Twenty series theme. WordPress falls back to a default theme when the active theme is broken or missing, and recovery mode relies on having one available. Keeping a single default theme installed and updated costs you almost nothing and gives you a working site to fall back to when a theme update goes wrong.
Everything else is fair game. If you are trialling several themes, delete the ones you rejected rather than leaving them installed "just in case". Reinstalling a free theme from the WordPress theme directory takes under a minute. See [How to Install a New WordPress Theme](/wordpress/how-to-install-a-wordpress-theme-from-the-dashboard/).
## Deleting Themes on a Multisite Network
On a WordPress multisite network, themes are installed once and shared across every site in the network. Individual site administrators see no delete option at all. To remove a theme, log in as a network administrator and go to **My Sites**, then **Network Admin**, then **Themes**. From there you can select one or more themes and use the **Delete** bulk action.
Before deleting, confirm that no site in the network has the theme active. Removing a theme that a sub-site is running will break that sub-site, not just deactivate it.
## Deleting a Theme Manually
If the dashboard is unreachable, or the theme itself is causing a fatal error that blocks the admin area, you can delete the folder directly instead.
1. Open the File Manager in your Noiz hosting control panel, or connect over SFTP.
2. Navigate to your WordPress installation, then to `wp-content/themes`.
3. Delete the folder matching the theme's directory name, for example `oldtheme`.
If you delete the folder of the theme that is currently active, WordPress falls back to an available default theme where one exists. If no theme remains, the front end will fail with a theme directory error until you upload one. That is the practical reason for the "keep one default theme" rule above.
## Troubleshooting
- **Symptom**: there is no **Delete** link in the theme details panel. The theme is either the active theme or, on multisite, you are not in Network Admin. Activate a different theme first, or switch to the network administrator view.
- **Symptom**: WordPress asks for FTP or SSH connection details when you try to delete. WordPress cannot write to the themes directory as the web server user. This is a file ownership or permission problem on the account rather than something to solve by entering credentials. Contact Noiz support and it will be corrected on the server.
- **Symptom**: the site shows a blank page or a "stylesheet is missing" error after a deletion. The active theme's parent was deleted, or the active theme itself was removed manually. Reinstall the missing theme, or upload a default theme into `wp-content/themes` and activate it.
- **Symptom**: the theme reappears after deletion. Something is reinstalling it, most commonly a theme or plugin bundle that ships its own dependencies, or an installer profile that reprovisions the site. Check for any staging or auto-install tooling pointed at the site.
- **Symptom**: layout or menus look wrong after deleting an unrelated theme. Clear any caching plugin and your CDN or browser cache, then reload. Cached CSS referencing the removed theme is the usual cause.
Cleaning out unused themes pairs naturally with the same job on plugins. See [How to Deactivate and Delete a WordPress Plugin](/wordpress/how-to-deactivate-and-delete-a-wordpress-plugin/), and the broader [WordPress Security Checklist](/wordpress/wordpress-security-checklist/).
If you are not sure whether a theme is safe to delete, or a deletion has left the site in a bad state, open a ticket with Noiz support from your client area. On managed plans Noiz can check what the site depends on, take a restore point, and remove the theme for you.
# How to Disable wp-cron.php and Use a System Cron in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-disable-wp-cronphp-and-use-a-system-cron-in-wordpress/
WordPress runs its scheduled tasks (publishing scheduled posts, checking for updates, clearing transients, and anything plugins queue) through a file called `wp-cron.php`. On a busy site, the default way this file is triggered becomes a real performance problem. This guide explains why, and shows you how to switch WordPress over to a proper system cron so scheduled tasks still run reliably without the overhead.
**Last reviewed:** 27 July 2026, against current WordPress **6.x** releases. WP-Cron behaviour has been stable across recent WordPress versions. This guide is written for Noiz hosting and complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Plugin Handbook: WP-Cron](https://developer.wordpress.org/plugins/cron/)
- [Hooking WP-Cron Into the System Task Scheduler](https://developer.wordpress.org/plugins/cron/hooking-wp-cron-into-the-system-task-scheduler/)
## What is wp-cron.php and how does it work?
The `wp-cron.php` file is how WordPress handles scheduled events by default. Any function that relies on scheduling, such as core updates, plugin update checks, and scheduled post publishing, is handled through this file.
For this to work correctly, the file needs to run frequently, but no more than roughly once per minute. The problem is that WordPress does not use a system-level cron job out of the box. Instead, it triggers on incoming traffic: when a visitor requests a page, WordPress fires an additional request to `wp-cron.php` over HTTP(S) to check whether any scheduled task is due.
## Why is this a problem?
On a small site with only a handful of visitors per hour, this approach works fine. On a medium or larger site, or on any site that attracts a lot of bot traffic and vulnerability scans, it does not. Every one of those requests can spawn a second internal request to `wp-cron.php`, so the site more than doubles the load it places on itself. In effect, WordPress ends up DDoS-ing itself: pages slow down, and the web server carries needless extra load.
There is a second, subtler issue. Because WP-Cron only runs when someone visits, scheduled tasks on a low-traffic site can run late or not at all, so a post scheduled for 09:00 might not publish until the next visitor arrives.
## The better approach: disable WP-Cron and use a system cron
The fix is to turn off the built-in trigger and let the server run WordPress's scheduled tasks on a fixed timetable instead. This keeps scheduled tasks running predictably while removing the per-request overhead. Running the job through the shell, rather than over HTTP(S), also avoids the extra web-server memory a full HTTP request would consume. If you would rather not touch configuration files at all, a Noiz Managed WordPress plan applies this optimisation for you by default.
### Step 1: Disable the built-in WP-Cron
Edit your `wp-config.php` file and add the following line **above** the `/* That's all, stop editing! Happy publishing. */` comment:
```
define( 'DISABLE_WP_CRON', true );
```
The setting must sit above that line so it takes effect before WordPress finishes loading; placed after it, the define is read too late to have any effect. The `wp-config.php` file lives in your site's root directory, typically `public_html`, though the exact path varies by host and control panel.
### Step 2: Set up a system cron
With the built-in trigger disabled, add a scheduled task on the server to call `wp-cron.php` directly. Running it every 5 to 15 minutes suits most sites; increase the frequency only if you depend on tightly timed scheduled events. A typical command, run through the shell, looks like this:
```
*/5 * * * * php /home/example/public_html/wp-cron.php >/dev/null 2>&1
```
Replace the path with the real path to your site's `wp-cron.php`. Exactly how you add this depends on your control panel:
- [ISPConfig](/ispconfig/how-to-create-a-cron-job-in-ispconfig/)
- [Plesk](/plesk/how-to-create-scheduled-tasks-in-plesk/)
- [cPanel](/cpanel/how-to-create-a-cron-job-in-cpanel/)
- Ubuntu command line: on a managed cloud server, a Noiz administrator can set this up for you on request.
## Why it is worth doing
WordPress powers a huge share of the web, which makes the default scheduling behaviour a costly compromise at scale. It adds avoidable load to individual sites and, multiplied across a hosting network where many sites use the same resource-heavy method, to the infrastructure as a whole. Moving to a system cron removes that overhead and makes scheduled tasks more reliable at the same time.
If you would rather not edit configuration files yourself, a Noiz Managed WordPress plan handles this change by default, along with the other performance and maintenance benefits that come with managed hosting. Most site owners notice a clear speed improvement once WP-Cron is running from the system scheduler.
# How to Email Your Registered Users in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-email-your-registered-users-in-wordpress/
This guide explains how to email the people who have registered on your WordPress site, whether you call them members, subscribers, customers or simply users, and how to make sure those messages actually reach the inbox rather than the spam folder. It draws a clear line between three different things that often get muddled: the automatic emails WordPress already sends on your behalf, the deliberate messages and newsletters you compose yourself, and the point at which you should stop sending through your web server and switch to a proper email service. It is written for Noiz clients running a self-hosted WordPress site and assumes no prior knowledge of how email delivery works.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Users screen (WordPress Documentation)](https://wordpress.org/documentation/article/users-screen/): how the list of your registered users works, including the columns and the bulk actions that are actually available in WordPress core.
- [Roles and Capabilities (WordPress Documentation)](https://wordpress.org/documentation/article/roles-and-capabilities/): the user roles you can target when you want to email only a segment of your users, such as customers or members.
- [wp\_mail() function reference (WordPress Developer Resources)](https://developer.wordpress.org/reference/functions/wp_mail/): the single core function that WordPress itself, and every email plugin, uses to send a message; useful for understanding what happens behind the scenes.
- [Email sender guidelines (Google)](https://support.google.com/mail/answer/81126): the authentication, unsubscribe and spam-rate rules that now apply to anyone sending email to Gmail addresses, and a good proxy for what every mailbox provider expects.
- [POPIA Section 69: Direct marketing by unsolicited electronic communications](https://popia.co.za/section-69-direct-marketing-by-means-of-unsolicited-electronic-communications/): the South African law that governs when you may email your users a marketing message.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an administrator. Installing plugins and changing how the site sends email both require the administrator role.
- A real From address on your own domain, for example `hello@yourdomain.com` (replace this with your own address). It should be a mailbox you can actually receive replies and bounce messages at, not an address that only exists in a settings field.
- Access to your domain's DNS if you plan to send to more than a handful of people, so that the authentication records described later can be added.
- A clear idea of who you are emailing and why, because that decides which of the approaches below is the right one.
## The Emails WordPress Already Sends
Before installing anything, it helps to know that a plain WordPress site already emails your users automatically. These are triggered by events, sent one message at a time, and you never compose them by hand. They include:
- **New user registration**: when someone registers, WordPress emails them their username and a link to set a password, and notifies the site administrator that a new account exists.
- **Password resets**: the "lost your password" link sends a reset email to the account holder.
- **Comment notifications**: WordPress can email you when a comment is posted or is held for moderation.
- **Account and admin notices**: confirmation when someone changes the site or account email address, and automatic notices about updates or a critical site error.
All of these are **transactional** emails: they are a direct response to something a specific person did. WordPress generates them through a single internal function, `wp_mail()`, and by default that function hands each message straight to your web server's own mail system. This matters later, because that default path is also the reason so many WordPress emails end up in spam.
What WordPress does **not** include is any way to sit down, write a message, and send it to all of your registered users at once. There is no "email your users" screen anywhere in the standard dashboard. That deliberate, one-to-many kind of email is the part you have to add.
## Where Your Registered Users Live
Every registered account appears under **Users** then **All Users** in the dashboard. The table lists each person's username, name, email address and role, and you can filter it by role, sort it, or search it.

It is tempting to assume that because you can see everyone's email address here, you can select them and send a message. You cannot. If you open the **Bulk Actions** drop-down at the top of the list, the only choices WordPress core offers are **Delete** and **Change role to**. There is no send-email action.

This screen is still useful, though: the **Role** column is how you decide who to email. A membership or shop plugin usually gives members and customers their own roles, so "email all customers" really means "email everyone with the customer role". Keeping that in mind makes the tools below far more precise than blasting every account on the site.
## Sending a Message to Your Users
Because WordPress has no built-in broadcast feature, you choose one of three broad approaches. They are not competitors so much as answers to different needs, and larger sites often use more than one at the same time.
### Option 1: An email-to-users plugin (occasional, low volume)
Several free plugins add a simple compose screen to the dashboard and let you send a message to every user, or to a chosen role. Plugins such as *Send Users Email*, *Email Users* and *Mass Email To Users* are examples of this category; naming them is not an endorsement. This is the quickest way to send an occasional announcement to a modest number of people.
Understand the important limitation before you rely on one: by default these plugins still send through your web server's mail system, the same unauthenticated path WordPress uses for its own emails. The plugin controls who receives the message and what it says, but it does nothing on its own to help the message reach the inbox. For a dozen recipients that is usually fine. For hundreds, it is not, which is what the next two options and the deliverability section address.
Because a plugin like this can read every registered user's email address and send email in your domain's name, treat it as a powerful, sensitive tool. Check a plugin's reviews, active-install count, last-updated date and how it handles data before installing it, and keep it updated afterwards. The [WordPress Security Checklist](/wordpress/wordpress-security-checklist/) explains how to vet and maintain plugins safely.
### Option 2: A newsletter or marketing platform (regular campaigns, growing list)
If you plan to send newsletters, product updates or promotions on a regular basis, use a dedicated email marketing service instead. These platforms handle the things a simple plugin does not: reusable templates, audience segmentation, scheduling, open and click tracking, automatic unsubscribe links, bounce handling and consent records. Many connect to WordPress through their own plugin that keeps your users or subscribers in sync. Services such as Mailchimp, Brevo, MailerLite and MailPoet are examples, again offered only as illustrations rather than recommendations.
The crucial difference is where the sending happens. With a marketing platform, your messages go out over the provider's own authenticated mail infrastructure, not your web server, so deliverability and list management are largely taken care of for you. This is the right home for anything that looks like a mailing list.
### Option 3: Authenticated SMTP for the emails you already send
Sometimes the real problem is not that you want to broadcast anything, but that the transactional emails WordPress and your plugins already generate, order receipts, membership notices, password resets, are not arriving. The fix here is an **SMTP plugin**. It does not add a compose feature; instead it reroutes `wp_mail()` so that every email WordPress sends goes out through an authenticated mail service rather than the raw web-server path. Plugins such as *WP Mail SMTP*, *FluentSMTP* and *Post SMTP* are examples of this category.
An SMTP plugin is often worth installing regardless of which other option you choose, because it also lets you set a proper From name and address for the whole site and makes your existing automatic emails much more reliable.
## When to Move Off Your Web Server's Mail
The single most useful thing to understand is why the default path fails as you grow. When WordPress sends through your web server, the message leaves from the server's shared IP address with no proof that you are allowed to send as your domain. Receiving mail systems see an unsigned message from an address they cannot verify and, quite reasonably, treat it with suspicion. The specific weaknesses are:
- **No authentication**: the message is not signed with your domain's DKIM key, and the sending server is usually not listed in your domain's SPF record, so receivers cannot confirm it is genuine.
- **Shared reputation**: the server's IP address is shared with other sites, and you do not control how it is regarded by mailbox providers.
- **Volume limits**: web servers are built to serve pages, not to push out large batches of email. Sending hundreds or thousands of messages can hit limits, back up in a queue, or get the server flagged.
- **No list hygiene**: bounces, spam complaints and unsubscribes are not tracked, so problems build up invisibly and damage your reputation further.
A simple rule of thumb: if you send a few transactional emails a day, an authenticated SMTP setup (Option 3) is plenty. The moment you are sending a genuine mailing list, whether that is tens, hundreds or thousands of people at once, move that sending to a dedicated email or marketing service (Option 2) that is designed for it. Trying to run a newsletter through your web server's mail is the most common cause of the deliverability problems below.
## Deliverability: Getting Into the Inbox
Deliverability is the umbrella term for whether your emails actually arrive. It rests on three DNS records that together prove your messages are legitimate:
- **SPF** lists which servers are allowed to send email for your domain.
- **DKIM** adds a cryptographic signature so receivers can confirm a message really came from you and was not altered.
- **DMARC** ties the two together and tells receivers what to do with mail that fails the checks, while giving you reports on what is being sent in your name.
These are no longer optional. Since the major mailbox providers tightened their rules in 2024, and Microsoft extended similar enforcement in 2025, SPF, DKIM and DMARC, together with a working one-click unsubscribe link and a spam-complaint rate kept well below one in three hundred messages, are effectively required for anyone sending in any volume. The strictest thresholds apply above roughly five thousand messages a day, but the same practices are what keep even a small site out of spam.
Setting up SPF, DKIM and DMARC for your Noiz-hosted domain, and connecting an authenticated mail service, is covered in the email deliverability documentation in the **Email** section of this knowledgebase. This guide deliberately does not repeat those steps, so that there is one authoritative place to keep them current. Beyond the DNS records, a few habits keep your delivery healthy:
- Always send from a real mailbox on your own domain, so replies and bounce messages reach you and so DMARC alignment works.
- Keep the unsubscribe link working and honour opt-outs promptly; a rising complaint rate is the fastest way to land in spam.
- Grow your sending gradually rather than mailing a large list from a cold start.
- Remove addresses that bounce, and only email people who genuinely expect to hear from you.
## Consent and the Law (POPIA)
Being able to email your users is not the same as being allowed to. This is a point worth taking seriously precisely because a plugin makes it so easy to email everyone at once.
Under South Africa's Protection of Personal Information Act (POPIA), section 69, direct marketing by electronic means, which includes email, is only permitted when the recipient has given consent, or is an existing customer whose contact details you collected during a sale, where you are marketing your own similar products or services and you gave them a fair chance to opt out. In practice this means someone registering an account, or buying from you, does not automatically agree to receive your newsletter.
Service and transactional emails, such as password resets, order confirmations and account notices, are not marketing and are unaffected. But promotional messages and newsletters need either consent or the existing-customer basis, every marketing email must offer an easy way to unsubscribe, and you should keep a record of how and when each person opted in. A good marketing platform (Option 2) records consent and manages unsubscribes for you, which is another reason to use one rather than a bare plugin once you are marketing rather than simply notifying. This is general guidance and not legal advice; if you are unsure, read the Act or speak to a professional.
## Troubleshooting
- **Users say the email never arrived, or found it in spam**: the message almost certainly went out through the unauthenticated web-server path. Route your mail through an authenticated service using an SMTP plugin or a marketing platform, and confirm SPF, DKIM and DMARC are in place for your domain. A mail-testing tool that scores a sample message will pinpoint what is missing.
- **Small messages send, but large batches do not**: you are hitting your web server's sending limits. Move bulk sending to a dedicated email service with its own sending queue rather than pushing the whole list through WordPress.
- **The From address shows something like `wordpress@yourdomain.com` or a server hostname**: no proper sender has been set. In your SMTP or marketing plugin, set a From name and a real From address on your own domain, so replies and bounces reach you and so the message passes DMARC alignment.
- **Password resets and other automatic emails do not arrive**: this is the same deliverability problem affecting transactional mail. Fix it with an authenticated SMTP setup. It is not a reason to install a bulk-email plugin, which would not help.
- **Bounces and complaints are climbing**: your list contains stale or non-consenting addresses. Remove addresses that bounce, honour every unsubscribe, and only email people who opted in. Ignoring this steadily wrecks your inbox placement for everyone else on the list.
If you are on a Noiz managed hosting plan, the support team can help you set up authenticated sending and the SPF, DKIM and DMARC records your domain needs, so your WordPress emails reach the inbox. If you are self-managed and get stuck, open a support ticket and include your domain, what you are trying to send, roughly how many recipients are involved, and what your recipients see happening, so the team can point you to the right approach.
# How to Find Your WordPress Login URL
Source: https://docs.noiz.ie/wordpress/how-to-find-your-wordpress-login-url/
Every WordPress site has a private sign-in page where you enter a username and password to manage it, and this guide shows you how to find that address for your own site. You will learn the two addresses WordPress uses by default, why a site owner might deliberately move or hide the sign-in page for security, how to track the address down when it has been changed and you can no longer remember it, and how to save it so you never have to hunt for it again. People call this the login URL, the admin URL, the wp-admin address or simply "the back end", and they all mean the same thing: the web address that brings up the login box. This article is written for Noiz clients who run WordPress, and it assumes nothing more than that you know your own domain name.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Administration Screens (WordPress Documentation)](https://wordpress.org/documentation/article/administration-screens/): describes the admin area that sits behind the login page, which is where the login address ultimately takes you.
- [Reset your password (WordPress Documentation)](https://wordpress.org/documentation/article/reset-your-password/): the official reference for the "Lost your password?" link that lives on the standard login page.
- [Giving WordPress its own directory (WordPress Developer Resources)](https://developer.wordpress.org/advanced-administration/server/wordpress-in-directory/): explains how a subfolder installation changes the address of the admin area.
## Prerequisites
- You know the domain name your WordPress site is published on, for example `yourdomain.com`.
- To actually sign in once you have the address, you also need your WordPress username and password. This article is only about locating the address; the sign-in itself, including the "Remember Me" option, is covered in [How to Log In to the WordPress Admin Dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
## The Two Default Addresses
On a standard WordPress installation there are two addresses that both lead to the login screen. Neither one is linked from your public website, which is deliberate: the login page is for site managers, not visitors, so WordPress keeps it out of the menus. You reach it by typing the address into your browser directly.
### yourdomain.com/wp-login.php
This is the login page itself. It works because `wp-login.php` is a real file sitting in the top folder of your WordPress installation on the server, and requesting it in a browser draws the login form on screen. Type your own domain in front of it, so if your site is published at `yourdomain.com` the address is `https://yourdomain.com/wp-login.php`. This same page carries the **Lost your password?** link, so it is also where you start a password reset.

### yourdomain.com/wp-admin/
The second address is `https://yourdomain.com/wp-admin/`. This is the address of the dashboard, the control panel you land on after signing in. Most people find it the easier of the two to remember. If you visit it while you are already signed in, it opens the dashboard straight away. If you visit it while you are signed out, WordPress cannot show you the dashboard, so it automatically forwards you to the login page first. You will notice the address bar change to something longer such as `wp-login.php?redirect_to=...`. That extra part is WordPress remembering where you were heading, so that the moment you log in successfully it returns you to the dashboard rather than dropping you on a blank page. In everyday use, then, typing `/wp-admin/` and typing `/wp-login.php` get you to the same place.
### A note on /admin and /login
Many people instinctively try `yourdomain.com/admin` or `yourdomain.com/login`, because that is how a lot of other systems work. WordPress does not create those two shortcuts by itself, so on a plain installation they lead nowhere useful. They only work if the site owner, a theme or a plugin has been set up to redirect them to the real login page. It is worth a try, but if it fails, fall back on the two addresses above rather than assuming the login is broken.
## When Your Site Lives in a Subfolder
The addresses above assume WordPress is installed at the root of your domain. Some sites instead keep WordPress in a subfolder, for example a blog running under `yourdomain.com/blog/` while the main homepage is something else. When that is the case, you simply add the subfolder to the address: the login page becomes `https://yourdomain.com/blog/wp-login.php` and the dashboard becomes `https://yourdomain.com/blog/wp-admin/`.
There is one variation worth knowing about. WordPress can be set up so that the site is viewed at the clean root address while its core files, and therefore its admin area, live in a subfolder. If your public site loads at `yourdomain.com` but `/wp-admin/` does not lead anywhere, the admin area is most likely tucked into a subfolder like this. The controlling value is the **WordPress Address (URL)** field under **Settings > General** in the dashboard, which points at wherever the core files live. If you can already get into the dashboard from another device, check that field to confirm exactly where your login and admin area are served from.

## When the Login Page Has Been Moved or Hidden
If you visit `/wp-login.php` or `/wp-admin/` and instead of the login box you get a **404 Not Found** page, or you are quietly bounced back to your homepage, the login page has almost certainly been moved to a custom address on purpose. This is a common and legitimate security measure. The default `wp-login.php` is the very first place automated attacks try when they attempt to guess passwords across the internet, so hardening the site by changing the login address, sometimes called changing the login slug, cuts off a large volume of that unwanted traffic. Various security plugins and server-level hardening setups offer this as a feature, and any of them may have been switched on by whoever built or maintains your site.
When this has been done, the login page still exists, it just answers to a different, private address that only the people who set it up are meant to know, for instance `yourdomain.com/my-private-login`. The two default addresses are usually turned into dead ends at the same time, which is exactly why they now return a 404 or redirect away. So a 404 at `/wp-login.php` is not a sign that anything is broken; it is a sign that the login has been deliberately relocated. Moving the login page is one of several steps covered in the [WordPress Security Checklist](/wordpress/wordpress-security-checklist/).
## How to Find an Address That Has Been Changed
If the login has been moved and you do not know the new address, work through these in order. One of the first few almost always turns it up.
- **Your password manager.** If you have ever saved your WordPress login in a browser or a dedicated password manager, the saved entry records the exact web address alongside the username and password. This is the single quickest place to look, because a password manager stores the real address you signed in at, custom slug and all.
- **Your bookmarks and browser history.** Look through your bookmarks, then search your browser history for your domain name or for the word "login". The custom address will show up if you have visited it before.
- **The original welcome email.** When WordPress was first installed, it sent a setup or welcome email that included a direct link to the login page. Search your inbox for your domain name or for "WordPress". If the login was already customised at install time, that email carries the correct link.
- **Whoever set the site up.** If a developer, agency or colleague built or manages the site, they chose the custom address and can simply tell you what it is. This is often the fastest route of all.
- **A device you are still signed in on.** If any computer or phone is still logged into the dashboard, you can read the custom address straight from the settings of the security plugin or hardening tool that changed it, then note it down for future use.
- **On the server, with help.** As a last resort the address can be recovered from the site's files or database on the Noiz server. Where a hardening tool stores its custom login address varies from tool to tool, so this is genuinely fiddly. Rather than guess, managed-plan clients can open a ticket and ask the Noiz support team to locate it. If you prefer to look yourself and you are comfortable with it, the site's settings are reachable through **phpMyAdmin** for the database and through **SFTP** or the panel **File Manager** for the files, on Plesk, DirectAdmin or ISPConfig alike.
## Save the Address So You Do Not Lose It Again
Once you have a login address that works, capture it so this is the last time you go looking. Bookmark it in your browser, and let your browser or password manager save the address the next time you sign in, which stores the login address and your credentials together. If your site keeps WordPress in a subfolder, or the login has been moved to a custom slug, saving it matters even more, because there is no obvious address for you or anyone else to guess your way back to.
One thing to keep separate in your mind: bookmarking the address is not the same as staying signed in. A bookmark saves the location of the login page; the **Remember Me** checkbox on that page is what keeps you signed in for a couple of weeks so you are not asked for your password every visit. You generally want both.
## Troubleshooting
- **Symptom**: `/wp-login.php` returns 404 Not Found. The login page has been moved to a custom address for security. Recover the new address using the methods above, starting with your password manager or the person who manages the site.
- **Symptom**: `/wp-admin/` redirects to your homepage instead of a login box. This is another sign the login has been relocated or hidden, so the default admin address has been closed off. Find the custom address as above.
- **Symptom**: the address bar cycles through redirects or shows "too many redirects", and the login never appears. This usually points to a mismatch between the **WordPress Address (URL)** and **Site Address (URL)** settings, or a mix of `http` and `https` versions of the address, rather than a missing login page. The Noiz support team can straighten out the site addresses for you.
- **Symptom**: you reach the login page fine but your username or password is not accepted. The address is correct; this is a credentials problem, not a location one. Use the **Lost your password?** link on the login page, or if the reset email never arrives, follow [How to Reset a WordPress Admin Password via phpMyAdmin](/wordpress/how-to-reset-a-wordpress-admin-password-via-phpmyadmin/).
If you have worked through the options here and still cannot find the address for your site, open a support ticket with the Noiz support team. Include your domain and mention whether the site was set up with any security or login-hardening tools, and the team can locate the correct login address for you. Once you are in, keep [How to Log In to the WordPress Admin Dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) handy for the sign-in itself.
# How to Fix Common WordPress Errors
Source: https://docs.noiz.ie/wordpress/how-to-fix-common-wordpress-errors/
This guide helps you diagnose and fix the errors that most often take a WordPress site offline: the white screen of death, the 500 internal server error, "error establishing a database connection", posts that suddenly return 404 Not Found, exhausted memory, a PHP syntax error after editing a file, being locked out of the admin dashboard, and a site stuck in maintenance mode. For each error you get the same three things: what you actually see, the likely cause, and a clear fix. It is written for Noiz hosting clients who run WordPress and want to get back online quickly, whether you have dashboard access or not.
Most of these errors look alarming but come from a small number of root causes: a bad plugin or theme, a broken file, a server limit, or wrong database details. Work through the relevant section calmly and in order, and you will usually be back within a few minutes.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Common WordPress errors (Advanced Administration Handbook)](https://developer.wordpress.org/advanced-administration/wordpress/common-errors/): the official catalogue of error messages and first-line fixes.
- [Debugging in WordPress](https://developer.wordpress.org/advanced-administration/debug/debug-wordpress/): the authoritative reference for `WP_DEBUG`, the debug log, and reading the actual error behind a blank page.
- [Recovery Mode](https://wordpress.org/documentation/article/recovery-mode/): how WordPress pauses a faulty plugin or theme and emails you a safe login link after a fatal error.
- [Editing wp-config.php](https://developer.wordpress.org/advanced-administration/wordpress/wp-config/): the full list of configuration constants used throughout this guide, including database, memory and repair settings.
- [Reset your password](https://wordpress.org/documentation/article/reset-your-password/): every method for regaining a login, from the email link to editing the database directly.
- [Customize permalinks](https://wordpress.org/documentation/article/customize-permalinks/): how WordPress builds post and page URLs, relevant to 404 errors.
## Prerequisites
- You know how to [log in to the WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/). Some fixes below need it; the rest deliberately work without it.
- A way to reach your site's files: an SFTP or FTP client, or the File Manager in your hosting control panel. Several fixes involve editing or renaming files such as `wp-config.php`, `.htaccess` and folders inside `wp-content`.
- A recent backup, or the ability to make one before you start. On Noiz managed plans a backup is taken for you and Noiz support can restore it; even so, copy any file to your own computer before you edit it.
## The Troubleshooting Toolkit
Almost every fix in this guide relies on one of five basic techniques. Learn these once here, and each error section stays short. Read this section first even if you are in a hurry, because these are the tools that turn a mysterious blank page into a solved problem.
### 1. Back up before you touch anything
Before editing a file or a database, make sure you can undo it. Download a copy of any file to your computer before you change it, so you can put the original back if the fix does not work. Do not start deleting or rewriting files on a live site with no way back.
### 2. Reach your files without the dashboard
When WordPress will not load, you fix it from the files instead. Connect with an SFTP or FTP client, or open the File Manager in your hosting control panel. The two locations you will use most are the site's root folder, which contains `wp-config.php` and `.htaccess`, and the `wp-content` folder, which contains `plugins` and `themes`.
### 3. Turn on the debug log to see the real error
A blank page or a generic "critical error" hides the actual problem. Turn on WordPress debugging to write the real message to a log file. Edit `wp-config.php` and, just above the line that reads `/* That's all, stop editing! Happy blogging. */`, add:
```
define( 'WP_DEBUG', true );
define( 'WP_DEBUG_LOG', true );
define( 'WP_DEBUG_DISPLAY', false );
```
Reload the site once, then open `wp-content/debug.log`. The last few lines usually name the exact file and line number causing the fault, which almost always points at a specific plugin or theme. Keeping `WP_DEBUG_DISPLAY` set to `false` means visitors never see the raw errors while you investigate. When you have finished, set all three values back to `false` so the log stops growing on a live site.
### 4. Deactivate every plugin without the dashboard
A faulty or conflicting plugin is the single most common cause of these errors, and you can switch them all off from the files. Using SFTP or File Manager, open `wp-content` and rename the `plugins` folder to something like `plugins-off`. WordPress can no longer find any plugin, so it deactivates them all. If your site returns, a plugin was the culprit: rename the folder back to `plugins`, then reactivate plugins one at a time from the dashboard until the error reappears, and the last one you switched on is the offender.
### 5. Rule out the active theme
If disabling plugins does not help, test the theme the same way. In `wp-content/themes`, rename the folder of your active theme. WordPress falls back to one of the default themes that ship with it (the Twenty-something series). If the site recovers, the problem is in your theme, often a broken change in its `functions.php` file.
## The White Screen of Death (Critical Error)
**What you see:** a plain white page with no content, or the message "There has been a critical error on this website." On the admin side you may see "There has been a critical error on this website. Please check your site admin email inbox for instructions."
**Likely cause:** a fatal PHP error, almost always from a plugin or theme that is incompatible, broken, or has just been updated, or from exhausted memory. The white page is simply WordPress failing to finish loading.
**How to fix it:**
Modern WordPress tries to rescue you automatically through Recovery Mode. When it detects a fatal error on a normal page load, it emails your site administrator address a special login link. Clicking that link logs you in with the faulty plugin or theme paused for your session only, so your dashboard loads and shows a notice naming the component at fault. Deactivate or fix that plugin or theme, then choose Exit Recovery Mode from the toolbar.
The recovery email does not always arrive. It is sent directly by the web server before your mail plugins load, so it can be filtered as spam or blocked entirely. If it does not turn up within a few minutes, or you cannot access the admin email, fix it manually instead:
1. Turn on the debug log (toolkit step 3) and reload the site to capture the exact error into `wp-content/debug.log`.
2. Read the last lines of the log. If they name a plugin, deactivate that plugin by renaming its folder inside `wp-content/plugins`. If they name your theme, rename the theme folder (toolkit steps 4 and 5).
3. If the log points at memory, raise the limit as described in the memory section below.
4. Reload the site. Once it returns, reactivate components one at a time to confirm which one broke and update or replace it.
## PHP Syntax Error After Editing a File
**What you see:** a message such as `Parse error: syntax error, unexpected '}' in /path/to/file.php on line 42`, or a white screen and critical error, immediately after you edited a theme or plugin file.
**Likely cause:** a small mistake in PHP code, a missing bracket, semicolon or quote, usually added through the built-in Appearance then Theme File Editor, or Plugins then Plugin File Editor. A single stray character can take the whole site down, and because the same fatal error blocks the editor, you often cannot undo the change from inside WordPress.
**How to fix it:**
1. Note the file and line number in the error message. That is exactly where the mistake is.
2. Open that file over SFTP or in File Manager and correct the change. If you are not sure what you altered, replace the file with the copy you backed up beforehand, or with a fresh copy of the same plugin or theme.
3. Save, upload, and reload the site.
To avoid this class of error, do not edit live code through the built-in file editors. Disabling them is a standard hardening step covered in the [WordPress Security Checklist](/wordpress/wordpress-security-checklist/). Make code changes in a staging copy or through a proper editor over SFTP, where a mistake is easy to reverse.
## Allowed Memory Size Exhausted (Memory Limit)
**What you see:** a white screen, a 500 error, or a message like `Fatal error: Allowed memory size of 268435456 bytes exhausted` in the page or the debug log.
**Likely cause:** a page or task needed more memory than WordPress was allowed to use. Heavy plugins, large imports, image processing, or page builders can push a site past its limit.
**How to fix it:**
Raise the memory WordPress may request. Edit `wp-config.php` and add this line above the "stop editing" line:
```
define( 'WP_MEMORY_LIMIT', '256M' );
```
For memory-hungry admin tasks such as bulk imports you can also add `define( 'WP_MAX_MEMORY_LIMIT', '512M' );`, which applies only inside the dashboard.
There is an important limit to understand: WordPress can never use more memory than the server's own PHP `memory_limit` allows. If the server cap is lower than the value you set here, raising the WordPress constant alone changes nothing. On Noiz hosting the PHP memory limit is generous by default, and if a genuine task needs more, Noiz support can lift the server-side limit for you. Before requesting more memory, check whether a single badly behaved plugin is the real cause, because unlimited memory only hides a leak rather than fixing it.
## 500 Internal Server Error
**What you see:** a browser or server page reading "500 Internal Server Error", often on every page including `/wp-admin`.
**Likely cause:** a deliberately vague server-side error. In WordPress it is usually a corrupted `.htaccess` file, exhausted memory, a plugin or theme conflict, a damaged core file, or an incompatible PHP version.
**How to fix it, in order:**
1. Turn on the debug log (toolkit step 3) and reload. The real error is often written there even when the browser shows only "500".
2. Rule out `.htaccess`. In the site's root folder, rename `.htaccess` to `htaccess-old`, then reload. If the site returns, the file was corrupt: log in and go to **Settings** then **Permalinks** and click **Save Changes**, which writes a fresh, correct `.htaccess`.
3. Deactivate all plugins, then the theme, using toolkit steps 4 and 5.
4. Raise the memory limit as shown above, in case the 500 is really memory exhaustion.
5. Check the PHP version. WordPress 7.0 requires at least PHP 7.4 and works best on PHP 8.3 or newer; a very old or mismatched PHP version can throw 500 errors. Your hosting control panel shows and changes the PHP version for the site.
A 500 error is the one case where the server's own error log is the fastest route to the cause, because it records the underlying reason the public page hides. On Noiz managed plans, Noiz support can read that server log and tell you exactly which file or limit is responsible.
## Error Establishing a Database Connection
**What you see:** a page that simply says "Error establishing a database connection" and nothing else.
**Likely cause:** WordPress cannot reach or log in to its database. The usual reasons are wrong database details in `wp-config.php` (very common straight after a site move or host change), a database server that is down or overloaded, or a corrupted database.
**How to fix it:**
1. Check the database details first. Open `wp-config.php` and confirm these four values match the database exactly: `define( 'DB_NAME', 'your_database_name' ); define( 'DB_USER', 'your_database_user' ); define( 'DB_PASSWORD', 'your_database_password' ); define( 'DB_HOST', 'localhost' );` The database name, user and password come from your hosting account, not from anything you choose freely. `DB_HOST` is `localhost` on most setups, but some hosts use a specific hostname, so use the value shown in your Noiz hosting details rather than assuming. A single wrong character here produces this exact error.
2. If the details are correct, the database server itself may be down or overloaded, for example during a traffic spike. Wait a few minutes and try again.
3. If the message hints that the database is corrupt, use the built-in repair tool. Add this line to `wp-config.php`: `define( 'WP_ALLOW_REPAIR', true );` Then visit `https://yourdomain.com/wp-admin/maint/repair.php` (replace `yourdomain.com` with your own domain) and click **Repair Database**. When it finishes, **remove that line again**. The repair page works without a login on purpose, so leaving it enabled is a security hole.
If the credentials are correct and the repair tool does not help, the problem is on the database server itself. On Noiz hosting, open a ticket and Noiz support can check whether the database service is healthy and whether your account has hit a database size limit.
## Posts and Pages Return 404 Not Found
**What you see:** the homepage works, but clicking into individual posts or pages gives a "404 Not Found" error, even though the content clearly exists.
**Likely cause:** the permalink rewrite rules that map friendly URLs to your content have been lost or corrupted, commonly after a site move, a change of permalink settings, or a damaged `.htaccess` file.
**How to fix it:**
1. Log in and go to **Settings** then **Permalinks**. Do not change anything; just click **Save Changes**. This alone regenerates the rewrite rules and, on Apache servers, rewrites the `.htaccess` file. It resolves the great majority of permalink 404s.
2. If that does not work, on the same screen select **Plain**, click **Save Changes**, then switch back to your preferred structure such as **Post name** and click **Save Changes** again to force a clean rebuild.
3. If the URLs still fail and your server uses `.htaccess`, the file may be missing or unwritable. Confirm the root folder contains an `.htaccess` file with the standard WordPress block: `# BEGIN WordPress RewriteEngine On RewriteBase / RewriteRule ^index\.php$ - [L] RewriteCond %{REQUEST_FILENAME} !-f RewriteCond %{REQUEST_FILENAME} !-d RewriteRule . /index.php [L] # END WordPress`

WordPress relies on the web server being set up to allow pretty permalinks. On Noiz hosting that is already configured, so re-saving permalinks is normally all you need. If only one specific page returns a 404 while the rest work, the cause is usually a clash between that page's slug and another item, or a stale cache, rather than the rewrite rules.
## Locked Out of the Admin Dashboard
**What you see:** you cannot log in at `/wp-admin`. This covers a forgotten password, a login page that reloads without letting you in, a "too many failed attempts" lockout, or a redirect loop.
**Likely cause:** a forgotten or changed password, a broken site email so the reset link never arrives, a plugin or theme conflict blocking the login page, or a security lockout after repeated failed attempts.
**How to fix it, by situation:**
- **Forgotten password, email working:** use the **Lost your password?** link on the login page. WordPress emails you a reset link, the simplest fix by far.
- **Reset email never arrives:** the site's outgoing mail is likely not configured, so use another method from the official [Reset your password](https://wordpress.org/documentation/article/reset-your-password/) guide. If you have database access, you can set a new password directly in the `wp_users` table through phpMyAdmin. On Noiz managed plans, support can reset the password on the database for you.
- **A fatal error blocks login:** if the login page shows a critical error rather than a password prompt, treat it as a white screen: check the recovery email and, if needed, deactivate plugins and the theme from the files (toolkit steps 4 and 5).
- **Locked out by failed attempts:** a security plugin may block your address after several wrong passwords. Wait for the lockout window to pass, or clear the lockout by temporarily deactivating that security plugin from the files.
- **Login page keeps redirecting:** a redirect loop often comes from an incorrect site address setting or a corrupted `.htaccess`. Rename `.htaccess` to test it, and confirm the site address is right before making further changes.
## Stuck in Maintenance Mode
**What you see:** every page shows "Briefly unavailable for scheduled maintenance. Check back in a minute." and never recovers.
**Likely cause:** an update was interrupted. When WordPress updates itself, a plugin, or a theme, it creates a hidden file named `.maintenance` in the site's root folder and deletes it the moment the update finishes. If the update stalls, times out, or you navigate away, the file is left behind and the site stays locked in maintenance mode.
**How to fix it:**
1. Connect over SFTP or open File Manager and go to the site's root folder, the same folder that contains `wp-config.php`.
2. Find the file named `.maintenance`. It may be hidden, so enable "show hidden files" in your client or File Manager if you do not see it.
3. Delete `.maintenance`. This is safe and immediately releases the site from maintenance mode.
4. Reload the site. If your browser still shows the maintenance page, clear its cache and reload.
Because the interruption may have left an update half-finished, log in afterwards and check **Dashboard** then **Updates**, and re-run any update that did not complete. To avoid a repeat, update plugins and themes in small batches rather than all at once, so a single slow update is less likely to time out. If the `.maintenance` file reappears on its own after you delete it, an update process is still running or a plugin is recreating it, and that plugin is the next thing to investigate.
## When to Contact Noiz Support
Work through the relevant section above and you can resolve most WordPress errors yourself. Some faults, though, sit on the server rather than in your site, for example a database server problem, a hard PHP limit, or an error only the server log reveals. On Noiz managed hosting, support can read the server error logs, restore a recent backup, adjust PHP settings, reset a locked account through the database, and reach your files for you.
If you get stuck, open a support ticket with the Noiz support team and include your domain name, the exact error text you see (a screenshot is ideal), and, crucially, what changed just before the error appeared: a plugin or theme update, a core update, a file edit, or a site move. That last detail is usually what points straight at the cause.
# How to Fix the \"Missing a Temporary Folder\" Error in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-fix-the-missing-a-temporary-folder-error-in-wordpress/
This guide shows you how to fix the WordPress upload error that reads **"Missing a temporary folder."** You usually meet it at the worst moment: you try to add an image to the Media Library, install a plugin or theme, or import content, and instead of the file appearing you get that short, unhelpful message. The same fault is sometimes described as "WordPress missing a temporary folder" or "temporary folder is missing", and they all point at the same thing. This article explains what the error actually means, why it turns up on otherwise healthy sites, and the two reliable ways to clear it: defining a temporary folder inside WordPress, and giving PHP a valid temporary directory through your Noiz hosting panel. It is written for Noiz clients who run their own WordPress site.
The reassuring part is that this is not a sign of a hacked, corrupt, or broken WordPress. It is almost always a small server-side configuration detail, most often a leftover setting from a site move, and once you understand where PHP looks for its scratch space the fix is quick. The official documentation tells you which constant to set; what it does not spell out is why the popular one-line fix sometimes fails to help, and that gap is exactly what this guide fills.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress and PHP documentation linked below.
### Official Documentation Reference
- [get\_temp\_dir() (WordPress Developer Resources)](https://developer.wordpress.org/reference/functions/get_temp_dir/): the core function that decides which temporary directory WordPress uses, and the order in which it looks.
- [Editing wp-config.php (Advanced Administration Handbook)](https://developer.wordpress.org/advanced-administration/wordpress/wp-config/): the reference for configuration constants, including `WP_TEMP_DIR`.
- [File upload errors (PHP Manual)](https://www.php.net/manual/en/features.file-upload.errors.php): the definitive list of PHP upload error codes, including `UPLOAD_ERR_NO_TMP_DIR`, the code behind this message.
- [The upload\_tmp\_dir directive (PHP Manual)](https://www.php.net/manual/en/ini.core.php#ini.upload-tmp-dir): what this PHP setting controls and how PHP behaves when it is missing or unwritable.
- [Common WordPress errors (Advanced Administration Handbook)](https://developer.wordpress.org/advanced-administration/wordpress/common-errors/): the official catalogue of WordPress error messages for wider context.
## Prerequisites
- A way to reach your site's files: an SFTP client, or the File Manager in your Noiz hosting panel. The first fix edits `wp-config.php` and creates a folder, both of which live in your WordPress installation.
- The ability to [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an administrator, so you can reproduce the error and confirm the fix by uploading a test file afterwards.
- Access to your site's PHP settings in the hosting panel, or, on a managed plan, the option to ask the Noiz support team to change them for you. The second fix needs this.
- A copy of `wp-config.php` saved to your own computer before you edit it, so you can put the original back if needed.
## What the Error Actually Means
Understanding the message makes every fix below obvious. When you upload a file to WordPress, the file does not go straight to its final home in `wp-content/uploads`. First PHP, the language WordPress is built on, receives the incoming file and writes it to a short-lived scratch location called a **temporary directory**. Only once the whole file has arrived safely does WordPress move it into place. That temporary directory is the "temporary folder" in the error.
If PHP has nowhere it is allowed to write that scratch file, it abandons the upload and flags it with a specific code, `UPLOAD_ERR_NO_TMP_DIR`, known to PHP as error number 6. WordPress reads that code and prints the matching sentence from its own list of upload messages, which for code 6 is exactly **"Missing a temporary folder."** So the message is not WordPress complaining about itself; it is WordPress faithfully reporting that PHP could not find a usable scratch folder underneath it.
That distinction matters, because it tells you where the fix lives: in the server's PHP configuration, or in a WordPress constant that steps in to supply the folder. It is not something you repair by reinstalling WordPress or deleting plugins.
### Do Not Confuse It With Its Neighbours
WordPress has a short family of upload errors that look similar but have different causes. Reading the exact wording saves you chasing the wrong fix:
- **"Missing a temporary folder."** is the one this guide covers: no writable temporary directory.
- **"The uploaded file exceeds the upload\_max\_filesize directive..."** means the file is simply too large for the current PHP limit, an entirely separate setting.
- **"Failed to write file to disk."** usually means the temporary folder exists but the final destination, `wp-content/uploads`, is not writable or the disk is full.
If your message is one of the last two, this guide is not the right one. Only the first wording points at the missing temporary folder.
## Why It Happens on a Healthy Site
Here is the detail most quick guides skip. Modern PHP, which every WordPress 7.0 site on Noiz runs, is forgiving about this: if no temporary directory is explicitly configured, PHP quietly falls back to the operating system's own default temporary location. Because of that fallback, a correctly configured site almost never sees this error. So when it does appear, it is worth understanding which of a small number of specific situations you are in, because that decides the cleanest fix:
- **A leftover setting from a site move.** This is by far the most common cause. When a site is migrated between servers, an old `php.ini` or a saved panel setting can carry an explicit `upload_tmp_dir` value pointing at a folder that existed on the old server but does not exist on the new one. PHP obeys the setting, looks for a folder that is not there, and fails. The fix is to correct or remove that stale value.
- **A path restriction blocking the system default.** Some hardened setups confine PHP to a set of allowed directories. If the operating system's default temporary location sits outside that allowed set, PHP cannot use its normal fallback and reports the missing folder instead.
- **A full or over-quota disk.** A temporary directory that has run out of space behaves, for the purpose of writing a new file, as if it were not writable at all.
- **Wrong permissions on a custom temporary folder.** If someone has pointed PHP at a specific folder but that folder cannot be written to by the user PHP runs as, the same error follows.
You do not need to diagnose which one applies before you start. The two fixes below resolve all of these situations, and the troubleshooting section at the end helps if the first attempt does not stick.
## Fix 1: Define a Temporary Folder in wp-config.php
This is the fix you can apply entirely by yourself, without touching any server settings, and it is the sensible first move. WordPress lets you name your own temporary directory with a constant called `WP_TEMP_DIR`. When this is set, WordPress's internal `get_temp_dir()` function returns it before considering anything the server offers, so you are supplying a folder you know exists and control.
### Step 1: Create the Folder
Using SFTP or the panel File Manager, open your site's `wp-content` folder and create a new folder inside it named `temp`. The full path will be `wp-content/temp`. Keeping it inside your own installation guarantees PHP is allowed to reach it, which sidesteps the path-restriction cause described above.
### Step 2: Add the Constant to wp-config.php
Open `wp-config.php` in your site's root folder, the same folder that holds `wp-admin` and `wp-content`. Just above the line that reads `/* That's all, stop editing! Happy blogging. */`, add:
```
define( 'WP_TEMP_DIR', dirname( __FILE__ ) . '/wp-content/temp/' );
```
The `dirname( __FILE__ )` part resolves automatically to wherever your WordPress lives, so this line points at the `temp` folder you just made without you having to know the full server path. Save the file and, if you edited a local copy, upload it back. Placing the line above the "stop editing" comment matters: constants added below it are ignored.
### Step 3: Check the Folder Can Be Written To
The new folder needs to be writable by the account your site runs under. On Noiz hosting, a folder you create through SFTP or File Manager is normally already owned correctly, so this usually needs no action. If you want to be sure, set the folder's permissions to `755`. Avoid `777`: it is not needed here and it weakens security for no benefit.
### An Honest Note on What This Fix Reaches
This is the point the popular one-line guides gloss over, and it is worth being straight about. Defining `WP_TEMP_DIR` reliably fixes the error for the many operations that run *through WordPress*: installing and updating plugins and themes, importing content, and the many plugins (for example backup, import, and media tools) that use WordPress's own temporary-file handling.
However, when you drag an image straight into the Media Library, PHP receives that upload and looks for its temporary folder *before any WordPress code runs at all*, so in that specific case PHP's own setting, not the WordPress constant, decides success or failure. If the error only appears on direct Media Library uploads and Fix 1 has not cleared it, that is expected, and Fix 2 is the one that will. Applying both is the belt-and-braces approach, and doing Fix 1 first costs nothing.
## Fix 2: Give PHP a Valid Temporary Directory in Your Panel
This is the definitive fix, because it corrects the setting PHP itself reads. There are two ways to go about it, and the right one depends on the cause. If a stale value is pointing PHP at a folder that no longer exists, the cleanest fix is simply to remove that value so PHP returns to using the reliable system default. If instead PHP is being blocked from the system default, you point it at a folder inside your own account. Either way, the change is made in your Noiz hosting panel's PHP settings, and the exact place depends on which panel your site is on.
Where you do point PHP at your own folder, use a directory inside your hosting account that you know is writable, such as the same `wp-content/temp` folder from Fix 1, and give its full server path. The directive you are setting is:
```
upload_tmp_dir = "/full/path/to/your/wp-content/temp"
```
Replace the path with the real absolute path to a writable folder in your account; your File Manager shows this path when you open the folder.
### On Plesk (neo.noiz.co.za)
For sites on the South African platform, open **Websites & Domains**, select your domain, and click **PHP Settings**. Scroll to the **Additional configuration directives** box at the bottom of the page. This box accepts raw PHP directives, so add your `upload_tmp_dir` line there, then click **OK** or **Apply**. If the cause is a stale directive that was set here previously, remove that line instead of adding one. Plesk also provides a per-subscription temporary area for each site, and Noiz support can confirm the correct path to use if you are unsure.

### On ISPConfig
For sites on the ISPConfig platform, open the site under **Sites**, then switch to the **Options** tab. In the **Custom php.ini settings** box, add your `upload_tmp_dir` line, then save the site so the change is written out and the PHP handler reloads. As with Plesk, if a leftover value is already present in that box and points at a folder that no longer exists, the fix is to delete that line rather than add another.
### On DirectAdmin
For sites on the Ireland platform, the equivalent lives in the domain's PHP configuration, where DirectAdmin lets you supply custom PHP directives for the selected PHP version. Add or correct the `upload_tmp_dir` value there and save so the setting is applied. If the exact location is not obvious in your account, the Noiz support team can point you to it or make the change for you.
### The Managed-Plan Shortcut
If your site is on a managed Noiz plan, you do not have to work through the panel at all. Open a ticket, quote the exact error, and ask the Noiz support team to set a valid PHP temporary directory or clear a stale one for your site. Support can also see at a glance whether a path restriction or a full disk is the underlying cause, which is harder to spot from inside your own account.
## Fix 3: Rule Out Permissions and Disk Space
If both fixes above are in place and the error persists, two server-level conditions are worth eliminating, and they are the usual reason a correctly configured folder still fails:
- **Permissions.** The temporary folder must be writable by the user your site's PHP runs as. If you created the folder yourself over SFTP this is normally fine; if it was created by a different process it may not be. Confirm the folder is set to `755` and owned by your hosting account.
- **Disk space and quota.** A temporary folder on a partition with no free space cannot accept a new file, which produces exactly this error even though the folder plainly exists. Check your disk usage in the hosting panel. If your account is at or near its limit, clearing space, or asking Noiz support to review your quota, resolves it.
These two are also the most common reason the error appears suddenly on a site that worked yesterday with no configuration change: the disk quietly filled up, or a routine tidied a folder and reset its permissions.
## Verify the Fix
Do not assume the change worked; prove it. Once you have applied a fix, go back into your WordPress dashboard and repeat the exact action that failed. If it was a Media Library upload, upload a small test image. If it was a plugin install or a content import, run that again. A clean upload, with the file appearing where it should, is your confirmation.
If you edited `wp-config.php` and want to leave the site tidy, there is nothing to undo: the `WP_TEMP_DIR` line is a permanent, harmless improvement and is fine to leave in place. This is unlike temporary debugging settings, which you would remove afterwards.
## Troubleshooting
- **Symptom**: the error only happens on direct Media Library uploads, not on plugin installs. This is the expected split explained above. PHP handles the raw upload before WordPress does, so the `WP_TEMP_DIR` constant alone will not cure it. Apply Fix 2 so PHP itself has a valid temporary directory.
- **Symptom**: the error started immediately after moving the site to a new host. A stale `upload_tmp_dir` from the old server is almost certainly the cause. In your panel's PHP settings, look for an existing `upload_tmp_dir` line pointing at a path that does not exist on the new server, and remove it so PHP falls back to the working default.
- **Symptom**: you added the `WP_TEMP_DIR` line but nothing changed and the site looks the same. Check that the line sits *above* the "stop editing" comment in `wp-config.php`, that the `wp-content/temp` folder actually exists, and that you uploaded the edited file back to the server rather than only saving your local copy.
- **Symptom**: uploads fail with a different message, such as one mentioning `upload_max_filesize` or "Failed to write file to disk." That is a different error with a different cause, covered by file-size limits or destination-folder permissions rather than the temporary folder. Match the exact wording to the right fix.
- **Symptom**: everything looks correct but the error keeps returning. The temporary partition may be full or your account may be over quota, so a folder that exists still cannot accept a file. Check disk usage, or ask Noiz support to review it for you.
## When to Contact Noiz Support
Most people clear this error with Fix 1 and Fix 2 in a few minutes. Some causes, though, sit at a level you cannot see from inside your own account: a path restriction on the PHP handler, a disk that has filled up, or a leftover configuration set during a migration. On managed Noiz hosting, support can inspect the PHP configuration directly, set or clear the temporary directory for you, check your disk and quota, and confirm the folder is writable by the right account.
If you get stuck, open a support ticket with the Noiz support team and include your domain, the exact error text (a screenshot is ideal), which action triggers it (a Media Library upload, a plugin install, or an import), and whether anything changed recently such as a site move or a spike in disk usage. That last detail usually points straight at the cause.
# How to Fix the \"Sorry, This File Type Is Not Permitted for Security Reasons\" Error
Source: https://docs.noiz.ie/wordpress/how-to-fix-the-sorry-this-file-type-is-not-permitted-for-security-reasons-error/
You try to add a file to your WordPress site, the upload runs for a moment, and then it stops with a red message: **"Sorry, this file type is not permitted for security reasons."** This guide explains why WordPress refuses the file, and walks you through the fixes in order from the safest to the one you should almost never use. You will learn how to tell whether the file itself is the problem, how to allow one specific file type in a controlled way, and why the "just allow everything" switch is a genuine security risk rather than a convenience. It is written for Noiz clients who manage their own WordPress site, and it fills in the parts the official documentation leaves unsaid: how WordPress really decides what is "permitted", the surprising reason a perfectly ordinary file sometimes gets rejected, and where on Noiz hosting to safely make a change without breaking anything.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [get\_allowed\_mime\_types() (WordPress Developer Resources)](https://developer.wordpress.org/reference/functions/get_allowed_mime_types/): the function that decides which file types your site accepts, and the capability rules that trim the list per user.
- [wp\_get\_mime\_types() (WordPress Developer Resources)](https://developer.wordpress.org/reference/functions/wp_get_mime_types/): the full default map of extensions to MIME types that WordPress ships with.
- [upload\_mimes filter (WordPress Developer Resources)](https://developer.wordpress.org/reference/hooks/upload_mimes/): the supported hook for adding or removing an allowed file type.
- [wp\_check\_filetype\_and\_ext() (WordPress Developer Resources)](https://developer.wordpress.org/reference/functions/wp_check_filetype_and_ext/): the second check that inspects a file's real contents, and the reason some valid files are still rejected.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an administrator. The list of file types allowed depends on your role, and only an administrator can change it.
- For the code-based fix, a way to reach your site's files: an SFTP client, or the File Manager in your Noiz hosting panel. Editing the wrong file, or editing without a backup, can take a site offline, so work on a copy where you can.
- A recent, restorable backup before you edit any theme file or `wp-config.php`.
## Why WordPress Blocks the File
WordPress does not accept just any file into your media library. It keeps a deliberate allow-list of file types, and anything not on that list is turned away with the "not permitted for security reasons" message. Understanding the reason for that list is the difference between a safe fix and one that opens a hole in your site.
The list exists because your media folder is web-accessible. If WordPress let anyone upload, say, a `.php` file, an attacker who found a way to reach the upload form could drop an executable script onto your server and then run it simply by visiting its URL. That single weakness is behind a large share of real WordPress compromises. The allow-list is the wall that stops it, which is why the message frames the block as a *security* decision and not a limitation to be casually switched off.
### The two checks every upload has to pass
What most guides gloss over is that WordPress runs **two separate checks**, and either one can produce this error. Knowing which one stopped you tells you which fix you actually need.
- **Check one, the allow-list.** WordPress compares the file's extension against the types returned by `get_allowed_mime_types()`. That set starts from a large built-in map of common formats and is then trimmed to suit the current user. If the extension is not on the list, the upload is refused before the file is even examined. This is the usual cause when you are uploading something genuinely uncommon, an SVG icon, a font file, a `.json` export, a `.webp` on a very old install.
- **Check two, the real contents.** Even for an allowed extension, WordPress then calls `wp_check_filetype_and_ext()`, which uses the server's file-inspection library to read the file's actual bytes and confirm they match what the extension claims. If the detected type disagrees with the extension, the file is rejected with the same message, even though the extension itself is perfectly acceptable.
### The gotcha: a valid file rejected anyway
That second check is the source of the most confusing version of this problem, where a file you know is fine, a normal Word document or a re-exported photo, is refused as "not permitted". It happens because the content-inspection library and WordPress do not always agree on what a file is:
- A modern Office document (`.docx`, `.xlsx`, `.pptx`) is internally a compressed archive, so the inspector often reports it as a generic `application/zip`. WordPress expects the specific Office MIME type, sees a mismatch, and blocks it.
- An image re-saved or exported by some editors can carry a slightly different internal signature from what its `.jpg` or `.png` extension implies.
- A file that was renamed rather than properly converted, an `.mp4` that is really a `.mov`, for instance, will be caught precisely because the check is doing its job.
The practical takeaway: if the file is one WordPress should normally accept, the answer is almost never to loosen your site's security. It is to fix the file, which is the first method below.
## Method 1: Convert or Re-save the File (Safest, No Code)
Before changing any site setting, deal with the file. This is the right first move for two of the situations above: a file in an everyday format that was wrongly rejected, and a file whose format you do not truly need to keep.
### Use a format WordPress already accepts
WordPress ships accepting a wide range of formats out of the box, so you may not need the exact one you have. Common images (`.jpg`, `.png`, `.gif`, `.webp`, `.avif`, `.ico`), documents (`.pdf`, `.doc`, `.docx`, `.xls`, `.xlsx`, `.ppt`, `.pptx`, and the OpenDocument equivalents), audio (`.mp3`, `.m4a`, `.wav`, `.ogg`, `.flac`) and video (`.mp4`, `.mov`, `.avi`, `.webm`) are all allowed as standard. If you are trying to upload a niche format, ask whether an accepted one would do the job: export a design as `.png` or `.pdf` rather than the source file, or a diagram as `.svg`'s safer cousin `.png`.
### Re-save a file that "should" work
When the format is one WordPress supports but the upload still fails, the content check has flagged a mismatch. Open the file in a proper application for its type and use **Save As** or **Export** to write a clean copy, rather than just renaming the extension. Re-saving a document from its Office application, or re-exporting an image from an image editor, rebuilds the file so its real contents and its extension line up, and the upload then passes. This solves the "valid file rejected" gotcha without touching your site at all.
## Method 2: Allow One File Type With a Filter (Controlled)
If you genuinely need a format WordPress does not accept, and you have decided it is safe to allow, add **only that one type** using the supported `upload_mimes` filter. This is the clean, surgical option: it widens the allow-list by exactly one entry and leaves every other protection in place.
### Where to put the code on Noiz hosting
Do not paste this into the parent theme's `functions.php`, because a theme update will wipe it out. The two durable homes for a snippet like this are a **child theme's** `functions.php`, or a small **must-use plugin**, a single `.php` file placed in `wp-content/mu-plugins/` that WordPress loads automatically and that no update or theme switch can disturb. The must-use plugin is the tidier choice because it keeps this behaviour independent of whichever theme you are running.
Reach either location through **SFTP** or your Noiz hosting panel's **File Manager**, both of which get you into `wp-content/`. If you are on a managed plan and would rather not edit files yourself, the Noiz support team can add a snippet like this for you; tell them exactly which file type you need to allow and why.
### The snippet
The filter receives the current allow-list as an array keyed by extension, and you add your entry. This example allows SVG images; change the extension and MIME type to suit the format you actually need.
```
add_filter( 'upload_mimes', function ( $mimes ) {
// Add ONE type you have decided is safe. Example: SVG.
$mimes['svg'] = 'image/svg+xml';
return $mimes;
} );
```
### When the filter alone is not enough
Here is the detail that sends people in circles: for some formats, adding the extension to `upload_mimes` still leaves you with the same error, because the content check from earlier disagrees about the file's real type. SVG is the classic example, since the inspection library may report an SVG as plain text or generic XML rather than `image/svg+xml`. When that happens you also have to reassure the content check, by hooking `wp_check_filetype_and_ext()` for that one extension:
```
add_filter( 'wp_check_filetype_and_ext', function ( $data, $file, $filename, $mimes ) {
if ( ! empty( $data['ext'] ) && ! empty( $data['type'] ) ) {
return $data; // Already resolved, leave it alone.
}
$check = wp_check_filetype( $filename, $mimes );
if ( 'svg' === $check['ext'] ) {
$data['ext'] = 'svg';
$data['type'] = 'image/svg+xml';
}
return $data;
}, 10, 4 );
```
Do this only for a specific extension you trust, as shown, never as a blanket "accept whatever the inspector says" rule, which would defeat the whole point of the second check.
## Method 3: Use a File-type Management Plugin
If you are not comfortable editing PHP, a dedicated file-type or MIME-management plugin gives you the same result through a settings screen: you pick the extensions to allow from a list, and the plugin registers them with the `upload_mimes` filter for you. Several reputable plugins in the WordPress plugin directory do exactly this, and any of them is a reasonable choice; the point here is the approach, not a particular product.
Two cautions apply whichever plugin you choose. First, prefer one that lets you enable **specific** types rather than throwing the doors open, so you are still making a deliberate decision about each format. Second, a plugin that is installed only to flip one switch is a permanent piece of code, and therefore a permanent thing to keep updated. For a single extra type, the one-off `upload_mimes` snippet in Method 2 is often the lighter-weight answer, because it adds no ongoing maintenance.
## The ALLOW\_UNFILTERED\_UPLOADS Route, and Why to Avoid It
You will find advice online to add one line to `wp-config.php` that makes the error disappear entirely:
```
define( 'ALLOW_UNFILTERED_UPLOADS', true );
```
It works, and that is exactly the problem. This constant does not add one format; it **switches off the file-type check altogether** for the highest-level users, meaning administrators on a single site, and only network super admins on a WordPress multisite network. From then on those accounts can upload *anything*, including executable `.php` scripts, which is precisely the attack the allow-list exists to prevent.
The danger is not hypothetical. If any administrator account is ever compromised through a weak password or a phished login, this setting turns that break-in into full remote code execution on your server. It also bypasses the content-mismatch check, so the safety net that catches disguised files is gone too. For these reasons:
- WordPress deliberately hides this behind a config-file edit and never exposes it in the dashboard.
- Security scanners commonly flag its presence as a vulnerability, and some managed environments disallow it.
- There is almost no situation where it is the correct fix. If you think you need it, you actually need Method 2 for the one or two formats in question.
If you have already added this line, remove it now, and make sure it is not left enabled after any one-off task. Then work through the [WordPress Security Checklist](/wordpress/wordpress-security-checklist/) to confirm nothing was uploaded while it was active.
## A Word on SVG and Other Risky Formats
Some formats are blocked by default not because they are exotic but because they can carry code. An **SVG** is a plain-text image built from XML, and that XML can contain embedded JavaScript, which means a malicious SVG uploaded to your site can become a stored cross-site-scripting attack against anyone who views it. HTML files (`.html`) and JavaScript files (`.js`) are restricted for the same reason and are only offered to users trusted with unfiltered content. So if you do allow SVGs by the methods above, treat every SVG as untrusted: sanitise uploaded SVGs (a good SVG-support plugin does this automatically), and do not allow uploads from users you do not fully trust. Allowing a risky format is a decision to accept and manage that risk, not a step to take lightly.
## Troubleshooting
- **Symptom**: an everyday file such as a `.docx` or a photo is rejected as not permitted. This is the content-mismatch check, not the allow-list. Re-save or re-export the file from its proper application (Method 1) rather than renaming it, and the fresh copy will upload.
- **Symptom**: you added the type to `upload_mimes` but still get the error. The second check is disagreeing about the file's real type. Add the matching `wp_check_filetype_and_ext()` filter for that one extension, as shown in Method 2.
- **Symptom**: your snippet works but vanishes after a while. It was added to the parent theme's `functions.php` and lost to a theme update. Move it to a child theme or, better, a must-use plugin in `wp-content/mu-plugins/`.
- **Symptom**: the message mentions a maximum size rather than a file type, for example "exceeds the maximum upload size". That is a different problem entirely, a server upload limit, and none of the fixes here apply; it is solved by raising the PHP upload limits, which the Noiz support team can adjust for you.
- **Symptom**: you run a WordPress **multisite** network and an allowed type is still refused. Multisite keeps its own network-wide list of permitted extensions under **Network Admin > Settings > Upload Settings**. Add the extension there as well as in any filter.
- **Symptom**: the upload fails but you never see the WordPress error at all, or you get a plain server error page. That points to a server-level block rather than WordPress. If you are hosted with Noiz, open a ticket so support can check whether a security rule on the server is intercepting the upload.
If you are unsure whether a particular file type is safe to allow, or you would like the Noiz support team to add a controlled `upload_mimes` snippet for you, open a support ticket and include your domain, the exact file type you need, and what you use it for. On managed plans the team can make the change and confirm it is done in the safest way for your site.
# How to Force Reinstall or Update a WordPress Plugin Without Losing Data
Source: https://docs.noiz.ie/wordpress/how-to-force-reinstall-or-update-a-wordpress-plugin-without-losing-data/
A plugin has started misbehaving, an update stopped halfway, or a file inside the plugin folder has been edited or corrupted. In cases like these you want a **force reinstall**: replace the plugin's files with a clean copy from the source, while leaving the plugin's settings and content in place.
This guide shows you four ways to do that on your Noiz-hosted WordPress site, ordered from safest to riskiest. It covers both active and inactive plugins.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Manage Plugins](https://wordpress.org/documentation/article/manage-plugins/) (WordPress.org documentation)
- [Plugin File Editor Screen](https://developer.wordpress.org/advanced-administration/plugins/editor-screen/) (Advanced Administration Handbook)
- [Editing Files](https://developer.wordpress.org/advanced-administration/wordpress/edit-files/) (Advanced Administration Handbook)
- [wp plugin install](https://developer.wordpress.org/cli/commands/plugin/install/) and [wp plugin update](https://developer.wordpress.org/cli/commands/plugin/update/) (WP-CLI command reference)
## Prerequisites
- Administrator access to the WordPress dashboard.
- A current backup of the site files and database. Take one before you start, whichever method you choose.
- The plugin's slug (the folder name, for example `hello-dolly`) if you plan to use WP-CLI.
- SSH access to your hosting account, for the WP-CLI method only.
## What a Force Reinstall Does and Does Not Do
Understanding this saves a lot of wasted effort.
- **Plugin files** live in `wp-content/plugins/plugin-slug/`. A reinstall replaces these.
- **Plugin data** (settings, licence keys, form entries, product catalogues, order history) lives in the database, in the `wp_options` table or in the plugin's own tables. A reinstall does not touch any of it.
- **Activation state** is also stored in the database. Overwriting the files does not deactivate an active plugin.
So a force reinstall fixes corrupted, missing or hand-edited plugin files. It will not fix a problem caused by bad data in the database, a conflict with another plugin, a theme conflict, or a PHP version mismatch. If a clean set of files does not resolve the fault, the cause lies elsewhere.
A force reinstall also wipes any customisations you made directly to the plugin's files, which is usually the point, but is worth noting if someone before you patched the plugin by hand.
## Method 1: WP-CLI (Recommended)
This is the cleanest and safest option. It downloads a fresh copy and overwrites the plugin folder in one step, with no editing of live files and no risk of the plugin's uninstall routine firing.
Connect over SSH and change into the directory containing `wp-config.php`, then confirm which version is installed:
```
wp plugin get hello-dolly --field=version
```
Reinstall the same version cleanly:
```
wp plugin install hello-dolly --force
```
The `--force` flag tells WP-CLI to overwrite the installed copy without prompting. Replace `hello-dolly` with your plugin's slug.
To reinstall a specific older version instead, name it:
```
wp plugin install hello-dolly --version=1.7.1 --force
```
Or move an installed plugin to a chosen version:
```
wp plugin update hello-dolly --version=1.7.1
```
An active plugin stays active throughout, because activation is recorded in the database rather than in the files.
**Gotcha:** these commands pull from the WordPress.org plugin repository. A premium or privately distributed plugin is not there, so WP-CLI cannot fetch it by slug. For those, install from the vendor's ZIP file instead:
```
wp plugin install /home/youruser/premium-plugin.zip --force
```
## Method 2: A Rollback Plugin (No Command Line)
If you do not have shell access, or you specifically want to step a plugin back to an earlier version from the dashboard, install a rollback utility such as [WP Rollback](https://wordpress.org/plugins/wp-rollback/) from the WordPress.org repository. It adds a **Rollback** link beside each plugin on the **Plugins** screen and lets you pick any version the repository still hosts.
Reinstalling the current version through a rollback tool also works as a repair: it replaces the files with a clean copy.
**Gotcha:** rollback tools read from the WordPress.org repository, so they only list versions for plugins hosted there. Remove the rollback utility once you are finished, since it is a maintenance tool rather than something a production site needs running permanently.
## Method 3: Deactivate, Delete and Reinstall
The obvious route, and it works, but read the warning first.
1. Go to **Plugins** and click **Deactivate** on the plugin.
2. Click **Delete**, then confirm.
3. Go to **Plugins** and then **Add Plugin**, search for the plugin, and click **Install Now**, or use **Upload Plugin** if you have the ZIP file.
4. Click **Activate**.
**Warning:** deleting a plugin is not the same as deactivating it. When WordPress deletes a plugin it runs that plugin's uninstall routine, and a well-behaved plugin uses that routine to clean up after itself. Some plugins deliberately drop their own database tables and options at that point. Deactivation is always safe; deletion is not guaranteed to be. If losing the plugin's settings would hurt, use Method 1 or Method 2 instead, and make sure your backup is current.
Also bear in mind that deactivating a page builder, security plugin or caching plugin, even briefly, can change how the live site renders while you work. Do this during a quiet period.
## Method 4: Force an Update by Editing the Version Number (Last Resort)
This is the classic trick: lower the version number in the plugin's main file so WordPress believes an update is available, then run that update. WordPress downloads a fresh copy from the repository and overwrites the folder.
It still works, but it is the riskiest method on this page, because you are editing a live PHP file on a running site with no backup taken by the editor. Use it only when the methods above are not available to you.
**Before you start, note these limits:**
- It only works for plugins distributed through the WordPress.org repository. Premium plugins using their own update servers will either show no update or fail a licence check.
- The **Plugin File Editor** may not appear at all. Many hosting setups and security plugins set `DISALLOW_FILE_EDIT` in `wp-config.php`, which removes the file editors from the admin menu by design.
- Since WordPress 5.2, saving a PHP file through the editor triggers loopback requests to the admin screen and the homepage, and the change is rolled back automatically if a fatal error is detected. Treat that as a safety net, not a guarantee: it does not catch breakage that stops short of a fatal error.
### Step 1: Open the Plugin File Editor
Log in to the WordPress dashboard, then go to **Plugins** and click **Plugin File Editor**.

**Where is it?** The location depends on your theme. On a classic theme the Plugin File Editor sits under **Plugins**. On a block theme, WordPress moves both file editors to **Tools**, so look for **Tools** and then **Plugin File Editor**.
### Step 2: Select the Plugin
From the **Select plugin to edit** drop-down, choose the plugin and click **Select**.

The editor opens the plugin's main file by default, which is the file carrying the plugin header comment. That is the file you need. Do not open a file from an `includes` or `assets` folder.
### Step 3: Lower the Version Number
Near the top of the file, inside the header comment block, find the version line:
```
Version: 1.7.2
```
Change it to a lower number, for example:
```
Version: 1.7.1
```

Change the version downwards only, and change nothing else on the line or anywhere else in the file. Keep the format valid, such as `1.7.1`. Do not set it to `0`, leave it blank, or delete the line: a missing or malformed version header confuses the updater and some plugins read their own version at runtime.
### Step 4: Save and Run the Update
Scroll down and click **Update File**. Then return to the **Installed Plugins** list. An update should now be offered for the plugin you edited. Click **Update now**.

WordPress puts the site into maintenance mode for a few seconds, downloads the current release, and replaces the plugin folder. When it finishes, confirm on the **Installed Plugins** screen that the version number has returned to the real current release. The plugin's settings and data are exactly as they were.
**If no update appears:** WordPress caches update information for up to twelve hours. Go to **Dashboard** and then **Updates**, and click **Check again** to force a fresh lookup, then revisit the Plugins screen.
## Troubleshooting
**Symptom**: There is no **Plugin File Editor** item anywhere in the menu. The file editors have been disabled through `DISALLOW_FILE_EDIT` in `wp-config.php`, or by a security plugin. This is a sensible hardening measure and is best left in place. Use Method 1 or Method 2 instead.
**Symptom**: Saving the file returns an error saying the change was reverted because it would cause a fatal error. You edited the wrong file, or the edit broke PHP syntax. Only the version number on the `Version:` line should have changed. Reopen the plugin's main file and try again.
**Symptom**: No update is offered after lowering the version. Force an update check from **Dashboard** and then **Updates**. If it still does not appear, the plugin is almost certainly not hosted on WordPress.org, so use the vendor's ZIP file with Method 1 or Method 3.
**Symptom**: The update fails with a permissions or "could not create directory" error. The plugin directory is not writable by the web user. Contact Noiz support and quote the exact error, and the file ownership will be corrected for you.
**Symptom**: The site shows a blank page or a critical error after the edit. Restore access by disabling the plugin outside the dashboard: rename its folder under `wp-content/plugins/` using SFTP or your control panel's file manager, which deactivates it immediately, or run `wp plugin deactivate plugin-slug` over SSH. Then reinstall it cleanly with Method 1.
**Symptom**: The plugin was reinstalled successfully but the original fault is still there. The problem is not in the plugin's files. Test by deactivating all other plugins and switching to a default theme, then reactivating one at a time to find the conflict, or check the plugin's own settings and database records.
## Getting Help
If the plugin is central to a live site and you would rather not experiment on it, Noiz support can take a restore point, run the reinstall through WP-CLI, and confirm the result for you. Open a ticket from the Noiz client area with your domain name, the plugin name, and a short description of what the plugin is doing wrong.
# How to Improve WordPress Search
Source: https://docs.noiz.ie/wordpress/how-to-improve-wordpress-search/
This guide explains why the search box that comes with WordPress often disappoints, and walks you up a ladder of ways to make it genuinely useful: getting the most out of the built-in search, widening what it looks through, adding live "results as you type" search, and, when you truly need it, moving search out to a purpose-built search engine. Site search is the feature visitors reach for when your menu has failed them, so a search that returns nothing, or the wrong thing, quietly costs you readers and sales. This guide is written for Noiz clients who run their own WordPress site. It names categories of tool, and gives specific products only as examples to illustrate a category, never as endorsements, because the right choice depends entirely on the size and shape of your site.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WP\_Query class (WordPress Developer Resources)](https://developer.wordpress.org/reference/classes/wp_query/): the reference for how WordPress runs a search, including the `s` search parameter, the `search_columns` argument, and the `relevance` ordering used for search results.
- [WP\_Query::parse\_search\_order() (WordPress Developer Resources)](https://developer.wordpress.org/reference/classes/wp_query/parse_search_order/): the exact relevance ranking WordPress applies to search results, which is more useful to understand than most people realise.
- [Search block (WordPress Documentation)](https://wordpress.org/documentation/article/search-block/): how to place and style a search box using the built-in Search block.
- [get\_search\_form() (WordPress Developer Resources)](https://developer.wordpress.org/reference/functions/get_search_form/): how WordPress renders the search form, and how a theme's `searchform.php` overrides the default.
- [Search plugins (WordPress Plugin Directory)](https://wordpress.org/plugins/tags/search/): the directory's search tag, where you can compare plugins by last-updated date, active installations, and compatibility before choosing one.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an administrator. Placing a search box needs only editor rights, but installing plugins or changing settings needs administrator rights.
- A recent, restorable backup of your site before you install a search plugin or edit any theme file. Nothing here is high-risk, but a backup is your safety net.
- For the code-level and template changes described later, a basic comfort with editing theme files through a child theme. If you would rather not touch code, the plugin and service routes achieve the same ends without it, and the Noiz support team can make template changes for you on a managed plan.
## How WordPress Search Actually Works
Understanding the built-in search is the fastest way to see why it falls short, and it saves you from reaching for a plugin you may not need. When a visitor submits a search, WordPress runs a database query against your posts and pages and looks for the search words in just three places: the **title**, the **excerpt**, and the **main body content**. Nothing else is consulted.
The matching itself is a plain substring match. WordPress asks the database, in effect, "does this text contain these letters somewhere", using a SQL `LIKE` pattern. It splits the phrase into words, drops very short common words, and requires each remaining word to appear somewhere in the title, excerpt, or body. That is the whole mechanism, and two consequences flow straight from it. Because it matches raw letters, it has no idea that words are related: a search for `run` will not find `running`, and a single mistyped letter finds nothing at all. And because the pattern can begin anywhere inside a field, the database usually cannot use an index to speed it up and must read through your content row by row, which matters on a large site.
There is one part people underrate. Contrary to a widespread belief that WordPress "just sorts search results by date", it has ordered them by relevance for many years. When a search term is present, WordPress ranks the matches roughly like this: a page whose **title contains the whole phrase** comes first, then pages where **every word appears in the title**, then pages where **any word appears in the title**, then a whole-phrase match in the excerpt, then a whole-phrase match in the body, with everything else last and ties broken by date. So the relevance is real, but it is coarse: it only knows about title versus excerpt versus body, and it cannot weigh how often a word appears, how important a page is, or anything about meaning.
## The Real Limits of the Built-in Search
With the mechanism in mind, the weaknesses are easy to name honestly. They fall into three groups, and which of them actually hurts you depends on your site.
### It Only Looks in Three Places
The search never sees a large amount of the information on a typical site. It does not look in **custom fields** (the extra data many themes and plugins store against a post, such as a price, an author bio, a document reference or an event date), it does not search **categories or tags**, it does not read **comments**, and it cannot look inside **uploaded files** such as the text of a PDF. It also ignores content that some page builders keep tucked away in custom fields rather than in the main body, which is why a site built with a heavy builder can have a search that mysteriously finds almost nothing. If your visitors expect to find a product by its stock code, a member by their profile details, or a document by a word inside it, the built-in search simply cannot do it.
### It Does Not Understand Language
Because matching is letter-by-letter, the search has none of the forgiveness people now expect from Google. There is **no typo tolerance**, so `accomodation` returns nothing for a page about accommodation. There is **no stemming**, so `bake`, `baked`, and `baking` are three unrelated searches. There are **no synonyms**, so a visitor searching for `doctor` will not find your page about a `physician`. Real visitors do not type the exact words you used, and every one of these gaps turns a near-miss into an empty results page.
### It Slows Down as a Site Grows
The row-by-row scan described earlier is cheap on a small blog and expensive on a large one. On a site with many thousands of posts, products, or documents, each search reads a great deal of the database, and busy sites can run many searches at once. There is a hosting-specific twist worth knowing: page-caching, which speeds up the rest of your site by serving saved copies of pages, generally does **not** cache search results, because every search is different and results must be current. So while your home page might be served instantly from cache, every single search goes all the way to the database and does the full work. On Noiz hosting this is handled gracefully for normal traffic, but it is the reason search is often the slowest thing a large WordPress site does, and the reason a dedicated search engine becomes attractive at scale.
## Decide How Much Better Your Search Needs to Be
Before changing anything, be honest about the problem you actually have, because the effort and cost rise steeply as you climb the ladder and there is no prize for over-engineering. Ask yourself:
- **Is search even used, and where is it failing?** The single most useful thing you can do first is find out what people search for and how often they get nothing. Many search plugins record this, and even a basic analytics setup can show it. If nobody uses search, invest your effort elsewhere. If people search constantly and often see "nothing found", you have a clear target.
- **Is the problem scope or relevance?** If the right pages exist but the search cannot reach them (a product code in a custom field, a term in a category), you need to *widen* what search looks through. If the right pages are found but buried, you need better *ranking*. These call for different fixes.
- **How much content, and how fast is it growing?** A few hundred posts behave very differently from fifty thousand products. Scale is what pushes you from a plugin towards an external search service.
The rest of this guide is arranged as that ladder. Climb only as far as your answers require.
## Step One: Get the Most From the Built-in Search
On a small, mostly text site, the built-in search is often adequate once you remove the things that make it look broken. None of this needs a plugin.
### Make Sure There Is a Search Box, and a Results Page
Add a visible search box using the **Search block**, which you can drop into your header, sidebar, or footer through the editor. A search visitors cannot find is a search nobody uses. Just as importantly, check that your theme actually has a proper **search results template**. If a theme is missing one, WordPress falls back to a generic template and the results page can look bare or confusing, which people often mistake for search being "broken". A good results page shows what was searched for, lists the matches clearly, and, crucially, shows a helpful message with links or a fresh search box when nothing is found, rather than a blank page.
### Widen What Search Looks Through (a Code-Level Option)
WordPress gives developers a supported way to control and extend the built-in search without a plugin. The `search_columns` setting (and its companion filter) lets you choose which of the title, excerpt, and body are searched, and well-established filters let you fold custom fields or taxonomy terms into the query so a search can, for example, match a product's stock code. This is genuinely useful for a targeted need, and it keeps your site lean.
Two honest cautions. First, this is code, and it belongs in a child theme's `functions.php` or a small site-specific plugin, never pasted into the built-in file editor on a live site. If you are going to edit theme files, do it the safe way described in [How to Safely Edit Your WordPress Theme](/wordpress/how-to-safely-edit-your-wordpress-theme/). On Noiz hosting you reach those files over SFTP or through the File Manager in your hosting panel (Plesk on neo.noiz.co.za, or DirectAdmin or ISPConfig depending on your plan), and managed-plan clients can ask the Noiz support team to add the snippet for them. Second, every column and custom field you add to the search makes each query heavier and slower, exactly the performance cost described above. Extending the query this way suits a specific, contained need on a modest site. Once you find yourself wanting custom fields, taxonomies, synonyms, and speed all at once, a plugin or a search service is the better tool.
## Step Two: Add Live "Results As You Type" Search
Live search, also called AJAX search, instant search, or autocomplete, shows a small dropdown of matching results while the visitor is still typing, without reloading the page. It is the behaviour people know from large sites, and it is one of the highest-impact improvements you can make, because it guides visitors towards a result before they even finish their query and keeps them from landing on an empty results page.
Under the surface, live search sends a quiet request to your site after each keystroke and drops the answers into the dropdown. That convenience has a cost worth respecting: instead of one search when the visitor presses enter, your site may now answer a burst of searches as they type. A well-built live search softens this by waiting until the visitor pauses before sending a request, requiring a minimum number of characters before it starts, and briefly caching common queries. A poorly built one fires on every single keystroke and can put real load on your database, which matters most on the large sites that also have the slowest underlying search.
The important point is that live search is a **presentation layer**. It changes how results are delivered, not how good they are. If it sits on top of the built-in search, it inherits every limitation above: it will be just as blind to custom fields and just as intolerant of typos, only faster to show you nothing. Live search is at its best when paired with one of the stronger back ends below, which is why most search plugins and search services offer it as a headline feature rather than as a standalone trick.
## Step Three: When a Search Plugin Makes Sense
When you have outgrown the built-in search but do not need an external engine, a dedicated search plugin is the usual answer, and for the large majority of sites it is the right stopping point. Rather than lean on the same limited database query, these plugins build and maintain their own **search index**: a separate, purpose-shaped copy of your content that can be searched far more flexibly. That indexing approach is what lets a good search plugin do the things core cannot.
The category, taken as a whole, typically offers:
- **Wider scope:** searching custom fields, categories and tags, comments, and often the text of PDFs and other documents, so the product code and the tagged term finally become findable.
- **Better relevance you can tune:** weighting a title match above a body match, adding synonyms so `doctor` finds `physician`, and handling common misspellings.
- **Built-in live search** as described above, already wired to the better index.
- **Search insights:** a record of what visitors searched for and which searches returned nothing, which is the raw material for fixing your content and your synonyms. This alone often justifies the plugin.
The trade-offs are modest but real. The index lives in your database and takes space, and it must be rebuilt when content changes or when you first switch the plugin on, which can be briefly demanding on a very large site. Because the plugin still runs on the same server and database as your site, it improves relevance and scope dramatically but does not, on its own, escape the underlying performance ceiling on a truly enormous catalogue. Well-known plugins in this category are offered here only as examples of the type, not as recommendations; before installing any of them, weigh it as you would any plugin, checking its last-updated date, active installations, and support activity in the [plugin directory](https://wordpress.org/plugins/tags/search/), and keeping the wider guidance in the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/) in mind.
## Step Four: When an External Search Service Makes Sense
At the top of the ladder, search is handled by a separate, dedicated search engine rather than by WordPress at all. This is the answer for large stores, big content libraries, and sites where search is central to the experience and must be fast and forgiving no matter how much content there is. In this arrangement your content is copied into a specialist search engine, and when a visitor searches, WordPress asks that engine for the answer instead of querying its own database.
Because these engines are built for one job, they bring capabilities a database-based search struggles to match: genuine **typo tolerance** and synonyms, **faceted search** (the "filter by brand, price, colour" panels shoppers expect), and results returned in a few thousandths of a second even across millions of items. Just as valuable on busy hosting, the heavy lifting happens **off your web server**, so a flood of searches no longer competes with everything else your site is doing.
These come in two shapes, and the difference matters for hosting:
- **Hosted (managed) search services** run the search engine for you in the cloud. You connect WordPress to them with an account and an API key, usually through a plugin, and you pay a monthly fee that scales with your usage. They are the practical route on standard web hosting, because your Noiz site can reach them over an ordinary outbound HTTPS connection with nothing to install at the server level.
- **Self-hosted search engines** are software you run yourself. These are powerful and avoid ongoing per-search fees, but they need their own dedicated server or virtual machine with sufficient memory to run alongside your site. They are not something that belongs on a shared hosting account. If you are considering this route, talk to the Noiz support team about a hosting plan that can accommodate a separate search server, so the search engine has resources of its own and does not starve your website.
Two considerations apply whichever shape you choose. There is a real **cost**, in monthly fees or in the server and effort to run your own, so this step should be driven by need rather than novelty. And with a hosted service you are **sending a copy of your searchable content, and your visitors' search queries, to a third party**, which is a data-sharing decision to make deliberately and, where personal information is involved, to reflect in your privacy policy under rules such as POPIA and the GDPR. Named services in this space are, again, mentioned only as examples of the category.
## Choosing Your Rung: A Sensible Path
You do not need to climb the whole ladder, and adding an external search engine to a two-hundred-post blog is wasted effort and money. Match the tool to the problem:
- **Small, mostly text sites.** Make sure there is a visible search box and a proper results page with a helpful "nothing found" message. If a single specific need is unmet, such as searching one custom field, extend the built-in query with a small snippet. This is free and keeps your site lean.
- **Growing sites that need custom-field or taxonomy search, better relevance, or live search.** A dedicated search plugin that builds its own index covers all of this at once, and its search insights tell you where your content is letting visitors down. For most sites, this is the right and final step.
- **Large stores or content libraries where search must be fast, typo-tolerant, and faceted at scale.** Move search out to an external service, hosted if you are on standard hosting, self-hosted on a dedicated server if scale and cost justify it. Choose this because you have measured the need, not because it sounds impressive.
Whichever rung you settle on, the groundwork from Step One still pays off. A clear search box, a well-built results template, and an informative empty-results page improve the experience no matter what is powering the search behind them.
## Troubleshooting
- **Symptom**: searching returns a blank or broken-looking page even when matching content exists. Your theme most likely lacks a proper search results template and WordPress is falling back to a generic one. Add or fix the search results template, or choose a theme that includes one, so results are laid out clearly with a message when nothing is found.
- **Symptom**: a product, member, or document that clearly exists cannot be found by an obvious word. That word almost certainly lives in a custom field, a taxonomy term, or a PDF, none of which the built-in search reads. Extend the query to include the relevant field, or move to a search plugin that indexes custom fields and documents.
- **Symptom**: near-miss searches return nothing, for example a small typo or a plural form finds no results. This is the built-in search having no typo tolerance or word-stemming. Add synonyms and misspellings where you can, and if it is a frequent problem, a search plugin or external service is the real fix.
- **Symptom**: search is noticeably slow, or slows the whole site when several people search at once. On a large site the built-in search reads a great deal of the database and its results are not page-cached. Reduce the load by moving to an indexed search plugin, or, at real scale, an external search service that runs off your web server.
- **Symptom**: live search feels sluggish or seems to hammer the site. It is probably sending a request on every keystroke. Choose a live-search option that waits for a pause in typing, requires a minimum number of characters, and caches common queries, and pair it with a stronger back end rather than the raw built-in search.
- **Symptom**: results include pages you did not expect, such as media attachment pages or an unrelated custom post type. Search includes every content type marked as searchable. Exclude the unwanted type from search so it no longer appears in results.
- **Symptom**: after installing a search plugin, results are missing or stale. The plugin's index has probably not finished building, or has not caught up with recent changes. Trigger a full rebuild of the index from the plugin's settings and let it complete.
If you are not sure which rung of this ladder your site needs, or you would like help extending the built-in search, choosing and configuring a search plugin, or connecting an external search service, open a support ticket with the Noiz support team. Include your domain, a rough idea of how much content your site holds, and what your visitors are trying to find but cannot, and a technician can help you put a proportionate improvement in place.
# How to Install a WordPress Plugin
Source: https://docs.noiz.ie/wordpress/how-to-install-a-wordpress-plugin/
Plugins are how a WordPress site gains features it does not ship with: contact forms, SEO tools, backups, caching, security hardening, shop functionality. This guide shows you how to search the official WordPress Plugin Directory and install a plugin directly from your WordPress dashboard, without touching FTP or a file manager, and how to tell a plugin worth installing from one that will cause you problems later.
This is the method to use for anything published on WordPress.org. If you bought a premium plugin and were given a ZIP file to upload, see [How to Manually Install a WordPress Plugin](/wordpress/how-to-manually-install-a-wordpress-plugin-from-a-zip-file/) instead.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for WordPress sites hosted with Noiz and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Documentation: Manage Plugins](https://wordpress.org/documentation/article/manage-plugins/)
- [The WordPress Plugin Directory](https://wordpress.org/plugins/)
- [Plugin Directory Guidelines (what a listed plugin must comply with)](https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/)
- [WordPress Roles and Capabilities](https://wordpress.org/documentation/article/roles-and-capabilities/)
## Prerequisites
- A WordPress site on your Noiz hosting account.
- An **Administrator** account on that site. Editor, Author and Contributor accounts cannot install plugins.
- A current backup, or the confidence that you can restore one. Installing a plugin changes your site's code, and a small number of plugins do not get on with each other.
- On a WordPress Multisite network, plugin installation is restricted to the Network Administrator from **My Sites** > **Network Admin** > **Plugins**.
## Install a Plugin From the WordPress Dashboard
### 1. Log in to the WordPress dashboard
Go to `https://yourdomain.com/wp-admin` (replace `yourdomain.com` with your own domain) and sign in with your Administrator account.
### 2. Open the plugin installer
In the left-hand menu, hover over **Plugins** and click **Add New Plugin**. On WordPress versions before 6.4 this menu item is labelled simply **Add New**, as shown below. Both open the same screen.

### 3. Search for the plugin you want
Use the **Search plugins** box on the right of the screen to search the WordPress Plugin Directory. You can search by exact plugin name, by author, or by keyword. In this example, typing **Security** returns plugins tagged for site security.

Search is live, so results update as you type. If you already know the exact plugin you need, type its full name rather than a keyword; keyword searches surface a lot of loosely related results.
### 4. Install the plugin
Find the plugin you want in the results and click **Install Now** on its card. WordPress downloads the plugin from WordPress.org and unpacks it into `wp-content/plugins` on your hosting account for you.

Before you click, read the card. It shows the star rating, the number of active installations, when the plugin was last updated, and whether it is marked compatible with your version of WordPress. Click **More Details** for the full readme, changelog and support history. See [Choosing a Plugin Worth Installing](#choosing) below for what those numbers actually tell you.
### 5. Activate the plugin
Installation takes a few seconds. When the button changes to **Activate**, click it. A plugin that is installed but not activated does nothing at all, so this step is not optional.

### 6. Configure the plugin
After activation, most plugins add their own entry to the dashboard menu, either as a new top-level item or as a sub-item under **Settings** or **Tools**. Plugins that need setting up before they do anything usually show a setup wizard or an admin notice with a link to it. If nothing obvious appears, check **Plugins** > **Installed Plugins**: the plugin's row often carries a **Settings** link.
## Choosing a Plugin Worth Installing
Every plugin listed in the WordPress Plugin Directory has passed a review, but that review checks compliance with the directory guidelines, not quality, performance or long-term maintenance. Before you install, look at four things on the plugin card or its **More Details** panel:
- **Last updated.** A plugin untouched for more than a year is a risk. Abandoned plugins are one of the most common routes into a compromised WordPress site, because nobody is left to patch them.
- **Active installations.** A plugin with hundreds of thousands of installs has had far more eyes on its code than one with two hundred. Low install counts are not disqualifying, but they raise the burden of proof.
- **Tested up to.** If the plugin has not been tested against a recent WordPress release, expect friction. WordPress will warn you before installing an untested plugin, and you can proceed, but do it on a staging copy first.
- **Support threads resolved.** On the plugin's WordPress.org page, the support tab shows how many recent threads the developer actually answered. A wall of unanswered threads tells you what your own support experience will be.
Also keep the total count down. Plugin count itself is not the problem, but every active plugin adds queries, HTTP requests and code that runs on each page load, and a site running forty plugins is a site where diagnosing a slowdown or a conflict becomes genuinely difficult. Install what you need, and remove what you stopped using rather than leaving it deactivated. See [How to Deactivate and Delete a WordPress Plugin](/wordpress/how-to-deactivate-and-delete-a-wordpress-plugin/).
## Troubleshooting
**Symptom**: there is no **Add New Plugin** item under the **Plugins** menu, or no **Plugins** menu at all.
Your account is not an Administrator, or the site is part of a Multisite network where plugin installation is handled by the Network Administrator. If you are certain you are an Administrator on a standalone site, the constant `DISALLOW_FILE_MODS` may be set to `true` in `wp-config.php`, which disables plugin and theme installation across the whole site. Some security plugins set this deliberately.
**Symptom**: WordPress asks for FTP connection details when you click **Install Now**.
This happens when WordPress cannot write to `wp-content/plugins` under its own user, usually because files were uploaded or restored under the wrong ownership. On Noiz hosting, file ownership is set correctly when the site is provisioned, so this prompt normally means something was copied in from elsewhere. Open a support ticket rather than entering credentials into the prompt, and Noiz will correct the ownership.
**Symptom**: the installation fails with a message about the destination folder already existing.
An earlier copy of the plugin is still on disk, often from a half-finished install or a manual upload. Check **Plugins** > **Installed Plugins** first: if the plugin is listed there, use its **Update** link instead of installing it again. If it is not listed, delete the leftover folder under `wp-content/plugins` using the File Manager in your hosting control panel, then retry.
**Symptom**: your site shows a blank page or an error immediately after activating a plugin.
The plugin has conflicted with your theme, another plugin, or the site's PHP version. If you can still reach the dashboard, deactivate the plugin. If you cannot, rename that plugin's folder inside `wp-content/plugins` using the File Manager; WordPress deactivates any plugin whose folder it can no longer find, which restores access to the dashboard.
**Symptom**: the plugin installs, but a required PHP extension or a higher PHP version is reported as missing.
Check the plugin's requirements on its WordPress.org page, then raise a ticket with Noiz. Most PHP version changes and extension requests are handled quickly on Noiz hosting.
## Related Articles
- [How to Manually Install a WordPress Plugin](/wordpress/how-to-manually-install-a-wordpress-plugin-from-a-zip-file/), for premium or third-party plugins supplied as a ZIP file.
- [How to Deactivate and Delete a WordPress Plugin](/wordpress/how-to-deactivate-and-delete-a-wordpress-plugin/), for removing plugins cleanly.
If a plugin will not install, breaks your site on activation, or needs a PHP setting your site does not currently have, open a ticket from the Noiz client area and the Noiz support team will take a look.
# How to Install a WordPress Theme from the Dashboard
Source: https://docs.noiz.ie/wordpress/how-to-install-a-wordpress-theme-from-the-dashboard/
A WordPress theme controls how your site looks: the layout, fonts, colours and the styling of every page. Installing one from the WordPress dashboard takes a few clicks and needs no technical knowledge, because WordPress downloads and unpacks the theme files on the server for you. This guide shows you how to find, install and activate a theme from the WordPress Theme Directory on a Noiz hosting account, what actually changes on your site the moment you activate it, and how to fix the handful of errors that come up.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress: Appearance Themes Screen](https://wordpress.org/documentation/article/appearance-themes-screen/)
- [WordPress: Work With Themes](https://wordpress.org/documentation/article/work-with-themes/)
- [The WordPress Theme Directory](https://wordpress.org/themes/)
## Prerequisites
- A WordPress site on your Noiz hosting account.
- An administrator login for that site. Editor, author and contributor accounts cannot install themes.
- A recent backup of the site, or a staging copy, if the site is already live. Activating a theme changes the front end immediately.
## Install a Theme From the WordPress Theme Directory
This method installs any of the free, licence-checked themes hosted on WordPress.org. It is the easiest and safest route, and it is the one to use unless you have bought a premium theme or been sent a ZIP file.
1. Log in to your WordPress dashboard at `yourdomain.com/wp-admin`, replacing `yourdomain.com` with your own domain.
2. In the left-hand menu, go to **Appearance** and click **Themes**. 
3. Click **Add New Theme** at the top of the page. On older WordPress versions this button is labelled **Add New**. 
4. Find a theme. You can type a keyword, theme name, author or tag into the search box, browse the **Featured**, **Popular**, **Latest** and **Favorites** tabs, or click **Feature Filter** to narrow by subject, features and layout.
5. Hover your mouse over the theme you want and click **Install**. Click **Preview** first if you want a full-screen look at the theme demo before committing. 
6. Once the download finishes, the **Install** button becomes **Activate**. Click **Activate** to make the theme live on your site. 
The theme is now installed and active. Visit your site in a new browser tab to see it. If you would rather install the theme now and switch to it later, stop after step 5: an installed but inactive theme sits harmlessly on the **Appearance** > **Themes** screen until you activate it.
## Installing a Theme You Downloaded as a ZIP File
Premium themes and themes bought from third-party marketplaces are not in the WordPress Theme Directory, so they will not appear in the search results above. Those arrive as a `.zip` file that you upload yourself, either through the dashboard or over FTP. See [How to Install a WordPress Theme Manually](/wordpress/how-to-manually-install-a-wordpress-theme-from-a-zip-file/) for that procedure.
One warning worth repeating: never install a "nulled" or cracked copy of a premium theme found on a file-sharing site. These are the single most common way WordPress sites on any host get compromised, because the pirated copy almost always carries injected backdoor code. If a paid theme is being given away free, the theme is not the product.
## What Changes the Moment You Activate a Theme
Activating a theme does not touch your posts, pages, media or users. Those live in the database and in `wp-content/uploads`, entirely separate from the theme. What does change, often more than people expect:
- **Menus.** Every theme defines its own menu locations. Your navigation menu still exists under **Appearance** > **Menus**, but it will usually need reassigning to the new theme's menu location before it reappears.
- **Widgets and sidebars.** If the new theme has fewer sidebars, or none at all, widgets from the old theme are moved to the inactive widgets area. They are not deleted, and they come back if you switch the old theme on again.
- **Theme settings.** Logo, colour choices, header images and layout options are stored per theme. A new theme starts with its own defaults, so expect to set your logo and colours again.
- **Homepage layout.** Themes that rely on a demo homepage will not import that demo automatically. Your homepage will show whatever **Settings** > **Reading** is set to, which may look nothing like the theme's screenshot until you build the page.
- **Shortcodes.** Any shortcodes provided by the old theme, rather than by a plugin, will stop working and can leave visible `[bracketed_text]` in your content. Search your pages for stray shortcodes after a switch.
## Block Themes and Classic Themes
WordPress themes come in two families, and the difference determines how you will edit your site afterwards.
- **Block themes** support full site editing. After activating one, the **Appearance** menu shows **Editor**, and you edit the header, footer and templates visually in the same block editor you use for pages. All default themes from Twenty Twenty-Two onwards are block themes.
- **Classic themes** use the older model: the **Customizer** under **Appearance** > **Customize**, plus PHP template files for anything deeper.
Neither is wrong, and both are fully supported on Noiz hosting. Just be aware that tutorials written for one will not match the screens you see in the other, which is a frequent source of confusion when following a guide that does not say which it assumes.
## Choosing a Theme That Will Not Cause Problems Later
Before you install, check these on the theme's directory listing. They take thirty seconds and save a great deal of trouble:
- **Last updated.** A theme not updated in two years or more is a poor bet. It may break on the next WordPress or PHP release and is unlikely to receive a security fix.
- **Active installations.** A large number is not proof of quality, but a widely used theme has had far more eyes on its bugs.
- **Tested up to.** Compare against the WordPress version your site runs, shown at **Dashboard** > **Updates**.
- **Support and review threads.** Unanswered support topics stretching back months tell you what happens when you need help.
Installing a handful of themes to compare them is fine, but do not leave them lying around. Every inactive theme still has to be kept updated, and an out-of-date inactive theme is just as exploitable as an active one. Delete the ones you rejected.
## Try Before You Switch on a Live Site
If the site is already live and taking visitors, do not activate an unfamiliar theme on it directly. Two safer options:
- **Live Preview.** On the **Appearance** > **Themes** screen, hover over an installed but inactive theme and click **Live Preview**. This shows the theme running against your real content, visible only to you, and nothing changes until you click **Activate**.
- **A staging copy.** Clone the site to a subdomain such as `staging.yourdomain.com`, switch the theme there, and rebuild the pages at your leisure. This is the right approach for a redesign rather than a quick swap.
Take a full backup either way. If you are on a Noiz managed plan and are unsure how to take one, open a ticket and Noiz will handle it for you before you begin.
## Troubleshooting
**Symptom**: there is no **Add New Theme** button on the Themes screen. Either you are not logged in as an administrator, or file modifications have been disabled in `wp-config.php` with `DISALLOW_FILE_MODS`. On WordPress Multisite, themes are installed from the Network Admin dashboard and then enabled per site, not from the individual site's dashboard.
**Symptom**: WordPress asks for FTP connection details when you click **Install**. This means WordPress cannot write to the themes folder as the web server user, which is nearly always an ownership or permissions problem after files were uploaded or restored by a different account. Do not paste FTP credentials into that box as a workaround. Open a support ticket and Noiz will correct the ownership on the account.
**Symptom**: "Installation failed: Could not create directory" or "Download failed". Check your disk usage in your hosting control panel first, because a full account cannot unpack the theme. If there is space, this is again a filesystem permissions issue on `wp-content/themes` and one for Noiz support to fix.
**Symptom**: "The package could not be installed. The theme is missing the style.css stylesheet." This appears when you upload the wrong ZIP, typically the full marketplace download that contains the theme ZIP, documentation and licence files inside it. Unzip it on your computer and upload only the inner theme folder's ZIP. This applies to the manual upload route rather than the directory install above.
**Symptom**: the site shows a blank white page or a fatal error after activating. The theme is incompatible with your PHP version or with an active plugin. You can still recover: log in at `yourdomain.com/wp-admin` and switch back to a default theme. If the dashboard itself is unreachable, rename the active theme's folder in `wp-content/themes` using File Manager in your hosting control panel. WordPress will fall back to a default theme automatically and let you back in.
**Symptom**: the theme installs but your site looks nothing like the demo. This is normal and not a fault. Theme demos are built with imported demo content and configured widgets or block patterns. Follow the theme author's own setup documentation to reproduce the layout.
## Need a Hand?
If a theme will not install, activation has broken your site, or you would like a redesign staged and tested before it goes live, the Noiz support team can help. Open a support ticket from the Noiz client area with your domain name and what you were doing when the problem appeared, and Noiz will take it from there.
# How to Log In to the WordPress Dashboard
Source: https://docs.noiz.ie/wordpress/how-to-log-in-to-the-wordpress-dashboard/
WordPress runs a large share of the web, and almost everything you do with it starts in the admin dashboard: writing posts, installing plugins, changing the theme, running updates. This guide shows you the three ways to reach that dashboard on a Noiz hosting account, and what to do when the login screen does not behave.
The dashboard is also called **wp-admin**, the **WordPress admin area**, or the **backend**. They all mean the same screen.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable), Plesk **Obsidian** with the **WordPress Toolkit**, and the **Softaculous** app installer. This guide is written for Noiz hosting and is kept current against WordPress and the control panels Noiz runs. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [The Dashboard screen](https://wordpress.org/documentation/article/dashboard-screen/): what each panel in the WordPress dashboard does once you are in.
- [Administration screens](https://wordpress.org/documentation/article/administration-screens/): the full map of the WordPress admin area.
- [Reset your password](https://wordpress.org/documentation/article/reset-your-password/): the official password recovery routes, including the database method.
- [Plesk WP Toolkit customer guide](https://docs.plesk.com/en-US/obsidian/customer-guide/wp-toolkit.79128/): the full WordPress Toolkit feature set.
- [Softaculous WordPress Manager](https://www.softaculous.com/docs/enduser/wordpress-manager/): the one-click admin login and management features.
## Prerequisites
- WordPress already installed and pointed at a working domain. If it is not installed yet, see [How to Install WordPress with Softaculous](/softaculous/how-to-install-wordpress-with-softaculous/).
- Your WordPress username or the email address on the account, plus the password. These are set during installation and are separate from your hosting control panel and Noiz client area logins.
- For the control panel methods, access to the hosting control panel for the subscription that holds the site.
## Log In from Your Web Browser
This is the method that always works, on any host and any WordPress install, so it is worth knowing even if you normally use a shortcut.
1. Open `https://yourdomain.com/wp-admin` in your browser, replacing `yourdomain.com` with your own domain name. WordPress redirects that address to the login form.
2. Enter your username or email address and your password, then click **Log In**. 
3. If the credentials are correct, WordPress opens the dashboard at `https://yourdomain.com/wp-admin/`.
### Which Address to Use
Several addresses reach the same login form, which is why different guides quote different URLs:
- `https://yourdomain.com/wp-admin`: the usual one. If you are already signed in, it skips the form and drops you straight into the dashboard.
- `https://yourdomain.com/wp-login.php`: the actual login script. Use this if `/wp-admin` loops back on itself.
- `https://yourdomain.com/admin` and `/login`: these are not built into WordPress. They only work if a plugin or a server rewrite rule has been added to create them.
If WordPress is installed in a subfolder rather than at the root of the domain, the login address includes that folder, for example `https://yourdomain.com/blog/wp-admin`. For a multisite network, log in through the address of the individual site, not the network root.
### Things That Catch People Out
- **The login page is hidden.** Security plugins such as All-In-One Security, Wordfence and iThemes Security can move the login form to a custom address and make `/wp-admin` return a 404 or a redirect to the home page. This is deliberate, not a fault. If that has been done on your site, you need the custom address; it cannot be guessed. See [How to Find Your WordPress Login URL](/wordpress/how-to-find-your-wordpress-login-url/).
- **Tick Remember Me only on your own device.** Without it the session expires after roughly two days; with it the session lasts about two weeks. Never tick it on a shared or public machine.
- **The redirect after login.** When you open a specific admin page while logged out, WordPress appends a `redirect_to` value to the login URL and sends you to that page after you sign in. That is normal, and it is why the address bar sometimes looks longer than expected.
- **Use HTTPS.** Typing `http://` sends your password in clear text before any redirect takes effect. Every Noiz hosting plan includes a free SSL certificate, so always start the address with `https://`.
- **Bookmark the login page, not the dashboard.** Bookmarking a deep dashboard URL means a stale `redirect_to` value every time you sign in.
## Log In from the WordPress Toolkit in Plesk
If your Noiz plan runs on Plesk with the WordPress Toolkit, you can open the dashboard without typing a WordPress password at all. The toolkit signs you in with a one-time token, which is handy when the password is stored in a manager on another device, or when you look after several sites.
1. Log in to the Plesk control panel for your subscription. 
2. Click **WordPress** in the left-hand navigation. You can also reach the same place from **Websites & Domains**, then the **WordPress** tab for the domain you want.
3. Find the card for the site. Each installation is shown as a card with a live screenshot of the site.
4. Click **Log in** below the screenshot. A new tab opens with you already signed in to the WordPress dashboard.
**Note:** the button is labelled **Log in**, and it sits next to **Setup**. If you click **Setup** by mistake you land on the general WordPress settings screen rather than the dashboard; go back and click the other button.
The short video below walks through the same steps.
### When the Toolkit Login Does Not Work
- **The Log in button is missing or greyed out.** The toolkit only offers a login for installations it has detected and attached. If WordPress was copied in by hand or restored from a backup, use **Scan** in the WordPress Toolkit so it picks the site up, then try again.
- **It sticks on "Retrieving WordPress admin credentials, please wait".** This is almost always the PHP memory limit for the site being too low for the toolkit to run its check. Raise the PHP memory limit for the domain, or ask Noiz support to do it, then retry.
- **It opens the WordPress setup page instead of the dashboard.** That means WordPress cannot reach its own database, so it thinks it is a fresh install. Do not complete that setup form, because it can overwrite a working configuration. Check the database credentials in `wp-config.php` instead, or raise a ticket with Noiz support.
- **Two-factor authentication is skipped.** The toolkit login is a server-side shortcut, so it can bypass a 2FA prompt that a security plugin would normally show. That is expected behaviour, but treat access to the control panel as being every bit as sensitive as access to WordPress itself.
## Log In from Softaculous
Plans that do not include the WordPress Toolkit come with the Softaculous app installer instead, which has its own one-click admin login.
1. Log in to the control panel for your subscription.
2. Click **Softaculous** in the left-hand navigation, or the **WordPress Manager by Softaculous** button under **Dev Tools**. 
3. Click the **All Installations** icon in the top navigation, or the **Installations** tile on the Softaculous dashboard.
4. In the **Admin** column for your site, click the small person icon to **Login as admin**.  Softaculous signs you in without asking for the WordPress password.
The video below shows the whole sequence.
**Worth knowing:** Softaculous can only offer this shortcut for installations it created or has since detected. A site moved in from another host may not appear in the list until Softaculous scans for it, and a site that was installed through the WordPress Toolkit is not managed by Softaculous at all. Pick one tool per site and stay with it.
## Troubleshooting
**Symptom**: "Error: The username is not registered on this site." The username is wrong, not the password. Try the email address on the account instead, since WordPress accepts either.
**Symptom**: "Error: The password you entered for the username is incorrect." Use the **Lost your password?** link under the form. If the reset email never arrives, the site cannot send mail, which is a separate problem. In that case reset the password from the database, as described in [How to Reset a WordPress Admin Password via phpMyAdmin](/wordpress/how-to-reset-a-wordpress-admin-password-via-phpmyadmin/).
**Symptom**: "Error: Cookies are blocked or not supported by your browser." WordPress uses cookies to hold the session. Allow cookies for the domain, then reload the login page before trying again. Strict privacy extensions and third-party cookie blockers are the usual cause.
**Symptom**: the login form reloads with no error, over and over. This is nearly always a site address mismatch, where the **WordPress Address** and **Site Address** settings disagree with the address you typed, most often `www` against no `www`, or `http` against `https`. Log in using exactly the address configured for the site.
**Symptom**: "Too many failed login attempts" or the login page is temporarily blocked. A security plugin or the server firewall has locked the address out after repeated failures. Wait for the lockout to expire, or contact Noiz support to have your IP address released.
**Symptom**: the dashboard loads but is blank, or half the styling is missing. That is a plugin or theme conflict rather than a login fault. Reach the dashboard through the control panel shortcut, then deactivate plugins one at a time to find the culprit.
## Protect the Login Once You Are In
The WordPress login form is the single most attacked part of any WordPress site, and every one of those attempts is aimed at the same handful of usernames. Two changes remove most of the risk:
- Avoid the username `admin`, and use a long, unique password held in a password manager.
- Turn on two-factor authentication, so a stolen password on its own is not enough. See [How to Set Up Two-Factor Authentication (2FA) in WordPress with All-In-One Security (AIOS)](/wordpress/how-to-set-up-two-factor-authentication-2fa-in-wordpress-with-all-in-one-securit/).
For the wider picture, work through the [WordPress Security Checklist](/wordpress/wordpress-security-checklist/).
If you are locked out, unsure which control panel your plan uses, or you would rather someone handled the site for you, contact Noiz support and the team will get you back into your dashboard.
# How to Manage WordPress Categories the Right Way
Source: https://docs.noiz.ie/wordpress/how-to-manage-wordpress-categories-the-right-way/
This guide shows you how to manage the categories on your WordPress site properly: creating them, renaming them, re-parenting them, moving posts between them, merging two into one, and deleting the ones you no longer need. It also explains the difference between categories and tags, how to keep the whole structure lean, and how a tidy category system quietly improves your internal linking and navigation. Categories and tags together are called your **taxonomy**, which is simply the system WordPress uses to file and group your posts. Everything here uses features built into WordPress itself, so no plugin is required.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Posts Categories screen (WordPress Documentation)](https://wordpress.org/documentation/article/posts-categories-screen/): the official reference for the Categories screen, its fields, and its bulk actions.
- [Posts Tags screen (WordPress Documentation)](https://wordpress.org/documentation/article/posts-tags-screen/): the equivalent reference for tags, useful when deciding between the two.
- [Settings Writing screen (WordPress Documentation)](https://wordpress.org/documentation/article/settings-writing-screen/): where the Default Post Category is set.
- [Categories and Tags Converter (WordPress.org)](https://wordpress.org/plugins/wpcat2tag-importer/): the official importer, reached from **Tools > Import**, for converting categories into tags or the reverse.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- An account with the **Administrator** or **Editor** role. Managing categories requires the capability to manage the site's taxonomy, which authors and contributors do not have by default.
- For any large reorganisation, a recent backup of your site. See the backup section near the end before you start moving posts in bulk.
## Categories or Tags: Choosing the Right One
WordPress gives you two built-in ways to group posts, and using them for the right job is what keeps a site easy to navigate.
- **Categories are your table of contents.** They are broad, structural, and hierarchical: a category can have a parent and child sub-categories. Think of the main sections of a magazine, such as `News`, `Tutorials`, or `Reviews`. Every post must belong to at least one category. If you publish a post without choosing one, WordPress files it under the default category automatically.
- **Tags are your index.** They are specific, descriptive keywords with no hierarchy: there are no parent or child tags. A single tutorial might be tagged `backups`, `security`, and `beginner`. Tags are always optional, and a post can have none, one, or many.
A useful test: if the word describes a whole section of your site that you would happily put in a navigation menu, it is a category. If it describes a detail that only some posts share, it is a tag. Avoid using the same word as both a category and a tag, because that creates two archive pages competing for the same visitors and search engines.
## Where Categories Live
Categories are managed on their own screen, separate from writing posts.
1. In the WordPress admin menu on the left, hover over or click **Posts**.
2. Click **Categories**. The Categories screen opens.

The screen has two halves. On the left is the **Add New Category** form. On the right is the table of every existing category, showing each one's **Name**, **Description**, **Slug**, and **Count** (how many posts use it). Sub-categories appear indented under their parents, prefaced by a dash that is only there to show the hierarchy and is not part of the name.
## Create a Category
Each category has four pieces of information, and only the name is required.
- **Name**: what readers see, for example `Tutorials`. Every category name must be unique.
- **Slug**: the URL-friendly version of the name, used in the category's web address (for example `tutorials` in `yourdomain.com/category/tutorials/`). Leave it blank and WordPress generates one from the name. Keep it lowercase, with words separated by hyphens.
- **Parent Category**: leave as **None** for a top-level category, or pick a parent to make this a sub-category.
- **Description**: optional. Some themes show it at the top of the category's archive page, and it is a good place to note internally what the category is for.
1. On the Categories screen, fill in the **Name** and, if you want, the other fields.
2. Click **Add New Category**. It appears in the table on the right immediately.

You can also create a category while writing, without leaving the editor. In the post's settings sidebar, open the **Categories** panel and click **Add New Category**. This is handy for one-off additions, but the dedicated Categories screen is the place to plan and tidy the whole structure.
## Rename a Category
There are two ways to edit an existing category, and the difference matters more than it first appears.
- **Quick Edit**: hover over the category in the table and click **Quick Edit**. You can change the **Name** and **Slug** inline, then click **Update Category**.
- **Edit**: click the category name (or the **Edit** link) to open the full Edit screen, where you can also change the parent and description.

**The gotcha worth knowing:** changing only the **Name** is safe. The category's web address is built from the slug, not the name, so renaming `News` to `Latest News` while leaving the slug as `news` keeps every existing link and archive URL working. Changing the **Slug** is a different matter: it changes the category's URL, so any old links to `/category/news/` will break and return a "not found" page. Only change a slug when you genuinely need to, and if you do, set up a redirect from the old address to the new one.
## Move a Category or Its Posts
"Moving" a category can mean two different things, so it helps to be clear about which you want.
### Re-parent a Category (Change Its Position in the Hierarchy)
To slot a category under a different parent, or promote a sub-category to the top level:
1. Open the category with **Quick Edit** or the full **Edit** screen.
2. Change the **Parent Category** drop-down. Choose **None** to make it top-level, or pick a new parent.
3. Save. The category, and all the posts filed under it, move together. The posts themselves do not need touching.
### Move Posts From One Category to Another
To move the actual posts, use the Posts screen rather than the Categories screen.
1. Go to **Posts > All Posts**.
2. Use the **All Categories** filter drop-down at the top, choose the category you want to work from, and click **Filter** so only those posts are listed.
3. Tick the checkbox in the table header to select every post shown.
4. In the **Bulk actions** drop-down choose **Edit**, then click **Apply**. The Bulk Edit panel opens.
5. In the **Categories** box, tick the destination category, then click **Update**.

**Critical limitation of Bulk Edit:** ticking a category in the Bulk Edit panel only *adds* it to the selected posts. It cannot *remove* the old category, and there is no unticking a category here. So this step leaves the posts in both the old and new categories. The clean way to finish the move is covered in the next section, because moving every post out of a category and then removing the empty original is exactly what merging is.
## Merge Two Categories Into One
WordPress has no single "merge" button. What it has is a reliable built-in sequence that achieves the same result: add the target category to every post in the source category, then delete the source. Because the posts already carry the target, none of them are left stranded.
1. Go to **Posts > All Posts** and filter to the **source** category (the one you want to get rid of), as described above. If it holds more posts than fit on one page, open **Screen Options** at the top right and raise the "Number of items per page" so you can select them all at once, or repeat the process page by page.
2. Select all the listed posts, choose **Bulk actions > Edit**, click **Apply**, tick the **target** category in the Bulk Edit panel, and click **Update**. Every post now belongs to both categories.
3. Go to **Posts > Categories**, hover over the source category, and click **Delete**. Because each affected post still carries the target category, deleting the source simply removes the redundant label. The merge is complete and no posts revert to the default category.
The order matters. If you delete the source category *before* adding the target, any post that was in the source category only is reassigned to the default category, not to your intended target, and you will have to fix those by hand.
Two related tools are easy to confuse with merging, so to be clear: the official **Categories and Tags Converter** under **Tools > Import** converts a category into a tag (or the reverse), it does not combine two categories. Some third-party plugins do add a genuine one-click "merge terms" feature; they are a convenience for very large sites and are mentioned only as an example, not a recommendation. The built-in sequence above needs nothing extra installed.
## Delete a Category
Deleting a category never deletes the posts inside it.
- **Delete one category**: on the Categories screen, hover over it and click **Delete**, then confirm.
- **Delete several at once**: tick each one, choose **Bulk actions > Delete**, and click **Apply**.
Any post that was filed *only* under the deleted category is automatically reassigned to the **default category** so that it still has a home. Posts that also belong to other categories simply lose the deleted one and keep the rest. The default category itself cannot be deleted, which is why the option is missing when you hover over it.
## The Default Category (Uncategorized)
Every WordPress site ships with one category called **Uncategorized**, set as the default. Two small improvements are worth making early:
- **Rename it to something meaningful.** "Uncategorized" looks unfinished if it ever appears on your live site. Open it with **Quick Edit** and give it a sensible name such as `General` or `Blog`. Renaming the name (not the slug) is safe, as explained above.
- **Point the default at a real category.** Go to **Settings > Writing** and set **Default Post Category** to whichever category you use most. From then on, any post published without a category chosen lands there instead of in a generic bucket.

Remember that the current default cannot be deleted. If you want to remove the original Uncategorized category entirely, first choose a different Default Post Category in **Settings > Writing**, save, and then delete the old one.
## Keep Your Taxonomy Lean
The most common category problem is not too few but too many. A sprawling list of thinly used categories confuses readers and dilutes your archive pages. A few guidelines keep things tidy:
- **Treat categories like the sections of a publication.** Most sites need only a handful, often between three and ten. If you cannot picture a category sitting in your main menu, it is probably a tag.
- **Do not create a category you will use only once.** A category that will only ever hold one or two posts adds a near-empty archive page for no benefit. Use a tag instead.
- **Assign one, occasionally two, categories per post.** Filing a post under five categories tells readers and search engines that it belongs everywhere, which is the same as belonging nowhere.
- **Let tags carry the detail.** Specific topics, product names, and recurring themes belong in tags, keeping the category list short and stable.
- **Review the Count column occasionally.** Categories with a count of zero or one are candidates to merge into a broader category or convert to a tag.
## Categories, Internal Linking and Site Structure
Categories are not just an admin convenience. Each one generates an **archive page** at an address like `yourdomain.com/category/tutorials/` that automatically lists every post in that category, newest first. That has real value for both visitors and search engines:
- **They are ready-made internal links.** A small, well-chosen set of categories creates a clear map of your content that both readers and search-engine crawlers can follow from one related post to the next. A bloated set scatters that link value across dozens of half-empty pages.
- **They belong in your navigation.** Add your main category archives to a menu under **Appearance > Menus** (or the site editor's navigation block on block themes) so visitors can browse a whole section in one click.
- **The category base is adjustable.** The `/category/` segment in those URLs can be changed under **Settings > Permalinks** using the **Category base** field. As with slugs, only change it deliberately, because it alters the address of every category archive at once and will break existing links unless you add redirects.
The practical takeaway is that a lean, logical category structure is one of the simplest internal-linking improvements available in WordPress, and it costs nothing but a little planning.
## Before a Big Reorganisation: Back Up First
Renaming a single category is trivial and needs no special care. Merging categories, bulk-editing hundreds of posts, or changing slugs and the category base across a large site touches many database records at once, and those changes are not undone with a single click. Before any large taxonomy reorganisation, take a full backup of the site (files and database) so you can restore quickly if the result is not what you expected. If your site is on a Noiz managed hosting plan, backups are part of the service, so you can restore a recent copy if a bulk change goes awry; take a fresh backup immediately before you begin so the restore point is as current as possible.
## Troubleshooting
- **Symptom**: after renaming a category, its links still show the old name in the URL. That is expected and correct. The URL is built from the slug, which renaming the name leaves unchanged. Change the slug only if you truly want a new address, and add a redirect if you do.
- **Symptom**: a merge left posts in both the old and new categories. Bulk Edit only adds categories, it never removes them, so the old category is still attached until you delete it. Finish the merge by deleting the source category, as described above.
- **Symptom**: posts vanished into "Uncategorized" after deleting a category. Those posts belonged only to the deleted category, so WordPress reassigned them to the default. To move them where you intended, filter Posts by the default category, bulk-edit them into the right category, and (if needed) remove them from the default by editing each one.
- **Symptom**: a category cannot be deleted; the Delete option is missing. It is set as the Default Post Category. Choose a different default under **Settings > Writing**, save, then delete it.
- **Symptom**: the same topic appears as both a category and a tag, splitting your posts across two archive pages. Decide which role fits better, then use the **Categories and Tags Converter** under **Tools > Import** to consolidate onto one, and delete the duplicate.
- **Symptom**: category archive pages return "not found" after changing the category base or a slug. The address changed but old links still point at the previous one. Confirm the new address works, then add redirects from the old paths, and re-save **Settings > Permalinks** to refresh the rewrite rules.
If you get stuck, open a support ticket with the Noiz support team and include your domain name, the categories involved, and what you are trying to achieve. If you are planning a large reorganisation on a busy site, mention it before you start so a technician can confirm a recent backup is in place first.
# How to Manually Install WordPress
Source: https://docs.noiz.ie/wordpress/how-to-manually-install-wordpress/
This guide walks you through installing WordPress by hand on your Noiz hosting: downloading the software, creating a database and database user, uploading the files, and running the browser-based setup that WordPress calls its famous five-minute install. A manual install is the alternative to the one-click app installer built into most hosting panels. It takes a few more steps, but it gives you a completely clean site running the exact core version you chose, with nothing bundled in that you did not ask for. This article is written for Noiz clients who are comfortable moving files with an SFTP client or the panel File Manager, and it uses generic example names such as `yourdomain.com` that you replace with your own.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [How to install WordPress (WordPress Developer Docs)](https://developer.wordpress.org/advanced-administration/before-install/howto-install/): the canonical reference for the manual install, including the detailed and basic step lists.
- [Editing wp-config.php (WordPress Developer Docs)](https://developer.wordpress.org/advanced-administration/wordpress/wp-config/): the full reference for every directive in the configuration file, including the table prefix and the many optional constants.
- [Requirements (WordPress.org)](https://wordpress.org/about/requirements/): the current server requirements WordPress recommends, kept up to date with each release.
- [Download WordPress (WordPress.org)](https://wordpress.org/download/): the official download page, and the only place you should ever get the core files.
## Prerequisites
- A Noiz hosting plan with the domain already pointed at your account, so that visiting the domain reaches your web space rather than a holding page.
- Access to your hosting control panel. Noiz runs **Plesk** on the South African platform (neo.noiz.co.za), **DirectAdmin** on the Ireland platform, and **ISPConfig**. The panel is where you create the database and can reach the File Manager and phpMyAdmin.
- Either an SFTP client (such as any modern file-transfer program) with your SFTP credentials, or comfort using the panel File Manager, for uploading the files.
- A server that meets the current WordPress requirements. Noiz hosting already ships with a supported **PHP 8.3 or newer** and a compatible **MySQL 8.0** or **MariaDB 10.11** database, and every Noiz site is served over HTTPS, which WordPress now expects. You do not need to arrange any of this yourself.
## When to Install Manually, and When a One-Click Installer Is Fine
Before you spend the extra effort, it is worth being honest about the trade-off. Most hosting panels include a one-click installer (an app installer or a WordPress toolkit) that provisions a database, drops in the files, and finishes the setup for you in under a minute. For a great many sites that is the right choice, and there is no prize for doing it the long way.
A manual install earns its keep when you want control the automated tool does not give you:
- **A genuinely clean site.** Some one-click tools pre-select a handful of plugins or a particular theme, or leave behind their own management plugin. A manual install gives you nothing but WordPress core, so you decide from an empty slate what goes on.
- **An exact, current core version.** Downloading straight from WordPress.org guarantees you are installing the latest release the moment it ships, rather than whatever version the installer's catalogue happens to have cached.
- **Installing into a subdirectory, or giving WordPress its own folder.** If you want WordPress to live at `yourdomain.com/blog/`, or to keep the core files tidily in their own directory while the site still answers at the root, a manual install makes that straightforward.
- **Reusing an existing database, or restoring a site.** If you are rebuilding from a backup or attaching WordPress to a database you already have, you are working by hand anyway.
- **Learning how the pieces fit.** Once you have done this once, the errors that take WordPress sites offline (a wrong database password, a mis-typed host, a permissions problem) stop being mysterious, because you know exactly which file holds which setting.
If none of those apply and you simply want a blog online quickly, the one-click installer in your panel is a perfectly good choice, and Noiz support can point you to it. If you are on a **managed plan**, you can also ask the Noiz support team to perform the manual install for you and hand over the finished site.
## Step 1: Download WordPress
Get the software only from the official source, [wordpress.org/download](https://wordpress.org/download/). The download is a single ZIP archive; the current release, WordPress 7.0.2, is served from `https://wordpress.org/latest.zip`. Never install a copy from a third-party site or a bundle of unknown origin, because that is one of the commonest ways a site is compromised before it even launches.
You have two sensible approaches:
- **Download to your own computer, then upload.** Save the ZIP, unzip it locally (you will get a folder named `wordpress` containing files such as `index.php`, `wp-admin`, `wp-content`, `wp-includes`, and `wp-config-sample.php`), and upload the files as described in Step 3.
- **Download straight onto the server.** If your File Manager offers a way to fetch a URL, or you use SFTP alongside a shell where fetching is available, you can pull `latest.zip` directly into your web space and extract it there, which is much faster than uploading thousands of small files one at a time.
Extracting on the server, where possible, is the quicker route, because unpacking one ZIP takes seconds while transferring the roughly two thousand individual files WordPress contains over SFTP can take several minutes.
## Step 2: Create a Database and Database User
WordPress stores all of your content, settings, users, and comments in a database. Before it can run, you need an empty MySQL or MariaDB database and a database user that has full rights over it. On Noiz shared hosting the reliable place to create both is your hosting panel, not phpMyAdmin: on shared platforms the phpMyAdmin login usually lacks the privilege to create new users, whereas the panel creates the database and the user together and grants the rights for you.
### Creating the database in your panel
- **Plesk** (South African platform, neo.noiz.co.za): open **Databases**, choose **Add Database**, give it a name, then add a database user with a strong password at the same time.
- **DirectAdmin** (Ireland platform): open **MySQL Management** and **Create New Database**; DirectAdmin creates the database and a user with full rights in one step.
- **ISPConfig**: under **Sites**, open **Database** and add a new database, creating its database user at the same time.
Whichever panel you use, write down four things, because you will type them into WordPress in the next step:
1. The **database name**.
2. The **database user**.
3. The **password** you set for that user.
4. The **database host**, which on Noiz shared hosting is almost always `localhost`. Check what the panel shows when the database is created, because a small number of setups use a different host name or a specific port, and getting this wrong is the single most common cause of the dreaded database-connection error.
**A gotcha worth knowing:** shared-hosting panels usually prepend your account name to whatever you type, so a database you name `wpsite` may actually be created as `youracct_wpsite`, and the same for the user. Copy the full final names exactly as the panel displays them, not the short names you typed.
Use a database character set of `utf8mb4` if the panel gives you the choice, as that is what modern WordPress expects and what lets it store the full range of characters and emoji correctly.
phpMyAdmin, reachable from the panel, is still useful here: after you create the database you can open it to confirm it exists and is empty, and later to import content or take a look inside. For a fresh install, though, it is the panel that does the creating.
## Step 3: Upload the WordPress Files
Now put the WordPress files into the correct place in your web space. On Noiz hosting your site is served from a document root, typically a folder such as `httpdocs` on Plesk or `public_html` on DirectAdmin; the panel File Manager opens in the right place, and your SFTP account lands there or nearby.
### Root install (the usual case)
To have WordPress answer at `yourdomain.com`, you want the *contents* of the `wordpress` folder in your document root, not the folder itself. This is the mistake almost everyone makes the first time: if you upload the `wordpress` folder whole, your site ends up living at `yourdomain.com/wordpress/`, which is not what you wanted. So the document root should directly contain `index.php`, `wp-admin`, `wp-content`, `wp-includes` and the rest, with no extra `wordpress` layer wrapping them.
### Subdirectory install
If you genuinely want WordPress in a subfolder, for example a blog at `yourdomain.com/blog/`, then create a `blog` folder in your document root and upload the contents of the `wordpress` folder into that instead. The site will then run at that subpath.
### A note on file permissions
Uploads through the panel File Manager or a normal SFTP account generally arrive with sensible permissions already, so you rarely need to touch them. If you do end up setting them, the safe convention is `644` for files and `755` for directories. Never set anything to `777`: fully world-writable files and folders are a security hole, not a fix, and if something will not write, the real cause is almost always ownership rather than a need to open permissions wide. On a managed plan, ask Noiz support rather than guessing.
## Step 4: Run the Setup and Create wp-config.php
WordPress keeps its database credentials and a handful of core settings in a single file, `wp-config.php`, which does not exist in a fresh download. There are two ways to create it, and the first is easier.
### Option A: Let WordPress build it for you (recommended)
Open your site in a browser over HTTPS, for example `https://yourdomain.com`. Because there is no `wp-config.php` yet, WordPress runs its `setup-config.php` routine and offers to create the file. After a language prompt it asks for the four database details you noted in Step 2: the database name, the database user, the password, and the database host (leave this as `localhost` unless your panel told you otherwise). There is also a **table prefix** field, covered below. WordPress tries to write the finished `wp-config.php` for you; if the server does not let it write the file directly, it shows you the exact contents to copy into a new `wp-config.php` yourself, which you can do in the File Manager.
### Option B: Edit the sample file by hand
If you prefer to prepare everything before visiting the site, rename `wp-config-sample.php` to `wp-config.php` and edit it. Set the four core values to match what you created:
```
define( 'DB_NAME', 'youracct_wpsite' );
define( 'DB_USER', 'youracct_wpuser' );
define( 'DB_PASSWORD', 'your-strong-password' );
define( 'DB_HOST', 'localhost' );
```
Replace each example value with your real one. Keep the single quotes, and if your password happens to contain a quote or a backslash you will need to escape it, which is a good reason to avoid those particular characters when you set the password.
### The table prefix
Just below the database settings sits the table prefix, which WordPress ships as `wp_`:
```
$table_prefix = 'wp_';
```
You may change it to something like `wp7x_` before installing, and some people do so on the grounds that it makes automated attacks slightly less predictable. Be clear-eyed about it: a custom prefix is a very small obfuscation, not a real security control, and it will not stop a determined attacker. It is optional. If you do want it, set it now, before the install runs, because changing it on a live site is fiddly. For genuine hardening, follow the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/) once the site is up.
### The authentication keys and salts
Further down, `wp-config.php` has a block of eight lines for authentication unique keys and salts, which WordPress uses to secure the cookies that keep you logged in. A fresh sample file has placeholder text here that you must replace with real random values. The official generator lives at `https://api.wordpress.org/secret-key/1.1/salt/`: open it in a browser, copy the whole block it returns, and paste it over the eight placeholder lines. If you used Option A above, WordPress fetches fresh salts for you automatically, so you can skip this. Never leave the placeholder values in place, and never reuse another site's salts.
## Step 5: Run the Famous Five-Minute Install
With `wp-config.php` in place and pointing at a working database, visit `https://yourdomain.com` again (or `https://yourdomain.com/wp-admin/install.php` directly). WordPress now runs its install script, which creates all the database tables and your first account. Because you are visiting over HTTPS, WordPress records your site address as an `https://` URL from the start, which is exactly what you want and saves a common post-launch headache.
The install screen asks for a small set of details:
- **Site Title**: the name of your site. You can change it later under **Settings > General**, so do not overthink it.
- **Username**: your administrator login name. Choose something other than `admin`, since `admin` is the first name every password-guessing bot tries. This one cannot be changed as easily later, so pick it deliberately.
- **Password**: WordPress suggests a strong random password. Accept it and store it in a password manager rather than weakening it. A weak admin password on a public site is asking for trouble.
- **Your Email**: used for password resets and important notices, so make sure it is an address you actually monitor.
- **Search engine visibility**: ticking **Discourage search engines from indexing this site** asks search engines to stay away while you build. It is a request, not a wall, but it is sensible during setup. The vital part is to remember to untick it once you launch, because a live site left with this ticked will struggle to appear in search results.
Click **Install WordPress**. In a few seconds WordPress confirms success and offers a login link. Your site is now installed.
## After the Install: First Login and Next Steps
Log in at `https://yourdomain.com/wp-admin` with the username and password you just set; the general guide to [logging in to the WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) covers this and the small things that trip people up. A sensible short list for a brand-new site:
- Under **Settings > General**, confirm the **WordPress Address** and **Site Address** both begin with `https://`.
- Under **Settings > Reading**, check that **Discourage search engines** is unticked if the site is meant to be live.
- Under **Settings > Permalinks**, choose a readable structure such as **Post name**.
- Work through the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/) before you invite anyone to the site.
## Troubleshooting
- **Symptom**: **Error establishing a database connection**. One of the four database values in `wp-config.php` is wrong. Re-check the database name, user, and password against what the panel shows (remembering the account-name prefix), and confirm the host is `localhost` unless your panel specified otherwise. A freshly reset user password that was never saved into `wp-config.php` is a frequent cause.
- **Symptom**: your site loads at `yourdomain.com/wordpress/` instead of the root. You uploaded the `wordpress` folder itself rather than its contents. Move the files up one level so that `index.php` sits directly in your document root, then reload.
- **Symptom**: the install screen says WordPress is **already installed**. The database you pointed at already contains WordPress tables. Use an empty database, or if you truly intend to start over, drop the existing tables in phpMyAdmin first (this deletes their content, so be sure).
- **Symptom**: you see the raw contents of `wp-config.php` as text, or a blank white page. PHP is not running the file, which usually means the file was uploaded to the wrong place or with a wrong extension, or the core files are incomplete. Confirm the full set of WordPress files is present in the document root and re-upload if the transfer was interrupted.
- **Symptom**: WordPress cannot write `wp-config.php` during setup. This is normal on some configurations. Copy the block of text WordPress displays, create `wp-config.php` yourself in the File Manager, paste it in, and continue.
- **Symptom**: you have lost the admin password you set during the install. You can reset it directly in the database by following [how to reset a WordPress admin password via phpMyAdmin](/wordpress/how-to-reset-a-wordpress-admin-password-via-phpmyadmin/).
If a manual install stalls at any point, or you would rather have it done for you, open a support ticket with the Noiz support team. Tell them your domain, which platform your account is on, and where you have got to, and if you are on a managed plan a technician can complete the install, create the database, and hand you a working site to log in to.
# How to Manually Install a WordPress Plugin From a Zip File
Source: https://docs.noiz.ie/wordpress/how-to-manually-install-a-wordpress-plugin-from-a-zip-file/
Not every plugin lives in the WordPress.org plugin directory. Premium plugins bought from a developer, plugins built for you by an agency, beta builds, and older versions you need to roll back to all arrive the same way: as a `.zip` file. This guide covers installing one of those on a WordPress site hosted with Noiz, by uploading the zip through the WordPress dashboard.
If the plugin you want is in the public directory, you do not need any of this. Search for it and install it in two clicks instead, as described in [How to Install a WordPress Plugin](/wordpress/how-to-install-a-wordpress-plugin/). Come back here when there is nothing to search for, only a file you have downloaded.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Manage Plugins, manual plugin installation](https://wordpress.org/documentation/article/manage-plugins/#manual-plugin-installation-1), the upstream reference for the screens shown here
- [Managing Plugins, advanced administration](https://developer.wordpress.org/advanced-administration/plugins/plugins/), covering the filesystem layout and the `wp-content/plugins` directory
- [Common WordPress Errors](https://wordpress.org/documentation/article/common-wordpress-errors/), for the upload and memory errors referenced in Troubleshooting
## Prerequisites
- A WordPress site on your Noiz hosting account, and an administrator login to its dashboard.
- The plugin's `.zip` file already downloaded to your computer. Do not unzip it.
- A current backup, or at least the confidence that you can restore one. Any plugin can take a site down on activation.
## Before You Upload: Check the Zip
Most failed manual installs fail because of the archive, not because of WordPress. Two quick checks save a lot of guesswork.
**The plugin folder must sit at the root of the zip.** Open the file and you should see a single folder, for example `my-plugin/`, containing a PHP file with the plugin header inside it. If instead you see `my-plugin/my-plugin/`, or the PHP files sitting loose at the top level, WordPress will either reject the archive or install something that never appears in the plugins list.
**Do not re-zip a folder unless you have to.** Upload the file exactly as the developer supplied it. Compressing a folder yourself, particularly on macOS, adds a `__MACOSX` directory and `.DS_Store` files, and it is easy to end up with the nesting problem above. If you did unzip it to look inside, download a fresh copy rather than re-compressing.
Archives pulled from a GitHub repository using **Download ZIP** deserve a note of their own. They unpack to a folder named after the branch, such as `my-plugin-main`, which means WordPress treats each new download as a separate plugin rather than an update to the last one. Prefer the developer's official release zip where one exists.
## Step 1: Open the Add Plugins Screen
1. Log in to your WordPress dashboard at `yourdomain.com/wp-admin`, replacing `yourdomain.com` with your own domain.
2. In the left-hand menu, hover **Plugins** and click **Add New Plugin**.

On WordPress 6.3 and earlier this menu item was simply **Add New**, which is what the screenshot above shows. It was renamed to **Add New Plugin** in WordPress 6.4 to make it clearer at a glance. Either label takes you to the same **Add Plugins** screen, and everything that follows is unchanged.
## Step 2: Upload the Zip File
1. Click **Upload Plugin**, the button at the top of the screen beside the **Add Plugins** heading.
2. Click **Choose File**, labelled **Browse** in older versions and in some browsers, then select the plugin's `.zip` file.
3. Click **Install Now**.

WordPress uploads the archive, unpacks it into `wp-content/plugins`, and reports progress line by line. A successful run ends with **Plugin installed successfully**.
If the plugin is already installed, WordPress does not silently overwrite it. Since version 5.5 it shows a comparison of the current and uploaded versions, then offers **Replace current with uploaded**. That is the supported way to apply a manual update or to roll back to an earlier build, and it is safer than deleting the plugin first, because deleting a plugin can also remove its stored data.
## Step 3: Activate the Plugin
Installing only puts the files in place. The plugin does nothing until you switch it on.
1. Click **Activate Plugin** on the results screen.

If you navigated away before activating, the plugin is still installed. Go to **Plugins** in the sidebar, find it in the list, and click **Activate** underneath its name.
After activation, most plugins add themselves to the dashboard. Look for a new top-level item in the left-hand menu, or a new entry under **Settings**, **Tools** or **Appearance**. Some also show a setup wizard or a prompt to enter a licence key. Premium plugins usually will not receive updates until that key is entered, so do it now rather than discovering months later that the plugin has been frozen at the version you uploaded.
### On a Multisite Network
Plugins are uploaded from the **Network Admin** dashboard, not from an individual site. After installing, you choose either **Network Activate**, which turns the plugin on everywhere, or leave it inactive and let individual site administrators activate it themselves, if the network settings permit that.
## The Security Part, Read This Once
Uploading a zip bypasses every check that the WordPress.org directory applies. A plugin runs with the same privileges as WordPress itself, which means it can read your database, write files, and send mail from your domain. There is no sandbox.
Install only from the developer who wrote the plugin, or from a marketplace you have an account with. Be particularly wary of "nulled", "free premium" or "GPL club" copies of commercial plugins. Backdoors in those are common, and the cost of cleaning up a compromised site is far higher than the licence you avoided paying for.
Two habits worth keeping: check when the plugin was last updated before you trust it with a live site, and remove plugins you have stopped using rather than leaving them deactivated, since the code is still on disk either way.
## Alternative: Upload Over SFTP or File Manager
If the dashboard upload will not work, for example because the file is too large or the site is already in a broken state, you can place the plugin directly on the server.
1. Unzip the plugin on your computer, so you have a folder such as `my-plugin`.
2. Connect to your Noiz hosting account with SFTP, or open the File Manager in your control panel.
3. Navigate to the WordPress installation, then into `wp-content/plugins`.
4. Upload the whole folder into that directory.
5. Back in the WordPress dashboard, go to **Plugins**. The plugin now appears in the list. Click **Activate**.
Upload the folder, not the zip. WordPress does not unpack archives it finds on disk. If you prefer, upload the zip using File Manager and use its own extract function in place, then delete the archive afterwards.
## Troubleshooting
**Symptom: "The uploaded file exceeds the upload\_max\_filesize directive in php.ini".** The plugin zip is larger than the PHP upload limit for that site. Raise `upload_max_filesize` and `post_max_size` in the PHP settings for the domain in your Noiz control panel, setting `post_max_size` at least as high as `upload_max_filesize`, then retry. If you would rather not change the limits, use the SFTP method above instead.
**Symptom: "The link you followed has expired".** Despite the wording, this is almost always the same size limit, hit as the upload exceeds `post_max_size` or `max_execution_time`. Treat it exactly as the error above.
**Symptom: "Destination folder already exists".** A plugin with that folder name is already installed. Use the **Replace current with uploaded** option WordPress offers, or deactivate and delete the existing copy first if you genuinely want a clean install, accepting that its settings may go with it.
**Symptom: "The package could not be installed. No valid plugins were found."** The archive structure is wrong, or the main PHP file is missing its plugin header. Re-check the zip against the guidance at the top of this article, and confirm you downloaded the plugin itself rather than a documentation bundle or a full product package that contains the plugin zip inside it.
**Symptom: WordPress asks for FTP connection details before installing.** WordPress could not write to the plugins directory as the web server user, so it falls back to asking for credentials. On Noiz hosting this normally indicates ownership or permission drift on `wp-content`, often after a manual file restore. Open a ticket rather than entering credentials into the prompt, and Noiz will correct the ownership.
**Symptom: white screen or a fatal error immediately after activating.** The plugin is incompatible with your PHP or WordPress version, or it conflicts with something already installed. Rename the plugin's folder in `wp-content/plugins` over SFTP or File Manager, for example to `my-plugin-off`. WordPress deactivates any plugin whose folder it cannot find, and the site comes straight back. Then check the plugin's stated PHP and WordPress requirements before trying again.
**Symptom: the plugin installs but never appears in the Plugins list.** It has been unpacked one level too deep, giving `wp-content/plugins/my-plugin/my-plugin/`. Move the inner folder up a level over SFTP so the PHP files sit one directory below `plugins`, then refresh the Plugins screen.
## Need a Hand
If an upload keeps failing, or a plugin activation has taken the site down and you would rather not go digging through the filesystem, open a ticket in the Noiz client area. Include the site's domain, the plugin name and version, and the exact error text WordPress showed. On managed plans Noiz will install the plugin, confirm it activates cleanly, and restore from backup first if the site is already down.
# How to Manually Install a WordPress Theme From a ZIP File
Source: https://docs.noiz.ie/wordpress/how-to-manually-install-a-wordpress-theme-from-a-zip-file/
When you buy a premium theme, download one from a marketplace, or receive a theme built for you by a designer, it arrives as a ZIP file rather than something you can pick from a list. This guide shows you how to upload that ZIP straight into your WordPress site on Noiz hosting, activate it, and avoid the handful of errors that catch most people out the first time.
This is sometimes called a **manual theme install**, a **theme upload**, or **installing a theme from a ZIP**. They all describe the same thing. If instead you want to browse the free themes built into WordPress, that is a different route: see [How to Install a New WordPress Theme](/wordpress/how-to-install-a-wordpress-theme-from-the-dashboard/).
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Using Themes](https://wordpress.org/documentation/article/using-themes/): the full WordPress guide to finding, installing and switching themes.
- [Appearance Themes Screen](https://wordpress.org/documentation/article/appearance-themes-screen/): what every button and panel on the Themes screen does.
- [Child Themes](https://developer.wordpress.org/themes/advanced-topics/child-themes/): why a child theme is the correct place for your customisations.
- [Block Themes](https://developer.wordpress.org/themes/block-themes/): how block themes differ from classic themes, and what changes in the admin once one is active.
- [Manually Installing and Updating Themes](https://developer.wordpress.org/advanced-administration/upgrade/themes/): the file-level method, for when the browser upload is not an option.
## Prerequisites
- An administrator account on the WordPress site. Editors and authors do not see the **Appearance** menu. If you are not sure how to reach the admin area, see [How to Log In to the WordPress Dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- The theme ZIP file saved on your computer, from a source you trust.
- A recent backup of the site, or at least a note of which theme is currently active. Switching themes changes how every page looks, and it is far quicker to switch back than to rebuild.
## Check You Have the Right ZIP First
This single check prevents the most common failure. Premium theme purchases usually hand you a large bundle ZIP that contains the theme, a child theme, the licence, documentation, and sometimes a set of demo files. WordPress cannot install that bundle. It only accepts the theme ZIP itself.
Open the ZIP on your computer and look inside:
- **Correct.** The ZIP contains a single folder, and inside that folder are files including `style.css`, `index.php` or `templates/`, and `functions.php`. This is the file to upload.
- **Wrong.** The ZIP contains items such as `documentation/`, `licensing/`, `psd/`, `demo-content/` and a smaller ZIP named after the theme. Upload that inner ZIP instead, not the bundle.
Uploading the bundle is what produces the error *"The package could not be installed. The theme is missing the style.css stylesheet."* The upload worked perfectly; the file simply was not a theme.
On the trust question: only install themes from the WordPress.org directory, the developer who wrote them, or an established marketplace. Cracked or "nulled" copies of paid themes are one of the most reliable ways to get a site infected, because the code is modified before it is redistributed and the backdoor survives every theme update. See the [WordPress Security Checklist](/wordpress/wordpress-security-checklist/) for the wider picture.
## Upload and Activate the Theme
1. Log in to the WordPress dashboard as an administrator.
2. In the left-hand menu, go to **Appearance** and click **Themes**. 
3. Click **Add New Theme** at the top of the screen. On WordPress versions before 6.4 the same button is labelled simply **Add New**. 
4. On the Add Themes screen, click **Upload Theme**. The theme directory listing is replaced by a small upload panel. 
5. Click **Choose File**, select the theme ZIP from your computer, then click **Install Now**. Depending on your browser the file button may read **Browse** or **Choose file**; it does the same job. 
6. Wait for the upload and extraction to finish. WordPress prints a short progress log ending in *"Theme installed successfully."* Click **Activate** to make it the live theme, or **Live Preview** to see it applied to your content without changing the public site. 
The theme is now installed and, if you clicked **Activate**, live. It also appears from now on under **Appearance > Themes** alongside the others, so you can switch back at any time.
### Installing a Child Theme
If the download included a child theme, the order matters. Install and keep the parent theme, install the child theme second, and activate *the child*. Activating a child theme without its parent present gives the error *"The parent theme is missing. Please install the parent theme."*
Do not delete the parent afterwards, and do not activate it in place of the child. The parent supplies almost all of the code; the child only holds your changes, which is precisely what keeps those changes safe when the parent is updated. If you are planning to customise anything at all, read [How to Safely Edit Your WordPress Theme](/wordpress/how-to-safely-edit-your-wordpress-theme/) before you start editing files.
### Replacing a Theme You Already Have
Uploading a ZIP for a theme that is already installed no longer fails outright. WordPress compares the two and shows a table of the current version against the uploaded version, with a **Replace current with uploaded** button. That is the supported way to apply a manual update for a paid theme that has no automatic update channel.
Check the version numbers in that table before you confirm. It is easy to have downloaded an older ZIP than the copy already running, and the replace step will happily downgrade the site.
## When the Upload Will Not Go Through
Large multipurpose themes routinely ship as 20 MB to 80 MB ZIP files, which is bigger than the default PHP upload limit on many WordPress installs. Two errors point at this:
- *"The uploaded file exceeds the upload\_max\_filesize directive in php.ini"*: the file is larger than the per-file upload limit.
- *"The link you followed has expired"*: misleading, but on a theme or plugin upload it almost always means the request exceeded `post_max_size` or `max_execution_time`.
The current limit is shown on the upload panel itself, and again under **Tools > Site Health > Info > Media Handling**. Raise the PHP limits for the domain in your hosting control panel, or contact Noiz support and the team will lift them for you. As a guide, set `upload_max_filesize` and `post_max_size` comfortably above the size of the ZIP, and give `max_execution_time` at least 300 seconds for a big theme on a slow connection.
### Uploading the Theme by File Manager or SFTP Instead
If the browser upload keeps timing out, or the ZIP is very large, put the files on the server directly. This produces exactly the same result, because the browser upload is only a wrapper around the same operation.
1. Open the file manager in your hosting control panel, or connect over SFTP.
2. Navigate to the site's `wp-content/themes/` directory.
3. Upload the theme ZIP into that directory and extract it there. You should end up with one new folder, for example `wp-content/themes/yourtheme/`, containing `style.css` at its top level.
4. Delete the ZIP once it has been extracted, so it is not left sitting in a web-accessible directory.
5. Back in WordPress, go to **Appearance > Themes**. The theme now appears in the list, ready to activate.
The one thing to watch is a doubled folder. If extracting produces `wp-content/themes/yourtheme/yourtheme/style.css`, WordPress will not see the theme. Move the inner folder up one level and remove the empty wrapper.
## After You Activate
Switching themes changes presentation, not content. Your posts, pages, media and users are untouched. What does move around is anything the previous theme was responsible for displaying:
- **Menus lose their positions.** The menus themselves survive, but each theme defines its own menu locations. Reassign them under **Appearance > Menus**, or in the Site Editor for a block theme.
- **Widgets may disappear from view.** Themes define their own widget areas, and content in an area the new theme does not have is parked in **Inactive Widgets** rather than deleted.
- **The admin menu changes shape.** Activating a block theme replaces **Appearance > Customise**, **Widgets** and **Menus** with a single **Editor** entry, because headers, footers and menus are edited as blocks instead. This is expected, not a fault.
- **Some settings are theme-specific.** Logo, colours, homepage layout and typography usually live with the theme, so expect to set them again.
- **Shortcodes from the old theme stop rendering.** If the previous theme provided shortcodes or custom blocks, the raw text appears in your content once it is gone. Check your key pages after switching.
Clear any caching plugin and any server-side or CDN cache once you are happy, then load the site in a private browsing window to see what visitors see rather than a cached copy.
Old themes you are no longer using are worth removing, because an inactive theme still receives no attention and still ships code that can carry a vulnerability. Keep the active theme, its parent if it has one, and one current default theme such as Twenty Twenty-Five as a fallback for troubleshooting. See [How to Delete a WordPress Theme](/wordpress/how-to-delete-a-wordpress-theme/).
## Troubleshooting
**Symptom**: "The package could not be installed. The theme is missing the style.css stylesheet." You uploaded the wrong ZIP, almost always the marketplace bundle rather than the theme. Open the ZIP and upload the inner theme file. The same message appears if you re-zipped a theme folder in a way that buried `style.css` one level too deep.
**Symptom**: "Sorry, you are not allowed to install themes on this site." Either your account is not an administrator, or the install is a multisite network where themes are installed by the network administrator only. On a single site, the other cause is `DISALLOW_FILE_MODS` being set in `wp-config.php`.
**Symptom**: WordPress asks for FTP connection details before it will install anything. WordPress could not write to the themes directory as the web server user, so it falls back to asking for credentials. On Noiz hosting this should not happen; contact support rather than typing credentials into that form, because it points at file ownership or permissions needing correction.
**Symptom**: "The parent theme is missing. Please install the parent theme." You installed only the child theme. Install the parent, leave it installed, then activate the child.
**Symptom**: the theme installs but the site shows a white screen or a critical error after activation. The theme needs a newer PHP or WordPress version than the site is running, or it conflicts with a plugin. WordPress emails a recovery link to the admin address; use it, or switch back to a default theme, then check the theme's stated requirements. There is more on this in [How to Fix Common WordPress Errors](/wordpress/how-to-fix-common-wordpress-errors/).
**Symptom**: the new theme looks nothing like the demo. That is normal. Demos are built with the theme plus its demo content, its required plugins and a page builder configuration. Import the demo content through the theme's own setup wizard if it has one, and accept that a demo import will add pages, menus and settings to your site.
**Symptom**: the theme uploaded fine but does not appear under **Appearance > Themes**. Check the folder structure on the server. A doubled folder, or a theme extracted somewhere other than `wp-content/themes/`, is the usual reason.
If the upload will not complete, the site breaks after activation, or you would simply rather have someone else handle the theme change, contact Noiz support with the site address and the theme ZIP and the team will install it for you.
# How to Manually Reinstall WordPress Core
Source: https://docs.noiz.ie/wordpress/how-to-manually-reinstall-wordpress-core/
This guide shows you how to replace the core program files that run WordPress with a clean, official copy, without touching your posts, images, themes, plugins or settings. Reinstalling core, sometimes called replacing the core files or dropping in a fresh copy of WordPress, is one of the most effective and least understood repairs available to a site owner. It fixes a site whose engine has been damaged, whether by a half-finished update, a corrupted file, or malware that has written itself into a core file, and it does so without the risk people fear, because done correctly it leaves everything that makes your site *yours* completely alone. This article explains exactly which parts of WordPress you are replacing and which parts you must never overwrite, then walks through three safe ways to do it on Noiz hosting: the one-click reinstall in the dashboard, the precise WP-CLI method over SSH, and the manual file replacement over SFTP or your control panel's File Manager.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Updating WordPress (WordPress Documentation)](https://wordpress.org/documentation/article/updating-wordpress/): the official Manual Update procedure, whose file-replacement steps are the same ones used to reinstall core, including the explicit warnings about `wp-content` and `wp-config.php`.
- [Upgrading WordPress, Extended Instructions (WordPress Developer Resources)](https://developer.wordpress.org/advanced-administration/upgrade/upgrading/): the long-form version, with the full list of files and folders never to delete and detailed troubleshooting.
- [wp core download (WP-CLI Command Reference)](https://developer.wordpress.org/cli/commands/core/download/): the exact syntax and options for downloading core files from the command line, including `--version`, `--skip-content` and `--force`.
- [wp core verify-checksums (WP-CLI Command Reference)](https://developer.wordpress.org/cli/commands/core/verify-checksums/): the command that tells you precisely which core files differ from WordPress.org's official copies, so you know whether a reinstall is even needed.
- [WordPress Release Archive (WordPress.org)](https://wordpress.org/download/release-archive/): where to download the exact zip of any WordPress version, which you need if you want to repair an older install without also updating it.
## Prerequisites
- A recent, restorable backup of your site, both files and database. This is non-negotiable and is covered in its own section below.
- A way to reach your site's files. On Noiz hosting that means either SFTP with your hosting credentials, or the File Manager built into your control panel (Plesk on the South African platform, DirectAdmin on the Irish platform). The WP-CLI method additionally needs SSH access.
- To use the dashboard method, you need to be able to [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/). If the damage has locked you out, use the WP-CLI or manual method instead, neither of which needs a working dashboard.
## What "Reinstalling Core" Actually Means
The confusion that stops people reinstalling core, and the fear that they will wipe their site, both come from not knowing what WordPress is made of. It is worth two minutes to get this straight, because once you can see the parts clearly the whole operation becomes obvious and safe. Every WordPress install is really three separate things living in the same folder:
- **The core program, which is what you reinstall.** This is WordPress itself, the engine. It lives in two folders, `wp-admin` and `wp-includes`, plus a set of loose `.php` files in the root such as `index.php`, `wp-login.php`, `wp-settings.php` and `wp-load.php`. These files are identical on every WordPress site in the world running the same version. They contain none of your content and none of your settings, which is exactly why they are safe to throw away and replace: a fresh copy from WordPress.org is a perfect substitute.
- **Your content and customisation, which you never touch.** This is the single folder `wp-content`, and it holds everything that is unique to your site: your themes, your plugins, and the `uploads` folder with every image and media file you have added. Nothing in here is part of core and nothing here is replaced by a reinstall.
- **Your configuration and your data, which you also never touch.** The file `wp-config.php` in the root holds your database name, username, password and secret keys. The `.htaccess` file holds your permalink and redirect rules. And your actual posts, pages, users, comments and settings live not in any file at all but in your MySQL database. A core reinstall changes none of these.
So reinstalling core swaps out the first group and leaves the second and third groups exactly as they are. You are replacing the engine while keeping the bodywork, the fuel and the number plate. This is why it is such a clean repair: a damaged engine is a solved problem, because a brand-new, guaranteed-genuine engine is a free download away, and dropping it in cannot disturb anything you care about.
## When to Reinstall Core, and When It Will Not Help
Reinstalling core is the right tool for a specific class of problem: the core files themselves are wrong. That happens more often than you might think.
- **A failed or interrupted update.** If an update was cut short, by a timeout, a dropped connection, or a permissions error, you can be left with a mismatched set of core files, half old and half new. The classic sign is a site stuck on "Briefly unavailable for scheduled maintenance", which is caused by a leftover `.maintenance` file, often alongside a broken update. A reinstall of the matching version puts a consistent set of files back in place.
- **A white screen or fatal error that survives disabling plugins and switching themes.** If you have already ruled out plugins and the theme (the usual first suspects) and the site is still broken, damaged core files become a real possibility worth ruling out. It is worth diagnosing the exact error first; the Noiz guide to [fixing common WordPress errors](/wordpress/how-to-fix-common-wordpress-errors/) helps you narrow it down before you reach for this.
- **A checksum mismatch.** If a scan (or the WP-CLI command shown later) reports that a core file no longer matches WordPress.org's official copy, that file has been altered. A reinstall restores the genuine version.
- **Malware cleanup.** One of the commonest things malware does is inject itself into core files, because they are always present and rarely inspected. Overwriting every core file with a clean copy removes that injected code in a single stroke. It is important to understand that this is only part of a cleanup, not the whole of it, and there is a dedicated section on that below.
Equally, it is worth knowing when a reinstall is the wrong tool, so you do not waste effort on it. It will **not** fix a problem caused by a plugin or theme, because those live in `wp-content`, which a core reinstall deliberately leaves untouched. It will not fix an "Error establishing a database connection", because that is a configuration or database problem, not a core-files problem. And it will not, on its own, remove malware that has taken up residence in your plugins, uploads, database or `.htaccess`. Match the repair to the fault.
## Before You Start: Back Up (Not Optional)
Even though a correct reinstall is safe, you are about to delete folders and overwrite files, and the golden rule of any such operation is that you never do it without a way back. Take a full backup first: both the files and the database. On Noiz hosting you can download your files over SFTP or through the File Manager, and export your database through **phpMyAdmin** in your control panel. If your site is on a managed Noiz plan, you can simply ask the Noiz support team to take a fresh backup for you before you begin, or to perform the reinstall on your behalf. Do not skip this step because the reinstall "should" be safe. A backup costs a few minutes and turns any mistake into a five-minute restore instead of a disaster.
## The Golden Rule: What You Must Never Overwrite
This is the single most important part of the whole article, so it gets its own section. Whichever method you use, three things must survive completely untouched. Losing any of them is the one way to turn a routine repair into real data loss.
- **Never delete or overwrite `wp-content`.** This is your themes, your plugins and every image you have ever uploaded. If you are replacing files by hand, copy *into* this folder only if you have a specific reason to; for a pure core reinstall you should not be writing to it at all.
- **Never delete or overwrite `wp-config.php`.** This holds your database credentials and security keys. Without it, WordPress cannot find your content and behaves as if it has never been installed, sending you to the setup screen.
- **Never delete your `.htaccess` file** (and, if you have one, `robots.txt` or any other custom file you placed in the root). These hold your permalink rules and any redirects, and they are not part of WordPress core.
Here is the reassuring part, and the reason the manual method is safer than it sounds: the official WordPress download *does not contain* a `wp-config.php` or a `.htaccess` at all. It contains only a `wp-config-sample.php`. So when you unpack a fresh copy and upload its files, there is simply no file in the package that can overwrite your real configuration. Your `wp-config.php` will be safe. The only folder in the fresh download that overlaps with your content is `wp-content` (it ships with a default theme and one or two default plugins), and the methods below all show you how to avoid touching yours.
## First, Find Out Which Version You Are Running
A clean repair replaces your core files with a fresh copy of *the same version*. Mixing a repair with an update at the same time makes it much harder to tell whether the reinstall fixed anything, and downloading the wrong version can leave your files and your database out of step. So before you download anything, note your current version. You can find it in any of these ways:
- In the dashboard, at the bottom-right of almost every admin screen, or on the **Dashboard > Updates** screen, which states the version plainly.
- Over SSH with WP-CLI, by running `wp core version`.
- In the file `wp-includes/version.php`, on the line beginning `$wp_version`.
If you are already on the latest release (7.0.2 at the time of writing) then a reinstall and an update amount to the same download, and you can use any method below. If you are deliberately on an older version, download that exact version from the [release archive](https://wordpress.org/download/release-archive/) rather than the latest, so you repair without upgrading. The archive lets you fetch any version directly, for example `https://wordpress.org/wordpress-7.0.2.zip`.
## Method 1: Reinstall From the Dashboard (Easiest)
If you can still log in to WordPress, this is by far the simplest route and needs no file access at all. WordPress can reinstall its own core files for you.
1. Log in and go to **Dashboard > Updates**.
2. When you are already running the current version, WordPress shows a message that you have the latest version, followed by a button labelled **Re-install version 7.0.2** (the number matches whatever is current). Click it.
3. WordPress downloads a fresh copy of that version and drops the core files into place, leaving your content, plugins, themes and database alone. When it finishes, you are done.
This method reinstalls the current version only, and it needs a working login, so it is the wrong choice if the damage has locked you out or if you are pinned to an older version you do not want to change. In those cases use Method 2 or Method 3. One caveat worth knowing: because it relies on WordPress writing to its own files, a permissions problem on the server can make it fall back to asking for connection credentials, or fail outright; if it does, the manual method sidesteps that entirely.

## Method 2: Reinstall With WP-CLI (Precise and Fast)
If you have SSH access, WP-CLI is the cleanest way to do this. It is exact, it is quick, and it can tell you both what is wrong before you start and whether you fixed it afterwards. Managed-plan clients can ask the Noiz support team to run these steps.
Start by asking WordPress which core files, if any, do not match the official copies. This tells you whether a reinstall is warranted and exactly what it will fix:
```
wp core verify-checksums
```
If everything is genuine you will see a success message. If not, you will get a line for each altered file and an overall warning that the installation does not verify against checksums. Note that this command only checks WordPress *core* files against WordPress.org; it does not and cannot verify your plugins or themes in `wp-content`, because those are not part of core. A clean checksum result therefore does not prove your whole site is clean, only that the engine is genuine.
To reinstall, download a fresh copy of your current version straight over the top of the existing core files:
```
wp core download --version=$(wp core version) --skip-content --force
```
Two options in that command are doing important work:
- **`--skip-content`** tells WP-CLI to fetch WordPress *without* the default themes and plugins, so the download contains nothing that could be written into your `wp-content` folder. This is what keeps your themes, plugins and uploads guaranteed untouched. Do not leave it out.
- **`--force`** allows the download to overwrite the core files that are already there. Without it, WP-CLI refuses to run because it sees an existing installation.
Then confirm the repair worked by verifying again. This time it should come back clean:
```
wp core verify-checksums
```
One honest limitation: a reinstall *overwrites* genuine core files, but it does not delete files that were never part of core in the first place. If malware dropped an extra rogue `.php` file into `wp-includes` or your root, that stray file is not on WordPress.org's list and so is not removed by the download; verify-checksums with the `--include-root` option can help flag such unexpected root files, but removing them is a separate step covered in the malware section below.
## Method 3: Manual File Replacement (SFTP or File Manager)
This is the method to reach for when you cannot log in, when the automated methods fail on permissions, or when you simply want to see and control every file yourself. It is the same procedure the official documentation uses for a manual update, applied to the same version rather than a newer one. It works entirely over SFTP or your control panel's File Manager, so it needs no dashboard access.
### Step 1: Download and Unpack a Fresh Copy
Download the matching version zip from WordPress.org (the latest from `https://wordpress.org/latest.zip`, or a specific version such as `https://wordpress.org/wordpress-7.0.2.zip` from the release archive) onto your own computer, and unzip it. You will get a folder called `wordpress` containing the fresh `wp-admin` and `wp-includes` folders, a fresh `wp-content`, and the loose root files. Note again what it does *not* contain: no `wp-config.php`, no `.htaccess`.
### Step 2: Deactivate Plugins If You Can
If you still have dashboard access, deactivate your plugins first; it reduces the chance of a conflict while the files are in flux, and you will reactivate them at the end. If you are locked out, skip this and carry on; you can deal with plugins afterwards.
### Step 3: Delete the Old Core Folders
Connect over SFTP or open the File Manager, and navigate to your WordPress root (on Noiz hosting this is usually the document root of your domain, for `yourdomain.com` replace with your own). Delete the existing `wp-admin` and `wp-includes` folders entirely. This is deliberate: deleting them first, rather than merging over the top, guarantees that no stale or malicious file survives inside them. Do not delete anything else. Leave `wp-content`, `wp-config.php` and `.htaccess` exactly where they are.
### Step 4: Upload the Fresh Core Folders
Upload the new `wp-admin` and `wp-includes` folders from your unpacked copy into the root, in place of the ones you just deleted.
### Step 5: Overwrite the Loose Root Files
Upload all the loose files from the root of the unpacked `wordpress` folder (files like `index.php`, `wp-login.php`, `wp-settings.php`, `wp-cron.php` and so on) into your root, overwriting the existing ones when prompted. Because the package has no `wp-config.php` or `.htaccess` in it, this cannot touch your configuration. Your `wp-config.php` stays exactly as it was.
### Step 6: Leave wp-content Alone
For a pure repair, do not copy the fresh `wp-content` over yours at all. The only reason you would ever copy anything from it is if a default theme or the bundled default plugin was itself damaged, and even then you copy only the individual affected file *into* your existing `wp-content`, never the whole folder. If in any doubt, leave `wp-content` completely untouched.
### Step 7: Clear a Stuck Maintenance Message
If your site was showing "Briefly unavailable for scheduled maintenance", look in the root for a hidden file named `.maintenance` and delete it. That file is what puts WordPress into maintenance mode, and a failed update sometimes leaves it behind. (In the File Manager you may need to enable "show hidden files" to see it.)
### Step 8: Finish in the Dashboard
Visit `yourdomain.com/wp-admin`. If WordPress needs to bring the database into step with the code, it will show a "database update required" prompt; click through it. Then reactivate any plugins you deactivated, and if you run a caching plugin or server cache, clear it so visitors see the repaired site immediately rather than a stale copy.
## If You Are Reinstalling as Part of a Malware Cleanup
Reinstalling core is one of the strongest single moves in a malware cleanup, because it replaces every genuine core file with a known-clean version in one pass, wiping out any code injected into `wp-admin`, `wp-includes` or the root `.php` files. But it is a step, not the finish line, and treating it as the whole job is how reinfections happen. To understand why, remember what a core reinstall leaves alone: your `wp-content`, your database and your `.htaccess`. Attackers know this too, which is why they also hide:
- **Backdoors and injected code inside plugins, themes and the uploads folder**, none of which a core reinstall touches. These need to be found and cleaned or replaced separately, ideally by reinstalling each plugin and theme from a trusted source too.
- **Rogue extra files** dropped into core folders or the root that were never part of WordPress. Because they are not genuine core files, overwriting core does not remove them; they must be identified and deleted.
- **Malicious rules in `.htaccess`**, which a core reinstall preserves along with your legitimate rules.
- **Injected content or admin users in the database.**
After a cleanup, you should also change every password and rotate your security keys, and it is wise to assume the attacker knew your admin credentials. If you find you cannot get back in, the Noiz guide to [resetting a WordPress admin password via phpMyAdmin](/wordpress/how-to-reset-a-wordpress-admin-password-via-phpmyadmin/) covers regaining access. For the full picture of hardening a site so it stays clean, work through the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/). If your site is compromised and you are unsure how deep it goes, open a ticket with the Noiz support team; a reinstall of core is a good first move, but a proper cleanup is worth doing thoroughly.
## Troubleshooting
- **Symptom**: after the reinstall the site sends you to the setup screen asking to configure a database. Your `wp-config.php` is missing or was overwritten. Restore it from your backup. This is exactly the file the golden-rule section warns never to touch, and it is why the fresh download deliberately excludes it.
- **Symptom**: the site is stuck on "Briefly unavailable for scheduled maintenance" even after replacing the files. Delete the hidden `.maintenance` file in your WordPress root, which the earlier steps describe.
- **Symptom**: you see a "failed update" notice after the reinstall. Same cause as above; remove the `.maintenance` file to clear it.
- **Symptom**: WordPress prompts that a database update is required. This is normal and safe if you reinstalled a newer version than before; click through the prompt at `yourdomain.com/wp-admin/upgrade.php`. If you only meant to repair the current version, it means the version you downloaded was newer than the one you were running; that is fine, but it is now an update as well as a repair.
- **Symptom**: verify-checksums still reports altered files after a WP-CLI reinstall. Make sure you verified against the same version you are running by including `--version`, and remember the command flags files that were *added* as well as changed; a stray non-core file needs deleting by hand, it is not something the download will remove.
- **Symptom**: the dashboard re-install button asks for FTP or connection details, or fails. This is a filesystem permissions situation on the server. Use the WP-CLI or manual method instead, which do not depend on WordPress writing to its own files, or ask Noiz support to check ownership and permissions.
- **Symptom**: your theme or plugin settings look reset after the reinstall. A pure core reinstall cannot cause this, because those settings live in `wp-content` and the database, neither of which core touches. It points to the fresh `wp-content` having been copied over yours by mistake; restore `wp-content` from your backup.
If you are not sure whether reinstalling core is the right fix for what you are seeing, or you would rather not delete and replace files by hand, open a support ticket with the Noiz support team. Tell them your domain, the symptom you are chasing, and whether you can still log in, and a technician can confirm the diagnosis, take a safety backup, and reinstall core cleanly on your behalf, on both the South African and Irish platforms.
# How to Migrate a WordPress Site to Noiz Hosting
Source: https://docs.noiz.ie/wordpress/how-to-migrate-a-wordpress-site-to-noiz-hosting/
This guide walks you through moving an existing WordPress site onto Noiz hosting, whether it currently lives on WordPress.com or on another web host. The task goes by several names, including "migration", "moving", "transferring", and "importing", but they do not all mean the same thing, and the single most common mistake is choosing the wrong one. There are really two jobs hiding under one word: a **content import**, which carries your posts and pages but nothing else, and a **full-site migration**, which copies your entire site (files and database) so the new copy is identical to the old one. This guide explains the difference plainly, shows you the manual route, the migration-plugin route, and the special case of leaving WordPress.com, and then covers the part most tutorials skip: pointing your domain at Noiz cleanly, and proving the move actually worked before you switch off the old host.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Migrating WordPress (Advanced Administration)](https://developer.wordpress.org/advanced-administration/upgrade/migrating/): the official reference for moving a site to a new server, keeping or changing your domain, and the warning about serialised data.
- [Backing Up Your Database and Files (Backups)](https://developer.wordpress.org/advanced-administration/security/backup/): the two halves of a WordPress backup, database and files, and why you need both to move a site faithfully.
- [Tools Export screen](https://wordpress.org/documentation/article/tools-export-screen/): what the built-in exporter produces (a WXR file) and exactly which content it does and does not contain.
- [Tools Import screen](https://wordpress.org/documentation/article/tools-import-screen/): how to bring a WXR export into a WordPress site, including author mapping and downloading attachments.
- [WordPress Importer (plugin directory)](https://wordpress.org/plugins/wordpress-importer/): the official importer that reads a WXR file and can fetch media attachments from the old site.
- [Export your content (WordPress.com support)](https://wordpress.com/support/export/): the authoritative account of what a WordPress.com export includes, and its important limits.
- [wp search-replace (WP-CLI)](https://developer.wordpress.org/cli/commands/search-replace/): the serialisation-safe way to update URLs across the database when your domain changes.
## Prerequisites
- Administrator access to the site you are moving *from*, and to the fresh WordPress on Noiz you are moving *to*. If you are unsure how to reach either dashboard, see [how to log in to the WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A Noiz hosting plan with somewhere for the site to live: a domain or subdomain set up in your panel, with PHP and MySQL/MariaDB available (every Noiz WordPress plan provides these).
- A way to move files: an **SFTP** client, or the **File Manager** in your hosting panel. Both reach the same web space.
- Access to **phpMyAdmin** for the databases, reachable from your Noiz panel.
- A complete, tested backup of the source site taken immediately before you begin. A migration is exactly the moment you are most glad to have one.
- Patience with DNS. The final domain switch is not instant, and rushing it is the usual cause of a "half-moved" site.
If your site is on a Noiz **managed** plan and any of this feels daunting, you do not have to do it yourself. The Noiz support team can carry out the whole migration for you; skip to the closing section.
## First Decide: Content Import or Full-Site Migration
This one decision shapes everything that follows, so make it deliberately.
A **content import** uses WordPress's own export and import tools. It moves your *writing*: posts, pages, comments, categories, tags, custom fields, and (with the right option) your media files. It does **not** move your theme, your plugins, your settings, your menus, or your widgets. You rebuild those by hand on the new site. This is the right choice when your site is mostly a blog, when the old and new sites will look deliberately different, or when you are leaving WordPress.com (where a full copy is not possible; see the next section).
A **full-site migration** copies the two things that *are* your site: the **files** (WordPress core, your theme, your plugins, and uploads) and the **database** (your content and every setting). Done properly, the Noiz copy is indistinguishable from the original, down to the widgets and plugin configuration. This is the right choice for any established, self-hosted site, and it is almost always what people actually mean by "migrate".
As a rule of thumb: if you are moving from another host and want the same site, choose full-site migration. If you are moving from WordPress.com, or deliberately starting fresh, choose a content import.
## Special Case: Leaving WordPress.com
WordPress.com and self-hosted WordPress share the same software family, but a WordPress.com site is a managed, sandboxed environment, so you cannot lift its files and database off the platform the way you can with a normal host. What you *can* take is your content, and it is important to know precisely what that means before you rely on it.
The WordPress.com export produces a **WXR file** (a WordPress-flavoured XML file) containing your posts, pages, comments, categories, and tags, together with *links* to your media rather than the media files themselves. It deliberately excludes your theme design and customisations, and any plugin-style functionality, because those are provided by the platform and do not exist as portable files. In short, a WordPress.com export is a **content-only** transfer.
What this means in practice when you land on Noiz:
- You will install a fresh WordPress on Noiz and import the WXR file into it (Method A below).
- You must **rebuild the look**: choose and configure a theme, recreate your menus and widgets, and install the plugins that give you the features WordPress.com bundled in.
- Your **images need to come across too**. The importer can download them from your old WordPress.com media library automatically (the "download and import file attachments" option), and WordPress.com also lets you export the media library as a separate download if you would rather bring the files yourself. Either way, confirm the images actually arrive; this is the step that most often fails silently.
- Some WordPress.com features rely on the Jetpack service. If you used those, you will replicate the equivalent functionality with standalone plugins on Noiz.
None of this is a shortcoming of Noiz; it is simply the boundary of what WordPress.com allows you to take with you. The upside is that on Noiz you own the whole site outright, with full access to files, database, themes, and any plugins you like.
## Prepare the Noiz Side First
Whichever method you use, you need a place for the site to arrive. Set this up before you touch the old host.
1. **Point your domain or a subdomain at Noiz in the panel.** Noiz hosting runs on Plesk (on neo.noiz.co.za) for South African plans, DirectAdmin for Ireland, and ISPConfig for some accounts. In all three, you create the site so that a web space and a database can exist for it. You do not need to change your public DNS yet; that is the very last step.
2. **Install a clean WordPress** into that space, or leave the web space empty if you are going to upload the old site's files directly. Your panel's one-click installer is the quickest way to get a working WordPress and a matching database.
3. **Note the new database details.** A migration always needs the database name, database user, password, and host. Your panel creates these; keep them to hand for `wp-config.php`.
4. **Check the versions roughly match.** Aim for a PHP version on Noiz that is equal to or newer than the old host's, and make sure your WordPress is current (7.0.2). Moving to an *older* PHP or WordPress than the site was built on is the one direction that causes trouble.
## Method A: Content Import (Posts and Pages)
This is the built-in route, and the only route out of WordPress.com. It is straightforward but remember what it leaves behind.
### 1. Export from the old site
On the source site, go to **Tools** > **Export**, choose **All content**, and download the WXR file to your computer. The official [Tools Export screen](https://wordpress.org/documentation/article/tools-export-screen/) reference lists exactly what the file holds. Keep this file safe; it is your content.
### 2. Import into the fresh Noiz WordPress
On the new site, go to **Tools** > **Import**, and under **WordPress** install and run the importer (the official [WordPress Importer](https://wordpress.org/plugins/wordpress-importer/)). Upload the WXR file and, when prompted:
- **Map authors.** Assign the imported posts to an existing user on the new site, or let the importer create the original authors as new users. Choose deliberately, so posts end up under the right name.
- **Tick "Download and import file attachments".** This is what pulls your images across from the old site into the Noiz media library. If you skip it, your posts will still point at images hosted on the *old* site, which breaks the moment you switch that host off.
### 3. Rebuild everything the import did not carry
Now do the work a content import always leaves for you: install and configure your theme, recreate menus and widgets, install the plugins you need, and reset options such as your site title, tagline, and permalink structure. Set the permalink structure to match the old site if you want existing links and search rankings to survive.
### Watch out for large exports
A big site can produce a WXR file too large for the importer to swallow in one go, especially with attachment downloading switched on. If the import stalls or times out, split the export into smaller files (the export screen lets you filter by date range, for example) and import them in sequence. On a Noiz managed plan, support can raise the relevant limits or run the import for you.
## Method B: Full-Site Migration (Files and Database)
This is the faithful copy, and for a self-hosted site it is usually the better choice. You move the site's two halves separately, then join them back together. It sounds involved but it is just careful copying.
### 1. Back up and gather both halves on the old host
On the source site, take a full backup and download both parts to your computer: the entire WordPress folder (all the files, including the `wp-content` directory with your themes, plugins, and uploads), and a full export of the database. The official [Backups](https://developer.wordpress.org/advanced-administration/security/backup/) guide explains why you need both halves; one without the other is not a working site.
### 2. Move the files into your Noiz web space
Upload the files into the site's document root on Noiz using **SFTP** or the panel **File Manager**. If you installed a clean WordPress on Noiz earlier and only want the old site's content and customisations, the reliable approach is to overwrite `wp-content` and keep the fresh core, rather than mixing two WordPress versions. Preserve the folder structure exactly as it was.
### 3. Move the database with phpMyAdmin
Export the source database as a single SQL file (from the source host's phpMyAdmin or backup tool). Then, in the **phpMyAdmin** on your Noiz panel, select the empty database you created earlier and import that SQL file into it. If the file is large, compress it first; phpMyAdmin happily imports a `.sql.gz` or `.zip`, which sidesteps the upload size limit that trips people up on big databases.
### 4. Point wp-config.php at the new database
The database name, user, and password on Noiz are almost certainly different from the old host's. Edit `wp-config.php` in the site's root and update these four lines to match the Noiz database you noted earlier:
```
define( 'DB_NAME', 'your_noiz_db_name' );
define( 'DB_USER', 'your_noiz_db_user' );
define( 'DB_PASSWORD', 'your_noiz_db_password' );
define( 'DB_HOST', 'localhost' );
```
(`localhost` is correct on Noiz hosting in almost every case.) Get one of these four wrong and the site shows an "Error establishing a database connection"; that message is a wrong value here far more often than a real fault.
### 5. If the domain is changing, update the URLs (safely)
If the site is arriving on the same domain it left, skip this. If the domain is changing (for example from a staging address, or from a WordPress.com subdomain, or to a brand-new name), the site's old address is written all over the database and must be updated. This is the single most dangerous step in a migration, because of **serialised data**, and it has its own section below. Do not reach for a blunt find-and-replace.
## Method C: The Migration-Plugin Route
If moving files and databases by hand feels like too much, a migration plugin automates the packaging and unpacking. WordPress's plugin directory offers several reputable ones; Noiz does not endorse a specific plugin, so compare current options and read recent reviews before choosing. The pattern they all follow is similar:
1. Install the migration plugin on the **old** site and let it bundle the files and database into a single package (some produce a package plus a small installer file).
2. Install a fresh WordPress on Noiz (or the same plugin), and hand it the package.
3. The plugin unpacks the files, imports the database, and updates the URLs for you.
This route is genuinely convenient, with two honest caveats. First, large sites can exceed a plugin's free-tier size limit or your server's execution time, at which point the manual Method B is more reliable. Second, you are trusting the plugin to handle the serialised-data URL rewrite correctly, so pick a well-established one and, as always, keep the backup you took at the start. On a Noiz managed plan, if a plugin migration stalls partway, support can complete the move the manual way.
## Change the URLs Safely (Domain-Change Migrations Only)
When your domain changes, every stored copy of the old address, in your content, your theme options, your widgets, and your menus, needs updating to the new one. The catch is that WordPress stores a lot of settings as **serialised data**, a compact format that records the exact character length of each stored value. A naive database-wide find-and-replace changes the text but leaves those length markers wrong, which quietly corrupts widgets, theme options, and page-builder layouts. The official [migration guide](https://developer.wordpress.org/advanced-administration/upgrade/migrating/) carries the same warning.
So do **not** run a raw `REPLACE()` query in phpMyAdmin against your URLs. Use a serialisation-aware method instead, which decodes the data, makes the change, and re-encodes it with the length markers corrected:
- **WP-CLI**, if you have SSH access, is the most reliable. Preview first with `--dry-run`, then run it, always protecting the `guid` column: `wp search-replace 'https://oldsite.com' 'https://yourdomain.com' --skip-columns=guid` See the official [wp search-replace](https://developer.wordpress.org/cli/commands/search-replace/) reference for the flags. (`oldsite.com` and `yourdomain.com` are examples; use your real addresses, including the exact protocol.)
- **A serialisation-aware search-and-replace plugin**, if you prefer not to use the command line. Choose one that clearly states it handles serialised data and offers a dry run, and leave the `guid` column out of the replacement.
Also set the site's own address explicitly: under **Settings** > **General**, confirm the **WordPress Address** and **Site Address** both show the new domain. After any URL change, go to **Settings** > **Permalinks** and click **Save Changes** to rebuild the link rules, then clear every cache. If you are locked out and cannot reach Settings at all, these two values can be set directly in the database; see [how to work in phpMyAdmin](/wordpress/how-to-reset-a-wordpress-admin-password-via-phpmyadmin/) for the technique, applied to the `siteurl` and `home` options.
## Test Before You Switch the Domain Over
Here is the part that separates a smooth migration from a stressful one: **prove the Noiz copy works before you change any public DNS**. While your domain still points at the old host, you can preview the migrated site on Noiz privately.
- **Use a hosts-file override.** On your own computer, add a line to your `hosts` file mapping `yourdomain.com` to your Noiz server's IP address (shown in your Noiz welcome email and hosting panel). Your browser then loads the Noiz copy while the rest of the world still sees the old host. This is the cleanest way to test, because the site sees its real domain and nothing needs changing.
- **Or use a temporary URL** if your panel provides a preview address, remembering that a WordPress site with hard-coded URLs may not render perfectly under a different address.
Walk the whole site: home page, a few inner pages, a blog post, images, your menu, any contact form, and the login screen. Only when you are satisfied should you touch DNS.
## Cut Over the Domain (DNS)
This is the actual "go live" moment. There are two ways to point your domain at Noiz, and which you use depends on where the domain is managed.
### Option 1: Point the nameservers at Noiz
If Noiz will manage your DNS, set your domain's nameservers (at your domain registrar) to Noiz's hosting nameservers:
```
ns1.noiz.co.za
ns2.noiz.co.za
```
This hands all DNS for the domain to Noiz and is the simplest arrangement for a straightforward hosting move.
### Option 2: Keep your DNS where it is, change one record
If you prefer to keep managing DNS at your current provider (or at Cloudflare), leave the nameservers alone and instead update the domain's **A record** to point at your Noiz server's IP address. This is the right choice if you have email, subdomains, or other services whose DNS records you do not want to move.
### Do these two things around the cutover
- **Lower the TTL first.** A day before you switch, reduce the TTL on the record you are changing (to a few minutes if allowed). DNS changes are cached across the internet for the length of the TTL, so a low TTL makes the switch propagate quickly and a mistake quick to undo.
- **Leave the old host running** for a day or two after the switch. Because of caching, some visitors will still reach the old site during propagation. Keeping it live (and ideally read-only) means nobody hits a dead site, and nobody posts new content to a copy you are about to abandon.
Once DNS has settled on Noiz, issue or confirm the site's SSL certificate in your panel so the site loads over `https`, and check that `http` requests redirect to `https`.
## Verify the Migration Worked
Do not declare victory until you have checked these, ideally a few hours after the DNS switch when propagation is well under way:
- **Pages and posts load,** including deep inner pages, not just the home page. Broken inner pages usually mean permalinks need re-saving.
- **Images and media appear,** and are being served from your domain, not the old host. View an image's address to confirm it points at Noiz.
- **The login page works** and you can reach the dashboard. If not, see the troubleshooting below.
- **Forms, search, and any interactive features** behave as they did before.
- **No leftover old URLs.** Search the live site for the old domain or old staging address; any hit means the URL update missed something.
- **Caches are clear.** Purge WordPress caching, your panel's cache, and any CDN, then hard-refresh. A surprising number of "it didn't migrate" reports are simply a cache serving the old page.
When everything checks out, and only then, cancel the old hosting. With the move complete, this is the ideal moment to harden the fresh installation; work through the [WordPress Security Checklist](/wordpress/wordpress-security-checklist/) before you move on.
## Troubleshooting
- **"Error establishing a database connection" after moving files.** The database credentials in `wp-config.php` do not match the Noiz database. Recheck the name, user, password, and that `DB_HOST` is `localhost`. Confirm the SQL import actually completed and the tables exist in phpMyAdmin.
- **The home page works but inner pages give a 404.** The rewrite rules have not been rebuilt. Go to **Settings** > **Permalinks** and click **Save Changes**. On some servers you may also need the correct rewrite rules in the site's configuration; the Noiz support team can confirm these for your panel.
- **You are redirected back to the old domain, or cannot reach the dashboard.** The old address is still stored in the database. Update the `siteurl` and `home` values (via a serialisation-aware search-replace, or directly in phpMyAdmin) to the new domain, then clear caches.
- **Images are missing or still load from the old host.** For a content import, the "download and import file attachments" step did not run or timed out; re-run it, or copy the `wp-content/uploads` folder across by SFTP. For a full migration, confirm you uploaded the whole `uploads` folder and that URLs were updated.
- **Widgets, theme options, or a page builder look broken after a domain change.** This is serialised-data corruption from a raw find-and-replace. Restore your backup and redo the URL change with a serialisation-aware method only.
- **You cannot log in on the new site.** If the password was not carried across cleanly, or you are locked out after a domain change, reset it directly in the database: see [how to reset a WordPress admin password via phpMyAdmin](/wordpress/how-to-reset-a-wordpress-admin-password-via-phpmyadmin/).
- **The site still shows the old host days later.** Either DNS has not propagated (check the record you changed and its TTL) or your local machine, browser, or a CDN is caching the old address. Test from a different network or device to be sure.
If you would rather not run the migration yourself, the Noiz support team can move your WordPress site onto Noiz hosting for you. Open a support ticket with your current host details (or WordPress.com login), your domain, and whether you want a content import or a full copy, and a technician will carry out the move, update the URLs safely, and confirm the result before the old site is retired. Managed-plan clients can request this as part of their plan.
# How to Optimise WordPress for AI Search (llms.txt and GEO)
Source: https://docs.noiz.ie/wordpress/how-to-optimise-wordpress-for-ai-search-llmstxt-and-geo/
This guide is a plain-language, deliberately honest tour of how to make a WordPress site work well with AI search: the answers that ChatGPT, Google's AI Overviews and AI Mode, Perplexity, Gemini and Copilot now put in front of people before they ever reach a list of blue links. It covers what an `llms.txt` file is and how to add one, the practices grouped under Generative Engine Optimization (GEO), how structured data helps machines understand your pages, and how to control which AI crawlers may read your site. This field goes by several names you will meet online: GEO, Answer Engine Optimization (AEO), and LLM optimisation (LLMO) all describe roughly the same goal, which is being the source an AI answer draws from and cites. It is a fast-moving, half-formed area, so this guide is careful throughout to separate what is genuinely established from what is still marketing and guesswork. It is written for Noiz clients who run their own WordPress site, and it names specific tools only as examples, never as endorsements.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official documentation linked below. AI search is changing month to month, so treat any specific figure or tactic here as a snapshot of mid-2026, and weight the durable principles over the fashions.
### Official Documentation Reference
- [The /llms.txt proposal (llmstxt.org)](https://llmstxt.org/): the original specification by Jeremy Howard, defining the file's exact format and intent.
- [Schema.org](https://schema.org/): the shared vocabulary of structured-data types (Article, Organization, Product, FAQ and so on) that search and AI systems read.
- [Introduction to structured data (Google Search Central)](https://developers.google.com/search/docs/appearance/structured-data/intro-structured-data): how to mark up pages with JSON-LD, and which types Google supports.
- [AI features and your website (Google Search Central)](https://developers.google.com/search/docs/appearance/ai-features): Google's own guidance on how AI Overviews and AI Mode use your content, and how to control it.
- [Google crawlers overview (Google Search Central)](https://developers.google.com/search/docs/crawling-indexing/overview-google-crawlers): the full list of Google's user agents, including `Googlebot` and `Google-Extended`, and exactly what each one controls.
- [Reading Settings (WordPress Documentation)](https://wordpress.org/documentation/article/settings-reading-screen/): the built-in **Search engine visibility** control and how WordPress signals crawlers.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an **Administrator**, which you need to install plugins and change settings.
- The ability to upload a file to your site's web root (the folder that holds `wp-config.php`, usually named `public_html` or `httpdocs`). On Noiz hosting you reach it over SFTP or through the panel File Manager. If you are on a managed plan, you can ask the Noiz support team to place a file for you.
- A site with real, substantive content. None of this helps a thin site. AI answers draw on genuine, useful material, so the single biggest lever is having something worth citing.
## What "AI Search" Actually Means, and the Two Ways Your Content Reaches a Model
Before any tactics, it helps to understand the machine you are optimising for, because one distinction explains almost everything that follows. Your content can reach a large language model by two very different routes, and they are governed by different controls.
- **Training.** A model is trained, once, on an enormous snapshot of the web. Anything learned this way is baked in until the next training run and has no live link back to your page. Crawlers such as `GPTBot`, `ClaudeBot` and `Google-Extended` gather this training data.
- **Retrieval (also called grounding).** When you ask a modern assistant a current question, it usually runs a live search, fetches a handful of pages, and writes an answer from what it just read, with citations. This is where being "cited by AI" actually happens, and it is driven by a search index and by retrieval crawlers such as `OAI-SearchBot`, `PerplexityBot` and Google's own index behind AI Overviews.
Almost all the practical wins in 2026 are about the second route. Retrieval means an AI answer is, underneath, a search result that has been summarised and attributed. That is why the old craft of being findable and trustworthy in search has not died so much as changed shape: if a system cannot find and parse your page at answer time, it cannot cite you.
## The Shift You Are Optimising For: Zero-Click and Citation
The reason this topic exists at all is a measurable change in how people get answers. A large and growing share of searches now end without anyone clicking through to a website, because the answer is shown on the results page itself. Across 2026, credible studies put the proportion of Google searches that end without a click at somewhere around two-thirds, up from roughly half a few years earlier, and the figure climbs higher still on the queries where an AI Overview appears. Exact numbers vary a lot between studies, because they measure different query sets in different ways, so treat any single headline percentage with caution. The direction, though, is not in doubt: the click is becoming scarcer, and the answer box is becoming the destination.
This reframes the goal. For informational content especially, you are no longer only competing to rank and win the click. You are competing to be the source the answer is built from and names. There is a genuine silver lining worth holding onto: the visitors who do still click after reading an AI answer tend to arrive better-informed and more ready to act, so the traffic you keep is often higher-intent than before. The honest cost is that raw visit counts to informational pages have fallen for many sites, and no amount of GEO fully reverses that. The realistic aim is to protect your share of a changed pie, not to pretend the pie is the same.
## Honest Ground Rules: What Is Established and What Is Speculation
This area attracts a great deal of confident advice, much of it selling something. It is worth fixing a few reference points before spending any effort.
- **Established.** AI Overviews and AI Mode are generated from Google's ordinary search index, so classic search fundamentals (crawlable, fast, well-structured, genuinely useful pages) still decide whether you are eligible to be cited. Clear, well-organised, quotable content is easier for a model to lift accurately. Structured data helps machines read your pages without guessing. Being mentioned favourably on other trusted sites raises the odds an assistant repeats you. None of this is exotic; it is good publishing.
- **Plausible but unproven.** Small formatting habits (leading with a direct answer, using question-shaped headings) probably help, and cost little, but the evidence is soft and the platforms do not confirm the mechanics.
- **Speculative or oversold.** The idea that adding an `llms.txt` file measurably improves your AI citations is, as of mid-2026, not supported by the available evidence. Any tool promising to "guarantee" placement in AI answers is selling certainty that does not exist. The systems are opaque and change without notice.
Read the rest of this guide with that ranking in mind: spend most of your effort on the established fundamentals, adopt the cheap plausible habits, and treat the speculative items as low-cost experiments rather than priorities.
## llms.txt: What It Is, How to Add One, and What to Honestly Expect
### What the File Is
The `llms.txt` proposal, published by Jeremy Howard in September 2024, suggests a single Markdown file placed at your site's root, at `https://yourdomain.com/llms.txt`, that hands a language model a clean, curated map of your most important content. The reasoning is that a model's context window is too small to swallow a whole website, so a short, hand-picked index of links (with a one-line note on each) lets it find the good parts quickly. It is, loosely, a sitemap written for machines that read prose rather than XML. The format is deliberately simple:
- A single **H1** line with the site or project name (the only strictly required part).
- A **blockquote** giving a one-sentence summary of what the site is.
- Optional free-form Markdown describing the site in more detail.
- One or more **H2** sections, each a list of Markdown links to key pages, with an optional short note after each link.
- An optional section literally named **Optional**, whose links a model may skip when it needs to keep things short.
A companion convention, `llms-full.txt`, goes further by concatenating the full Markdown text of your key pages into one large file, so a model can ingest everything in a single fetch. Here is what a modest business site's `llms.txt` might look like:
```
# Example Accounting
> Example Accounting is a Cape Town accountancy firm offering tax, payroll and advisory services to small businesses across South Africa.
## Core pages
- [Services](https://yourdomain.com/services): the tax, payroll and advisory services offered
- [About](https://yourdomain.com/about): company background, team and professional credentials
- [Contact](https://yourdomain.com/contact): office address, phone number and enquiry form
## Guides
- [Small business tax guide](https://yourdomain.com/guides/small-business-tax): plain-language guide to provisional tax
- [Payroll basics](https://yourdomain.com/guides/payroll): how PAYE and UIF work in practice
## Optional
- [Full article archive](https://yourdomain.com/blog): every article published on the site
```
Replace `yourdomain.com` and the example content with your own. Keep the list short and honest: the point is to highlight your best, most representative pages, not to dump your whole sitemap.
### The Honest Status of llms.txt in 2026
This is where realism matters. Despite eighteen months of discussion, `llms.txt` sits on only around one in ten sites, and adoption is not climbing quickly. More importantly, it is a community convention, not a ratified standard: no standards body backs it, and, as of mid-2026, no major AI provider has publicly committed to reading it in their production search systems. Google has said plainly that it does not use it, likening it to the long-abandoned keywords meta tag, and log studies of hundreds of millions of AI-crawler visits find that the retrieval bots overwhelmingly ignore the file and simply read your normal HTML instead. Independent analyses of large domain samples have found no measurable lift in AI citations from having the file.
So why mention it at all? Because it does have one genuine, proven use: developer-facing documentation. AI coding assistants and the IDE tools built on them (and setups using the Model Context Protocol) do consume `llms.txt` to work with a product's docs more accurately. If your site is documentation for software, or an API, an `llms.txt` is worth having on those grounds alone. For an ordinary business or content site hoping for more AI search citations, set your expectations to near zero and treat it as tidy housekeeping, not an SEO tactic.
### How to Add llms.txt to a WordPress Site
WordPress does not create this file for you, and there is nothing about it in core. You have two straightforward routes.
1. **Upload a static file (simplest and most reliable).** Write your `llms.txt` in any plain-text editor and upload it to your site's web root, alongside `wp-config.php`. Because the web server serves any real file that exists before it hands the request to WordPress, a physical `llms.txt` at the root is delivered directly and correctly, exactly as `robots.txt` works. On Noiz hosting you upload it over SFTP or through the panel File Manager. Managed-plan clients can send the file to the Noiz support team to place for them.
2. **Use a plugin.** Several SEO and dedicated plugins now generate and maintain an `llms.txt` for you, keeping it in step as you add pages. This trades a little control for convenience, and it means one more plugin to keep updated. If you go this way and also upload a physical file, the physical file wins, so pick one method.
Whichever route you take, verify it by visiting `https://yourdomain.com/llms.txt` in your browser. You should see your plain Markdown text, not a styled WordPress page and not a 404. If you get a themed "page not found", the file is not at the true web root, or a plugin is intercepting the path.
## Generative Engine Optimization: The Practices That Genuinely Help
If `llms.txt` is the overhyped part, this is the part that actually earns citations, and reassuringly little of it is new. GEO is mostly good writing and good structure, aimed at being easy for a machine to find, parse and quote accurately.
### Lead With the Answer, Then Explain
Models building an answer look for a passage they can lift that directly settles the question. Put a clear, self-contained answer in the first sentence or two under a heading, then expand beneath it. A paragraph that opens with "Provisional tax is paid twice a year, in August and February" is far more quotable than one that warms up for four sentences before reaching the point. In the WordPress block editor this is simply a matter of habit: state the conclusion first in each section, then support it.
### Write in Question-Shaped Sections
People ask assistants full questions, so headings phrased as the questions your readers actually type give a model an obvious match between the query and your content. Use the heading blocks (**H2** and **H3**) to structure a page around real questions, keep one idea per section, and let the answer sit immediately below its heading. This also happens to make the page clearer for human readers, which is the point.
### Be Quotable: Specifics, Statistics and Named Sources
Vague, hedged prose is hard to cite; concrete claims are easy. Where you can, include specific figures, dates, named sources and direct statements of fact, and attribute anything you have borrowed. Original material a model cannot get elsewhere (your own data, a genuine case study, first-hand experience, clear definitions) is disproportionately valuable, because it gives the assistant something to cite that is uniquely yours. Confident, plain writing beats padded, keyword-stuffed writing here.
### Build Entity and Topic Authority, and Keep Your Naming Consistent
These systems reason about "entities", meaning the people, organisations, products and concepts your site is about. Help them by being consistent: refer to your business, products and key terms the same way every time, rather than drifting between synonyms. Cover a topic thoroughly across several linked pages rather than in one thin post, and use internal links so a crawler can see how your pages relate. A clear **About** page, consistent contact details, and structured data (below) all reinforce who you are and what you are authoritative about.
### Earn Mentions Where the Engines Already Look
This is the uncomfortable but important one, and it happens off your own site. Assistants lean heavily on sources they already trust: established publications, reputable directories, community discussions and review sites. Being mentioned, accurately and favourably, on those external sources raises the chance an assistant repeats what they say about you. That means the unglamorous work of real public relations, genuine listings, honest reviews and being part of your field's conversation matters more for AI visibility than any on-page trick. There is no file you can upload that substitutes for being talked about elsewhere.
### Keep It Fresh
Retrieval systems favour current information, and a page last touched three years ago competes poorly with one updated this quarter. Revisit your important pages periodically, correct anything stale, and let genuine updates show. Freshness is not a licence to churn out filler; it is a reason to maintain the pages that matter.
## Structured Data: Helping Machines Read Your Pages Without Guessing
Structured data is a block of machine-readable code, added invisibly to a page, that spells out what the page is about in the shared Schema.org vocabulary: this is an *Article* with this author and date, this is an *Organization* with this address, this is a *Product* with this price. It removes guesswork, letting search and AI systems understand your content precisely rather than inferring it from the words. The modern, preferred way to add it is JSON-LD, a small script in the page's head, and you almost never write it by hand.
On WordPress, most structured data comes from your theme and plugins rather than core. WordPress core outputs some basic markup, but the rich, connected schema that describes your organisation, articles, breadcrumbs and products is typically added by an SEO plugin. Several capable options exist, free and paid, and they generate the JSON-LD automatically from content you have already entered. The categories most worth having in place are:
- **Organization** or **LocalBusiness**, describing who you are, which anchors your entity.
- **Article** or **BlogPosting** on your content, carrying author, headline and dates.
- **BreadcrumbList**, describing where a page sits in your site.
- **Product** and offer details for shops, and **FAQ** on genuine question-and-answer pages.
One honest caveat so you calibrate your effort: since 2023 Google has stopped showing the eye-catching FAQ and how-to rich results in ordinary listings for most sites, so structured data is no longer the guaranteed route to a fancier search snippet it once was. Its value now is quieter and more durable: it helps machines, including AI systems, understand your pages accurately, and it is a low-cost foundation rather than a magic switch. After setting it up, check a few pages with a structured-data validator (Google's Rich Results Test or the Schema.org validator) to confirm the markup is valid and matches the visible page, since invalid or misleading markup does more harm than none.
## Controlling Which AI Crawlers May Read Your Site
You get a say in whether AI systems may use your content, exercised mainly through the `robots.txt` file at your site's root. This is a decision with a real trade-off, and one widespread misconception that is worth clearing up before you touch anything.
Recall the two kinds of AI crawler. Training crawlers (such as `GPTBot`, `ClaudeBot`, `Google-Extended` and the Common Crawl bot `CCBot`) gather data to teach future models. Retrieval crawlers (such as `OAI-SearchBot`, `ChatGPT-User`, `PerplexityBot` and `Perplexity-User`) fetch pages to answer questions live, and these are the ones that produce citations back to you. Blocking a training crawler protects your work from being absorbed into a model; blocking a retrieval crawler removes you from that assistant's answers, references and all. That is the core tension: the same openness that lets an assistant use your content without a click is what lets it cite and link you.
The misconception concerns Google, and it catches people out. Google's AI Overviews and AI Mode are built from Google's *ordinary* search index, gathered by `Googlebot`. The separate `Google-Extended` token controls only whether your content trains Google's Gemini models; it does **not** control whether you appear in AI Overviews. So blocking `Google-Extended` will not take you out of AI Overviews, and the only way to leave AI Overviews is to block `Googlebot`, which would also remove you from Google Search entirely. For nearly every site that is far too high a price, so most owners keep `Googlebot` fully allowed and accept that AI Overviews come with ordinary search visibility.
A common middle path is to allow the retrieval and search crawlers, so you remain eligible to be cited in AI answers, while blocking the pure training crawlers if you would rather your content not feed future models. A minimal `robots.txt` in that spirit looks like this:
```
User-agent: GPTBot
Disallow: /
User-agent: CCBot
Disallow: /
User-agent: Google-Extended
Disallow: /
User-agent: *
Allow: /
```
That example blocks three training crawlers and leaves everything else, including search and retrieval bots, free to read the site. Adjust it to your own choice; there is no universally right answer, and reasonable owners land in different places. On WordPress you can edit `robots.txt` either by uploading a physical file to the web root over SFTP or the File Manager, or through the `robots.txt` editor most SEO plugins provide. Note that `robots.txt` is a request, not a lock: reputable crawlers honour it, but it is not a security control, so never rely on it to hide anything sensitive. Genuinely private material belongs behind a login, as covered in the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/).
## How to Tell Whether Any of This Is Working
Honesty requires admitting that measuring AI-search success is genuinely hard, because the assistants rarely tell you when they used you. A few imperfect methods together give a usable picture.
- **Watch your referral traffic.** When someone does click through from an AI tool, it usually shows in your analytics as a referral from a domain such as `chatgpt.com`, `perplexity.ai`, `gemini.google.com` or a Copilot address. Tracking that segment over time is the closest thing to a direct signal. If you have not yet set up analytics, the Noiz guide to [setting up Google Analytics 4](/wordpress/how-to-set-up-google-analytics-4-on-your-wordpress-site/) is the place to start.
- **Spot-check by asking.** Periodically ask the main assistants the questions your content answers, and see whether they cite you, a competitor, or no one. It is manual and unscientific, but it tells you plainly where you stand on the queries you care about.
- **Track branded and comparison queries.** Growth in people searching for your name, or asking assistants to compare you with rivals, is a sign your entity is registering. Ordinary search-console data still helps here.
Expect noise and incomplete attribution, and judge trends over months rather than reacting to any single day. Anyone promising you precise, real-time measurement of AI citations is overstating what the platforms currently expose.
## Troubleshooting
- **Symptom**: visiting `yourdomain.com/llms.txt` shows a styled "page not found" instead of your text. The file is not at the true web root, so WordPress is handling the request. Confirm you uploaded it into the same folder as `wp-config.php` (commonly `public_html` or `httpdocs`), not into a subfolder or the theme.
- **Symptom**: your `llms.txt` is live but nothing about your AI visibility changed. That is the expected outcome in 2026, not a fault. The file is not a citation booster for general sites; put your effort into the GEO fundamentals and structured data instead.
- **Symptom**: you blocked `Google-Extended` to escape AI Overviews, but you still appear in them. This is by design. `Google-Extended` governs only Gemini model training, not AI Overviews, which are drawn from the normal index. Leaving them would require blocking `Googlebot`, which also removes you from Google Search, so most sites should not.
- **Symptom**: your structured-data validator reports errors, or "markup does not match visible content". The schema is describing something the page does not actually show, which search systems penalise rather than reward. Fix the plugin settings so the markup reflects the real, visible page, and never mark up content that is not on the page.
- **Symptom**: you see no AI referral traffic at all. Referrals from AI tools are genuinely low in volume because most AI use ends without a click, so a small or empty number can be normal. Confirm your analytics is installed correctly first, then judge the trend over a longer period rather than a single week.
- **Symptom**: assistants describe your business inaccurately. They are likely repeating stale or wrong information from elsewhere on the web. Correct your own site's facts and structured data, keep your naming consistent, and work on getting accurate mentions on the external sources the assistants trust, since that is where the wrong information usually originates.
AI search is one of the least settled areas in web publishing right now, and it is easy to waste effort on tactics that sound impressive and change nothing. If you would like help separating the worthwhile from the hype for your specific site, placing an `llms.txt` or robots rules on Noiz hosting, or setting up structured data and analytics so you can actually see what is happening, open a support ticket with the Noiz support team. Include your domain and a note of what you are trying to achieve, and a technician can help you focus on the parts that genuinely move the needle.
# How to Remove Sample Posts, Pages and Comments From WordPress
Source: https://docs.noiz.ie/wordpress/how-to-remove-sample-posts-pages-and-comments-from-wordpress/
Every fresh WordPress installation ships with a small set of placeholder items: one sample post, one sample comment, a sample page and a draft privacy policy page. None of it is required, and leaving it in place makes a live site look unfinished. This guide shows you how to identify and remove that sample content on a WordPress site hosted with Noiz, including the parts most guides skip: what happens to the sample comment when you bin the post it belongs to, why the draft privacy policy page is worth keeping, and how to remove the same items from the block editor and the Site Editor.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Posts Screen](https://wordpress.org/documentation/article/posts-screen/), the full reference for row actions and bulk actions on the post list.
- [Pages Screen](https://wordpress.org/documentation/article/pages-screen/).
- [Comments Screen](https://wordpress.org/documentation/article/comments-screen/), covering approve, reply, spam and bin.
- [Page and Post Settings Sidebar](https://wordpress.org/documentation/article/page-post-settings-sidebar/), where the block editor keeps its **Move to trash** control.
- [Site Editor Pages](https://wordpress.org/documentation/article/site-editor-pages/), for block themes.
- [Settings: Discussion Screen](https://wordpress.org/documentation/article/settings-discussion-screen/).
- [wp-config.php: EMPTY\_TRASH\_DAYS](https://developer.wordpress.org/apis/wp-config-php/#disable-trash), which controls how long binned items are retained.
## Prerequisites
- An Administrator (or Editor) login for the WordPress dashboard at `https://yourdomain.com/wp-admin`, replacing `yourdomain.com` with your own domain.
- Confidence about which content is genuinely placeholder. If the site has been live for a while, check the publish dates before deleting anything.
- A current backup if the install is anything other than brand new. Noiz takes scheduled backups of hosting accounts, but taking your own restore point before a bulk deletion costs nothing.
## What a Fresh WordPress Install Actually Contains
WordPress creates exactly four items during installation. Knowing all four saves you from cleaning up three and leaving the fourth in place:
- **Post:** **Hello world!**, published, at the slug `hello-world`.
- **Comment:** a single approved comment on that post, authored by **A WordPress Commenter** from the address `wapuu@wordpress.example`, with an outbound link on the author name.
- **Page:** **Sample Page**, published, at the slug `sample-page`.
- **Page:** **Privacy Policy**, saved as a **draft** at the slug `privacy-policy`. Because it is a draft it never appears on the front end, which is why most people never notice it.
**The gotcha worth knowing first:** the sample comment belongs to the sample post. When you bin the post, WordPress moves its comment to an internal `post-trashed` state and it disappears from the **Comments** screen along with it. So if you delete the post first, the comment is already handled. Step 3 below still matters if you decided to keep the **Hello world!** post, or if you are cleaning up a site where the post was edited into real content but the placeholder comment was left underneath it.
## Step 1: Remove the Sample Post
1. Log in to the WordPress dashboard.
2. In the left-hand admin menu, go to **Posts** and click **All Posts**. 
3. Hover your mouse over the **Hello world!** row. A set of row actions appears underneath the title. Click **Trash**. 
If you are clearing several posts at once, tick the checkbox in the header row to select everything on screen, choose **Move to Trash** from the **Bulk actions** dropdown, and click **Apply**.
**Note on wording:** a default WordPress install uses American English, so the action is labelled **Trash**. If the site language is set to English (UK) or another locale, the same action may be labelled **Bin**. It behaves identically.
## Step 2: Remove the Sample Page
Pages live on their own screen, not under **Posts**. This is the single most common place people get stuck, because **Sample Page** is nowhere to be found on the posts list.
1. In the admin menu, go to **Pages** and click **All Pages**.
2. Hover over the **Sample Page** row and click **Trash**. 
**Leave the Privacy Policy page alone, or better, finish it.** The draft **Privacy Policy** page on the same screen is not clutter in the same sense. WordPress links a designated privacy policy page from login and registration screens, and any South African site that collects personal information (a contact form is enough) has obligations under POPIA. Rather than binning it, open it, replace the boilerplate with a policy that reflects what your site actually collects, and publish it. Confirm the page is still designated under **Settings** then **Privacy**. If you genuinely do not want a privacy policy page yet, leaving it as an unpublished draft is harmless.
## Step 3: Remove the Sample Comment
Only needed if you kept the **Hello world!** post, or if the comment survived an earlier cleanup.
1. Click **Comments** in the admin menu.
2. Hover over the comment from **A WordPress Commenter** and click **Trash**. 
Do not click **Spam** here out of habit. Marking the default comment as spam trains the anti-spam service on a legitimate entry and, on sites that share spam data, is mildly counterproductive. **Trash** is the correct action.
## Step 4: Empty the Bin to Delete Permanently
Binning an item does not delete it. It stays in the database with a `trash` status until it is purged.
1. On the **Posts**, **Pages** or **Comments** screen, click the **Trash** link in the row of status filters above the list.
2. Click **Empty Trash** to delete everything listed permanently, or hover an individual row and click **Delete Permanently**.
Left alone, WordPress purges binned items automatically after **30 days**. That interval is set by the `EMPTY_TRASH_DAYS` constant in `wp-config.php`. If a site sets it to `0`, the bin is disabled entirely and the row action reads **Delete Permanently** instead of **Trash**, with no undo. Check that before you start clicking on a site you did not build.
One small benefit of the bin: WordPress appends `__trashed` to the slug of a binned post or page immediately, so the `hello-world` and `sample-page` slugs are freed for reuse straight away. You do not have to empty the bin before creating a new page at `/sample-page`.
## Doing the Same Thing From the Block Editor
If you have already opened an item in the block editor, you do not need to go back to the list screen:
- Open the settings sidebar (the panel icon at the top right), select the **Post** or **Page** tab, and scroll to the bottom for **Move to trash**.
- Alternatively, use the **Options** menu (the three vertical dots at the top right) and choose **Move to trash**.
On a site running a **block theme**, pages can also be managed from the Site Editor. Go to **Appearance** then **Editor**, click **Pages**, select **Sample Page**, and use the actions menu to move it to the bin. The classic **Pages** screen still works on block themes and is usually faster for a one-off cleanup.
## Worth Checking Once the Placeholder Content Is Gone
- **Navigation menus.** Removing a page does not always remove its menu entry. On a classic theme, tidy up under **Appearance** then **Menus**. On a block theme, edit the Navigation block in the Site Editor.
- **Comments you may not want at all.** If the site is a brochure or business site rather than a blog, go to **Settings** then **Discussion** and untick **Allow people to submit comments on new posts**. Note that this only applies to content created afterwards; existing posts keep their individual comment setting, which you can change in bulk from the posts list using **Bulk actions** then **Edit**.
- **An empty blog index.** If **Hello world!** was the only post and the home page is set to show latest posts, the front page will read "Nothing Found" until you publish something. Either publish a first real post, or set a static front page under **Settings** then **Reading**.
- **Unused default themes and plugins.** A fresh install also carries the bundled twenty-something themes and the Hello Dolly plugin. Every inactive theme and plugin still ships code that must be kept patched, so delete what you will not use. Keep one default theme installed as a fallback for troubleshooting.
## Troubleshooting
**Symptom: no Trash link appears when hovering a row.** Row actions only appear on hover over the row itself, and only for users whose role permits deletion. Subscribers and Contributors cannot delete published content. If every row shows **Delete Permanently** instead, the site has `EMPTY_TRASH_DAYS` set to `0` in `wp-config.php`.
**Symptom: the sample post is gone from the dashboard but still loads on the live site.** This is caching, not WordPress. Clear any caching plugin, then any server-side or CDN cache in front of the site, then reload with a hard refresh or in a private browsing window.
**Symptom: the sample comment vanished before you got to it.** Expected behaviour. It was attached to the **Hello world!** post and followed it into the bin. Restore the post and the comment returns with it.
**Symptom: Sample Page still shows in the site menu.** The menu item is a separate object from the page. Remove it from **Appearance** then **Menus**, or from the Navigation block if the theme is a block theme.
**Symptom: the sample content came back.** Something re-ran an installation over the top, most commonly a fresh install pushed to the same directory, or a staging site cloned back over production. Check the publish dates on the restored items to confirm.
## Need a Hand?
If you are unsure whether something is placeholder content or the real thing, stop before you empty the bin and open a support ticket from the Noiz client area. Noiz can check the account backups and confirm what the site looked like before the change. On managed plans, the Noiz team is happy to do the post-install tidy-up for you as part of a new site handover.
# How to Rename the Default Uncategorized Category in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-rename-the-default-uncategorized-category-in-wordpress/
Every WordPress site starts with a single post category called **Uncategorized**, and every post published without a category chosen for it lands there. It is the one category WordPress will not let you delete, which is why the **Delete** link that appears on every other category is missing from its row. This guide shows you how to rename it into something useful, and, if you would rather it did not exist at all, how to remove it properly by promoting a different category to default first.
Renaming takes about thirty seconds. The part worth reading is what happens to the category's web address when you change its slug, because that is where sites quietly break.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Documentation: Posts Categories screen](https://wordpress.org/documentation/article/posts-categories-screen/)
- [WordPress Documentation: Categories](https://wordpress.org/documentation/article/categories/)
- [WordPress Documentation: Settings Writing screen (where the default post category is set)](https://wordpress.org/documentation/article/settings-writing-screen/)
- [WordPress Documentation: Settings Permalinks screen (category base)](https://wordpress.org/documentation/article/settings-permalinks-screen/)
- [WP-CLI: wp term update (rename a category from the command line)](https://developer.wordpress.org/cli/commands/term/update/)
## Prerequisites
- A WordPress site on your Noiz hosting account.
- A dashboard login with the **Administrator** or **Editor** role. Authors and Contributors cannot manage categories.
- A decision on the new name. Changing the slug as well changes a live URL, so read the section on slugs before you type anything into that field.
## Step 1: Log In to the WordPress Dashboard
Go to `https://yourdomain.com/wp-admin` (replace `yourdomain.com` with your own domain) and sign in.
If you have mislaid the dashboard password, you do not need to reset it to make this change. The WordPress management tooling in your Noiz control panel lists each installed site and offers a one-click login that signs you in as an administrator, so you can go straight to step 2 from there.
## Step 2: Open Posts and Then Categories
In the left-hand dashboard menu, hover over **Posts** and click **Categories**.

The screen splits in two: **Add New Category** on the left, and the table of existing categories on the right. **Uncategorized** is in that table, and on a new site it is usually the only entry.
Look at the **Count** column beside it before you go further. That number is how many published posts are currently filed under Uncategorized, and it tells you whether you are tidying up a label nobody sees or renaming a category that is already showing on the front of the site.
## Step 3: Hover Over Uncategorized and Click Quick Edit
Move your mouse over the **Uncategorized** row. A small set of links fades in underneath the name.

On every other category you would see four links: **Edit**, **Quick Edit**, **Delete** and **View**. On Uncategorized the **Delete** link is absent, and the row has no checkbox for the bulk **Delete** action either. That is not a bug or a permissions problem. WordPress is refusing, because this category is currently set as the site's default. The section further down explains how to change that.
Click **Quick Edit**. The row turns into two editable fields without leaving the page.
## Step 4: Change the Name and Slug, Then Update
Quick Edit gives you exactly two fields:
- **Name**: what visitors see wherever the category is displayed, such as under a post title, in a sidebar widget, or in a breadcrumb trail. Change this to something that describes the content, for example `News`, `Blog` or `Updates`.
- **Slug**: the version of the name used in the URL. Lowercase letters, numbers and hyphens only. Leaving it alone is safe. Changing it is not always safe, and the next section explains why.
Confirm with **Update Category**.

The table refreshes with the new name. Nothing else about the category has changed: it keeps the same numeric ID, the same posts, the same description, and it is still the site's default category. Every post that was filed under Uncategorized is now filed under the new name automatically, because it is the same category wearing a different label.
If you also want to add or edit the **Description**, or make the category a child of another one, use the full **Edit** link instead. Quick Edit deliberately exposes only the name and the slug.
## What Changing the Slug Does to Your URLs
The slug is the piece of the category archive address that identifies the category. With WordPress permalinks set to anything other than plain, the archive lives at:
```
https://yourdomain.com/category/uncategorized/
```
Change the slug to `news` and that page becomes:
```
https://yourdomain.com/category/news/
```
The old address stops working and returns a 404. On a site that has been live for a while, that matters:
- Links to the old category archive from other sites, newsletters or social posts now land on an error page.
- Search engines have the old URL indexed and will drop it once they see the 404.
- Anything hard-coded in a theme, a menu item or a widget that points at the old path breaks.
Two things fix this. First, put a permanent redirect in place from the old path to the new one, which preserves both visitors and search ranking. The guide on [redirecting a page using .htaccess](/server-administration/how-to-redirect-a-page-to-another-page-or-website-using-htaccess/) covers the exact rule. Second, check **Appearance** then **Menus** for any menu item pointing at the old category, since custom links do not update themselves.
On a brand new site with no traffic and nothing indexed, none of this applies and you can change the slug freely.
## Why Uncategorized Cannot Be Deleted
WordPress requires every post to belong to at least one category. If you publish a post and pick no category, WordPress has to file it somewhere, so it uses the category set as **Default Post Category** in the site settings. On a fresh install that is Uncategorized.
Because deleting the default would leave WordPress with nowhere to put uncategorised posts, the interface simply removes the option: no **Delete** link on the row, and no checkbox for the bulk action. The restriction applies to whichever category is set as default, not to the word "Uncategorized" itself. Promote a different category to default and the old one becomes deletable immediately, while the new default loses its own Delete link.
This is also why deleting a category never deletes the posts inside it. WordPress reassigns them to the default category instead. If posts seem to vanish after you delete a category, look in the default category rather than in the trash.
## How to Remove Uncategorized Completely
If you want it gone rather than renamed, do it in this order.
### 1. Create the Category That Will Replace It
On the same **Posts** then **Categories** screen, fill in the **Add New Category** box on the left with the name you want, then click **Add New Category**. The full walkthrough is in [How to Add a New Category in WordPress](/wordpress/how-to-add-a-new-category-in-wordpress/).
### 2. Make It the Default
Go to **Settings** then **Writing**. The first option on that screen is **Default Post Category**. Select your new category from the drop-down and click **Save Changes**.
### 3. Move the Existing Posts (Optional but Sensible)
If Uncategorized still holds posts, decide where they should go before you delete it. Deleting the category will sweep every one of them into the new default, which may not be where each of them belongs.
To place them deliberately, open **Posts** then **All Posts**, use the category filter at the top to show only Uncategorized posts, tick the ones you want, choose **Edit** from the **Bulk actions** menu and click **Apply**. Tick the correct category in the panel that opens, then click **Update**. Note that bulk edit can only add a category, not remove one, so the posts will briefly sit in both. Deleting Uncategorized in the next step removes it from them.
### 4. Delete the Old Category
Return to **Posts** then **Categories**. The **Delete** link now appears on the Uncategorized row. Click it and confirm. Full detail on this step is in [How to Delete Categories in WordPress](/wordpress/how-to-delete-categories-in-wordpress/).
## Renaming It From the Command Line
If your Noiz plan includes SSH access and WP-CLI is available, the same change is a single command run from the site's root directory. Uncategorized is term ID `1` on almost every install:
```
wp term update category 1 --name="News" --slug="news"
```
To change which category is the default:
```
wp option update default_category 7
```
Replace `7` with the ID of your chosen category, which you can find by hovering over its name in the dashboard and reading the `tag_ID` value in the status bar, or by running `wp term list category --fields=term_id,name,slug`. This route is worth knowing if you are setting up several sites and want the same tidy-up applied to each without clicking through the dashboard.
## Gotchas Worth Knowing
- **The old name can linger in caches.** If a caching plugin, a server-side page cache or a CDN is in front of the site, the previous name may keep appearing on the public pages for a while. Purge the cache after renaming, then reload with a hard refresh.
- **Category names must be unique.** If the name you want already exists, WordPress rejects it. Slugs must be unique too, and if you enter one already in use, WordPress silently appends a number, giving you `news-2`.
- **Pages do not use categories.** Only posts do. Renaming Uncategorized has no effect on your pages, and a page will never appear in a category archive.
- **WooCommerce keeps its own Uncategorized.** Product categories are a separate taxonomy with a separate default, set under **WooCommerce** then **Settings** then **Products**. Renaming the post category leaves the product one untouched, and vice versa.
- **The category ID never changes.** Renaming affects the label and, if you choose, the slug. Anything referencing the category by ID, such as a widget, a shortcode or a theme template, carries on working.
- **The word itself depends on the site language.** On a site installed in another language the default category is named in that language, but it behaves identically and sits in the same place.
- **The `/category/` part of the URL is separate.** That prefix is the category base, set under **Settings** then **Permalinks**. Changing a category slug does not touch it, and changing the base affects every category at once.
- **On multisite, each site is independent.** Renaming the default category on one site in a network changes nothing on the others.
## Troubleshooting
**Symptom**: There is no **Delete** link on the Uncategorized row. This is expected. It is the site's default post category. Set a different category as default under **Settings** then **Writing**, and the link appears.
**Symptom**: Hovering shows no links at all, or **Quick Edit** does nothing when clicked. Quick Edit relies on JavaScript in the dashboard. A plugin conflict or a JavaScript error will disable it. Use the **Edit** link to open the full category screen instead, which works without it, and check the browser console for the underlying error.
**Symptom**: The **Categories** item is missing from the Posts menu. Your user role does not include the capability to manage categories. Sign in with an Administrator account, or ask the site owner to raise your role.
**Symptom**: The category archive returns a 404 after changing the slug. Go to **Settings** then **Permalinks** and click **Save Changes** without altering anything. That rewrites the permalink rules and usually clears it straight away.
**Symptom**: The new name saved, but the site still shows "Uncategorized". Either a cache is serving an old copy, or what you are looking at is not the category name. Some themes print a hard-coded label, and some plugins add their own taxonomy. Check the Categories table to confirm the rename actually took.
**Symptom**: Uncategorized reappears after you thought you had removed it. WordPress recreates a default category if the ID recorded in its settings no longer points to a real category, which happens when a category is deleted directly in the database rather than through the dashboard. Set a valid default under **Settings** then **Writing**, then delete the stray one from the Categories screen.
**Symptom**: Posts disappeared after you deleted a category. They were not deleted. WordPress moved them into the default category. Open **Posts** then **All Posts** and filter by that category to find them.
## Related Guides
- [How to Add a New Category in WordPress](/wordpress/how-to-add-a-new-category-in-wordpress/)
- [How to Delete Categories in WordPress](/wordpress/how-to-delete-categories-in-wordpress/)
- [How to Remove Sample Comments and Posts From WordPress](/wordpress/how-to-remove-sample-posts-pages-and-comments-from-wordpress/)
- [How to Redirect a Page to Another Page or Website Using htaccess](/server-administration/how-to-redirect-a-page-to-another-page-or-website-using-htaccess/)
## Need a hand?
Renaming a category is harmless, but changing a slug on an established site can cost you traffic if the old address is left returning a 404. If you are on a managed Noiz plan and would like the redirect put in place at the same time, or you want the category structure of an inherited site sorted out properly, contact the Noiz support team through the client area with your domain name and the team will assist.
# How to Reset WordPress File and Directory Permissions
Source: https://docs.noiz.ie/wordpress/how-to-reset-wordpress-file-and-directory-permissions/
This guide shows you how to reset the file and directory permissions of a WordPress site back to safe, working values when uploads, updates or plugin installs have started failing, or when a security scan has flagged files as too open. File permissions (sometimes called the file *mode*, or set with the `chmod` command, so you may see them written as "CHMOD 644") decide who is allowed to read, change or run each file and folder on the server. Get them wrong in one direction and WordPress cannot write to its own folders; get them wrong in the other and you hand an attacker an easy way in. This article explains what the correct values are, why the wrong ones break things, and how to put them right using an SFTP client, your hosting panel's File Manager, or a couple of `find` and `chmod` commands over SSH. It is written for Noiz clients who run WordPress, and the same values apply whether your site is on Plesk, DirectAdmin or ISPConfig.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Changing File Permissions (WordPress Developer Resources)](https://developer.wordpress.org/advanced-administration/server/file-permissions/): the reference values, the reasoning behind them, and the strong warning against ever using 777.
- [Hardening WordPress (WordPress Developer Resources)](https://developer.wordpress.org/advanced-administration/security/hardening/): how ownership and permissions fit into securing a site, including the recommended lockdown for `wp-config.php`.
## Prerequisites
- A way to reach your site's files: an SFTP client, your hosting panel's File Manager, or SSH access. Each method is covered below, so you only need one.
- The path to your WordPress installation, that is, the folder that holds `wp-config.php`, `wp-admin`, `wp-content` and `wp-includes`. On Noiz hosting this is your domain's document root, for example `httpdocs` on Plesk or `public_html` on DirectAdmin.
- A recent backup, or the confidence that you can take one. Resetting permissions is reversible and low-risk, but it is good practice to have a restore point before any bulk change.
If you are on a managed plan and would rather not do this yourself, skip to the end: the Noiz support team can reset permissions and ownership for you.
## What File Permissions Actually Mean
Every file and folder on a Linux server carries a three-digit number such as `644` or `755`. It looks cryptic, but it decodes very simply, and understanding it makes the rest of this guide obvious rather than something to memorise.
The three digits describe three groups of people, in this order:
- The **owner** of the file (your hosting account).
- The **group** the file belongs to (often the web server).
- **Everyone else** on the server.
Each digit is the sum of three possible permissions: **read** is worth 4, **write** is worth 2, and **execute** is worth 1. So a digit of `6` means read plus write (4+2), a digit of `5` means read plus execute (4+1), and a digit of `4` means read only. Reading `644` from left to right, then, means: the owner can read and write, while the group and everyone else can only read.
The one part that trips people up is **execute** on a folder. For a directory, the execute bit does not mean "run a program"; it means "you are allowed to enter this folder and list what is inside". That is why directories need a `5` (read plus execute) where files only need a `4` (read). A folder set to `644` cannot be entered by anyone, which quietly breaks everything below it. Keep that single fact in mind and the common mistakes below will make sense.
## The Correct Permissions for WordPress
These are the values WordPress itself recommends and the values its automatic updater applies to your files. Setting everything to match is exactly what "resetting permissions" means.
- **Directories: 755.** The owner can read, write and enter the folder; everyone else can read and enter but not change it. Every folder in the install, including `wp-content` and `wp-content/uploads`, uses this value.
- **Files: 644.** The owner can read and change the file; everyone else can only read it. This covers almost every file in the install, including your theme files, plugin files and `.htaccess`.
- **wp-config.php: 640 or 600.** This one file holds your database name, username and password, so it deserves tighter treatment than an ordinary `644` file. Lock it down separately after the bulk reset, as described later.
- **Never 777, on anything.** A `777` file or folder is writable by every account on the server. WordPress is blunt about this: no directory should ever be 777, not even the uploads folder. It is one of the most common ways a shared-hosting site is compromised.
A useful sanity check: on a healthy WordPress install, if you look at the mode of any folder you should see `755`, and any file should see `644`. The only routine exception is `wp-config.php`. If you see `777`, `666` or a mix of odd values, something has drifted and this reset will fix it.
### A note on ownership, which is not the same thing
Permissions decide what each category of user may do; **ownership** decides who the "owner" actually is. On Noiz hosting your files should be owned by your own hosting account, and because the PHP process runs as that same account, the standard `755`/`644` values give WordPress everything it needs to write to its own folders. Problems appear when files end up owned by the wrong user, which can happen after a clumsy manual upload, an archive extracted as the web server, or a migration from another host. When ownership is wrong, no amount of `chmod` will fix upload or update failures, because the numbers are being applied to the wrong owner. Correcting ownership needs root-level access, so if you suspect this, that is a job for the Noiz support team rather than something you can set in a File Manager.
## Why the Wrong Permissions Break Things
Permissions fail in two opposite directions, and the symptoms are different, so it helps to recognise both.
### Too restrictive: WordPress cannot write to itself
WordPress needs to write into its own folders to do everyday work: saving an uploaded image, unpacking a plugin or theme, or installing a core update. If the folders are too locked down for the account that runs PHP to write to them, those actions fail. The tell-tale signs are:
- Media uploads fail with a message like *"Unable to create directory wp-content/uploads/2026/07. Is its parent directory writable by the server?"*
- Installing or updating a plugin, theme or WordPress core fails with *"Installation failed: Could not create directory"* or *"Could not copy file"*.
- WordPress unexpectedly asks you for FTP or SSH connection details when you try to install or update something. That prompt is WordPress admitting it cannot write to the folder directly and looking for another way in.
- A folder accidentally set to `644` (missing the execute bit) produces a *403 Forbidden* error or a blank white page for everything inside it, because the server is no longer allowed to enter that folder.
### Too permissive: a security hole, and sometimes a 500 error
Loosening permissions to "make it work", usually by setting things to `777`, is the wrong fix and creates two new problems. The first is security: a world-writable file or folder can be modified by any other account on the server, which is exactly the foothold attackers look for on shared hosting. The second is more surprising. Many modern hosting setups, including the way PHP runs on Noiz servers, deliberately **refuse to execute** a script that is writable by the group or by everyone, treating it as unsafe. So a file you set to `777` to fix an upload can instead give every visitor a *500 Internal Server Error*, because the server now declines to run it. The correct values, `644` and `755`, avoid both problems at once, which is the whole point of resetting rather than loosening.
## Method A: Reset Permissions Over SSH (Most Precise)
If you have SSH access, this is the cleanest way to reset an entire install, because the `find` command can target files and directories separately and apply the right value to each in one pass. This is precisely what the two-pass warning in the GUI methods below is trying to work around by hand.
Change into your WordPress root first, then run the two resets:
```
cd /path/to/your/wordpress
# Set every directory to 755
find . -type d -exec chmod 755 {} \;
# Set every file to 644
find . -type f -exec chmod 644 {} \;
```
The `-type d` filter matches directories only and the `-type f` filter matches files only, so directories keep their essential execute bit and files never gain one. Replace `/path/to/your/wordpress` with your actual document root, for example the full path to your `httpdocs` or `public_html` folder. Once both commands finish, harden `wp-config.php` as described further down.
## Method B: Reset Permissions With an SFTP Client
If you connect to your site with an SFTP client, you can reset permissions through its interface. The important thing to understand is that a graphical tool cannot tell files and folders apart the way `find` can, so you must do the job in **two separate passes** and use the client's "apply to" options carefully. Doing it in one careless pass is the single most common way people make the problem worse.
Connect to your site over SFTP and navigate to your WordPress root folder, then:
1. **First pass, directories.** Select the WordPress root folder, open its permissions or attributes dialogue (in most clients this is a right-click, then **File permissions** or **Attributes**), and enter the numeric value `755`. Tick the option to **recurse into subdirectories**, and then choose the option to **apply to directories only**. Confirm. This sets every folder in the install to `755` without touching the files.
2. **Second pass, files.** Open the same dialogue again on the WordPress root folder, this time entering `644`, ticking **recurse into subdirectories**, and choosing **apply to files only**. Confirm. This sets every file to `644` without touching the folders.
**Why the two passes matter.** If you instead recurse `644` onto everything, you strip the execute bit off every directory and the whole site goes down with 403 or blank-page errors, exactly the mistake described earlier. If you recurse `755` onto everything, your files become needlessly executable. Keeping directories and files separate is the entire trick, and the "apply to directories only" and "apply to files only" options are what make it possible in a GUI.
## Method C: Reset Permissions in the Hosting Panel File Manager
Every Noiz hosting panel includes a File Manager that can change permissions without any separate software, which is handy if you do not have an SFTP client set up. The exact labels differ between panels, but the principle is identical to the SFTP method: reset directories and files in two separate recursive passes.
- On **Plesk** (Noiz South African hosting), open **Files**, select the WordPress folder, and use **Change Permissions**. Plesk lets you tick the group and owner permission boxes and apply the change recursively to subfolders and files, so set directories to `755` and files to `644` in turn.
- On **DirectAdmin** (Noiz Ireland hosting), open the **File Manager**, select your items, and use **Set Permission** with the recursive option to apply `755` to folders and `644` to files.
- On **ISPConfig**, the built-in file tools are more limited, and for a full recursive reset SFTP (Method B) or SSH (Method A) is usually the smoother route.
Whichever panel you use, apply the same discipline as with SFTP: one recursive pass for directories at `755`, a second recursive pass for files at `644`, and never a single blanket pass over both.

## Lock Down wp-config.php Separately
After the bulk reset, `wp-config.php` will be sitting at `644` along with every other file, which means any other account on the server could read your database password. Because this file is uniquely sensitive, tighten it on its own:
```
chmod 640 /path/to/your/wordpress/wp-config.php
```
A value of `640` lets your account read and write the file and lets the web server's group read it, while everyone else is shut out. On the per-account PHP setup used across Noiz hosting, where PHP runs as your own user, you can go further to `600` (owner only) and WordPress will still read the file perfectly. The official WordPress hardening guide suggests the even tighter `440` or `400`, which make the file read-only to everyone including you; those work too, with the small trade-off that you must temporarily relax the file back to `640` if you ever need to edit it. Any of `640`, `600`, `440` or `400` is a sound choice; `644` for this one file is not.
You can set the same value through your SFTP client or File Manager if you prefer: right-click `wp-config.php`, open its permissions dialogue, and enter `640` for that single file only.
## Confirm the Reset Worked
Two quick checks confirm the site is healthy again:
- **The site loads normally.** Visit your home page and a couple of inner pages. If they load without 403 or blank-page errors, your directories have their execute bit back.
- **WordPress can write again.** [Log in to your WordPress dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) and upload a test image under **Media > Add New**. A successful upload proves `wp-content/uploads` is writable and that the earlier upload or update failures are resolved.
## Troubleshooting
- **Symptom**: after a recursive change the whole site shows *403 Forbidden* or a blank white page. You almost certainly applied `644` to directories as well as files, stripping the execute bit off every folder. Re-run the directory pass, setting all directories back to `755` (Method A does this cleanly with `find . -type d -exec chmod 755 {} \;`).
- **Symptom**: uploads or updates still fail after the reset, with "could not create directory" style messages. The permissions are now correct, so the likely cause is **ownership**: some files are owned by the wrong user and `chmod` cannot help. This needs root access to fix. Contact the Noiz support team, quoting the exact error and your domain.
- **Symptom**: a *500 Internal Server Error* appeared after you set something to `777` or `666` to try to fix an upload. The server is refusing to run a file that is writable by group or others. Reset that file to `644` (or the folder to `755`) and the error will clear; then solve the original write problem properly, not by loosening permissions.
- **Symptom**: WordPress keeps asking for FTP or SSH credentials whenever you install or update anything. WordPress cannot write to its folders directly. Run the reset above so directories are `755` and files `644`; if it persists, ownership is the likely culprit and support can confirm.
- **Symptom**: a security scan reports `wp-config.php` as world-readable even after the reset. The bulk pass set it to `644`; tighten it separately to `640` or `600` as shown above.
Correct file permissions are one layer of a well-secured site rather than the whole story. For the wider picture, including keeping WordPress, plugins and themes current and limiting where files can be written from, see the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/).
If you are on a managed Noiz plan, or you would simply rather not touch permissions by hand, open a support ticket and the Noiz support team will reset your file and directory permissions, correct any ownership problems, and lock down `wp-config.php` for you. Include your domain and, if you have one, the exact error message you are seeing, so the fix can be applied straight away.
# How to Reset a WordPress Admin Password via phpMyAdmin
Source: https://docs.noiz.ie/wordpress/how-to-reset-a-wordpress-admin-password-via-phpmyadmin/
If you have lost access to your WordPress admin account, you can reset the password directly in the site database using phpMyAdmin. This method is useful when the password-reset email is not arriving, when the mail service on the site is broken, or when you no longer have access to the admin email address the account was registered with.
**Last reviewed:** 27 July 2026, against WordPress **6.x** (current stable series). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Resetting your password](https://wordpress.org/documentation/article/reset-your-password/) (includes the phpMyAdmin method)
- [Editing wp-config.php](https://developer.wordpress.org/advanced-administration/wordpress/wp-config/) (where to find your database name and table prefix)
## Prerequisites
- Access to phpMyAdmin for the account that hosts the WordPress site. On Noiz hosting, open phpMyAdmin from your hosting control panel under **Databases**.
- The database name and table prefix used by the site. If you are unsure, both are listed in the site's `wp-config.php` file (the `DB_NAME` constant and the `$table_prefix` value).
## Reset a WordPress Admin Password
1. Open **phpMyAdmin**.
2. Select your WordPress database from the left-hand menu (for example **wp\_example**). If several databases are listed and you are not sure which one belongs to the site, check the `DB_NAME` value in `wp-config.php`.
3. Select the **wp\_users** table. If the site uses a custom database prefix, this table will be named **yourprefix\_users** instead. Account for your custom prefix throughout this procedure.
4. Locate the user whose password you want to reset and click **Edit** next to that row.
5. Find the **user\_pass** field and update it as follows:
- In the **Function** dropdown on the left, select **MD5**. **Important:** if this is not set to MD5, the value will be stored as plain text and the new password will not work.
- In the **Value** field, enter the new password in plain text. phpMyAdmin applies the MD5 hash for you when the row is saved.
6. Click the **Go** button at the bottom of the page to save the change.
7. A green success banner confirms the row was updated. If you get a red error instead, read the error message to identify and correct the issue.
You should now be able to log in to your WordPress site using the username and the new password you just set.
## Why the MD5 Method Still Works on Modern WordPress
MD5 is an old hashing algorithm and is not the format WordPress uses for new passwords. Current WordPress releases hash new passwords with a stronger algorithm, but they still recognise the legacy MD5 format for backward compatibility. When the user next logs in successfully, WordPress verifies the MD5 hash, then transparently re-hashes the password to its modern default format and stores that instead. Setting MD5 through phpMyAdmin is therefore a safe, temporary bridge, not a permanent weakening of the account.
## Troubleshooting
- **The new password is rejected:** confirm you selected **MD5** in the Function dropdown before saving. If the field was saved as plain text, edit the row again and re-save it with MD5 selected.
- **You edited the row but nothing changed:** check that you updated the correct user row and that you are working in the correct database and table prefix. A site with several WordPress installs under one account can have more than one users table.
- **Login still fails after a correct reset:** a security or two-factor-authentication plugin may still be blocking the account, since this method only changes the password. It does not disable 2FA or clear an account lockout. A caching plugin or a login-page cache can also serve a stale form, so clear your browser cache and try an incognito window.
If you are still stuck, contact the Noiz support team and they can handle this for you. Please note that if you are not on a managed WordPress plan, this work may be billable.
# How to Safely Edit Your WordPress Theme
Source: https://docs.noiz.ie/wordpress/how-to-safely-edit-your-wordpress-theme/
This guide shows you how to change the look or behaviour of your WordPress theme without risking your live site. It explains why the tempting shortcut, the built-in theme file editor, is the method most likely to take a site offline, and it walks through the safer approaches: a child theme for changes that must survive theme updates, a code-snippet plugin for small functional additions, and the CSS tools already built into WordPress for pure styling tweaks. It also covers how to decide which method fits the job, and how to recover if an edit does break the site. A theme is the design layer of your site, the parent theme is the one you installed, and a child theme is a small companion theme that overrides parts of it.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Child Themes (Theme Developer Handbook)](https://developer.wordpress.org/themes/advanced-topics/child-themes/): the authoritative reference for the `style.css` header, the `Template` field, enqueuing styles and block-theme child themes.
- [Appearance Theme File Editor Screen](https://wordpress.org/documentation/article/appearance-theme-file-editor-screen/): the official description of the built-in editor, including its warning that it keeps no backups.
- [wp-config.php constants (Advanced Administration)](https://developer.wordpress.org/advanced-administration/wordpress/wp-config/): the `DISALLOW_FILE_EDIT` and `DISALLOW_FILE_MODS` constants that switch the file editor off.
- [Global Settings and Styles (theme.json)](https://developer.wordpress.org/block-editor/how-to-guides/themes/global-settings-and-styles/): how block themes handle styling, which is where a block-theme child theme does most of its work.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an administrator.
- A full, recent backup of both your files and your database, taken *before* you make any change. See the first section below.
- A way to reach your site's files outside WordPress, for recovery: the **File Manager** in your Noiz hosting control panel, or an SFTP/FTP client with your hosting login. You may never need it, but if an edit crashes the site this is how you undo it.
- Knowing whether your active theme is a **block theme** or a **classic theme**. A quick test: in the admin menu, look under **Appearance**. If you see **Editor**, you are on a block theme; if you see **Customize** instead, you are on a classic theme. This changes where some menus live and how a child theme is built.
## Back Up Before You Touch Anything
Every method below can be undone if you have a backup and cannot be undone easily if you do not. A single missing semicolon in a PHP file produces a fatal error that replaces your whole site with a blank page or an error message, and if that file is your theme's code you cannot always fix it from inside WordPress.
- Managed Noiz plans keep their own backups, but take a fresh one immediately before editing so your restore point is minutes old, not hours or days.
- Back up **both** the files and the database. Theme code lives in files; content and settings live in the database; a safe restore needs the pair to match.
- If your plan includes a **staging** site, make your change there first, confirm the site still loads and behaves, and only then repeat it on the live site. A staging copy is a throwaway clone, so a mistake there costs you nothing.
## Understand Your Options Before You Edit
There is no single "edit the theme" button that is safe for everything. The right tool depends on what you are changing. Match the job to the method:
- **Only changing colours, spacing or other styling?** Use the CSS tools already built into WordPress. You do not need to edit a theme file at all. See *Add CSS Without Editing a File* below.
- **Adding a small piece of functionality**, for example a snippet you were given to change checkout behaviour or add a tracking tag? Use a code-snippet plugin. See *Add Functional Code With a Snippet Plugin*.
- **Changing templates, overriding theme files, or making larger design changes** that must survive theme updates? Use a child theme. See *Use a Child Theme for Lasting Changes*.
- **Just want to read the code, or make a throwaway test on a staging site?** The built-in editor is fine for viewing. Understand its risks first, in the next section.
The one method to avoid for anything permanent on a live site is editing your active theme's files directly, whether through the built-in editor or by overwriting them over FTP. The next section explains why.
## Why the Built-in Theme File Editor Is Risky
WordPress ships with a plain-text code editor for theme files. Where you find it depends on your theme type:
- **Classic theme active:** **Appearance** > **Theme File Editor**.
- **Block theme active:** the code editor moves to **Tools** > **Theme File Editor**, because **Appearance** > **Editor** is now the visual Site Editor, which is a different thing.

The editor works, but it has three properties that make it dangerous on a live site:
- **It edits the live site instantly.** When you click **Update File**, the change is live for every visitor at once. There is no draft and no preview.
- **It keeps no backup.** The official documentation states plainly that the editor does not make backup copies. If your change crashes the site, you cannot use the editor to fix it, because a crashed site often will not load the admin area either.
- **Your changes are wiped by theme updates.** Editing the active theme's files means the next theme update overwrites them with the developer's new version, silently removing your work.
Because of these three points, treat the built-in editor as a read-only viewer on production. It is safe to *look* at code with it; it is the wrong place to *save* changes you want to keep. The safer methods below fix all three problems: they preview or fail safely, they can be undone, and they survive theme updates.
## Add CSS Without Editing a File
Most "change the theme" requests are really styling requests: a different colour, a hidden element, more spacing. WordPress has a built-in place to add your own CSS that is stored separately from the theme, so it is never lost when the theme updates and never crashes the site (bad CSS simply does not apply, it cannot take the site offline the way bad PHP can).
- **Classic theme:** go to **Appearance** > **Customize** > **Additional CSS**. Type your CSS, watch the live preview update, and click **Publish**.
- **Block theme:** go to **Appearance** > **Editor** > **Styles**, open the three-dot menu, choose **Additional CSS**, add your rules and save.
If a change can be expressed in CSS, prefer this route over any theme file. It is the simplest safe method and needs no plugin.
## Add Functional Code With a Snippet Plugin
When you need actual PHP, for example a snippet that adds a feature or alters a behaviour, the traditional advice was to paste it into the theme's `functions.php`. On a live site that carries the same risks as the built-in editor: a typo crashes everything, and a theme update erases your snippet. A **code-snippet plugin** solves both problems and is the neutral, low-risk choice for most people.
These plugins store your PHP in the database, separate from the theme, and run it for you. Because the code lives outside the theme it survives theme updates and even switching themes entirely. Well-made snippet plugins also validate code before activating it and can automatically deactivate a snippet that would cause a fatal error, so a mistake stops that one snippet rather than the whole site. Several such plugins exist in the WordPress plugin directory (for example Code Snippets or WPCode, named only as examples, not a recommendation); any actively maintained one with good reviews will do.
### General Steps
1. Install and activate a code-snippet plugin from **Plugins** > **Add New**.
2. Open the plugin's **Add Snippet** screen and paste your PHP. Do not include the opening `
## functions.php or a Plugin: Where Code Belongs
People reach for `functions.php` because it is easy to find, but it is often the wrong home for code. A useful rule of thumb separates design from functionality:
- **Design belongs to the theme.** Code that only makes sense with this particular theme, such as registering a menu location or a template part it defines, is legitimately theme code and belongs in a child theme's `functions.php`.
- **Functionality belongs to a plugin (or a snippet plugin).** Anything you would still want if you changed themes, such as a tracking tag, a custom shortcode or a checkout tweak, should live in a plugin or a code snippet, not in the theme. Put it in `functions.php` and it vanishes the day you switch themes.
In short: if the code is about how the site *looks* with this theme, a child theme's `functions.php` is fine; if it is about what the site *does*, keep it in a snippet plugin or a dedicated plugin so it is independent of the theme.
## Use a Child Theme for Lasting Changes
A child theme is the correct way to change theme templates and styles so your work survives updates to the parent theme. It is a small separate theme that inherits everything from the parent and overrides only the files you place in it. When the parent theme updates, your child theme is untouched and your changes remain.
The steps differ slightly between classic and block themes. The full reference is the official Child Themes documentation linked above; the essentials and the parts people get wrong are below.
### Classic (or Hybrid) Theme Child
1. In `wp-content/themes`, create a new folder, for example `yourtheme-child` (an example name, use your own). Create it with the File Manager or over SFTP.
2. Inside it, create a `style.css` file that starts with a header comment. Two fields are essential: `/* Theme Name: Your Theme Child Template: yourtheme */` The `Template` value must be an exact, case-sensitive match for the parent theme's folder name inside `wp-content/themes`. This is the single most common child-theme mistake: if `Template` does not match the folder exactly, WordPress cannot find the parent and the child theme will not activate.
3. If the parent theme does not automatically load the child's stylesheet, create a `functions.php` in the child folder that enqueues styles correctly. Follow the enqueue example in the official documentation rather than copying older tutorials, which often use an outdated `@import` method.
4. In **Appearance** > **Themes**, activate **Your Theme Child**. Your site should look identical, because the child inherits everything, until you start overriding files.
Two things worth knowing that trip people up:
- **Do not copy the parent's whole `functions.php` into the child.** Unlike template files, a child's `functions.php` does *not* replace the parent's; both load, with the child loading first. Copying the parent's file wholesale causes "function already declared" fatal errors. Add only your own new functions.
- **To override a template**, copy just that one file from the parent into the same relative path in the child and edit the copy. For example, to change the footer, copy `footer.php` into the child folder and edit it there. WordPress uses the child's version instead of the parent's.
### Block Theme Child
Block themes are styled through `theme.json` and templates rather than PHP and `style.css`, so a block-theme child is built a little differently:
- The child still needs a folder and a `style.css` with the `Theme Name` and matching `Template` header, so WordPress recognises it as a child.
- Styling overrides go in a `theme.json` in the child folder, which merges with the parent's `theme.json` rather than replacing it.
- Template overrides go in an `.html` file placed in the child's `templates` folder, matching the template you want to change.
For many block-theme sites you will not need a child theme at all: the Site Editor (**Appearance** > **Editor**) saves template and style changes to the database, safely and reversibly, without editing any file. Reach for a child theme when you need overrides that the Site Editor cannot express, or that you want version-controlled as files.
## Lock Down the File Editor for Extra Safety
Because the built-in editor is both risky and a target for attackers (anyone who gains admin access can use it to inject code), many sites disable it entirely. WordPress has a built-in constant for this. Add the following line to your `wp-config.php` file, above the line that reads `/* That's all, stop editing! */`:
```
define( 'DISALLOW_FILE_EDIT', true );
```
This removes the Theme File Editor and Plugin File Editor from the admin menus. Your safe methods above still work: CSS tools, snippet plugins and child theme files edited over SFTP are all unaffected. If your plan already blocks plugin and theme installs with `DISALLOW_FILE_MODS`, that constant disables the file editors too, so you do not need both. Disabling the file editor is a standard hardening step; see the [WordPress Security Checklist](/wordpress/wordpress-security-checklist/) for the wider picture.
## Troubleshooting
- **Symptom: the site shows a blank page or a "critical error" after an edit.** This is a fatal PHP error, usually a typo. If you used a snippet plugin, WordPress often deactivates the faulty snippet automatically and emails the admin address a recovery link; use it to log in and fix or delete the snippet. If you edited a theme file, use the File Manager or SFTP to open the file you changed and revert it, or restore it from your backup.
- **Symptom: you cannot even reach the admin login after editing a theme file.** Using the File Manager or SFTP, rename the active theme's folder (for example add `-broken` to it). WordPress cannot find the theme, so it falls back to a default theme and the admin area loads again, letting you put things right.
- **Symptom: the child theme will not activate, or the site loses all styling after activating it.** The `Template` field in the child's `style.css` almost certainly does not match the parent folder name exactly. Correct it to the exact, case-sensitive folder name and re-activate.
- **Symptom: "function already declared" fatal error after adding a child theme.** The child's `functions.php` contains a function that also exists in the parent, commonly because the parent's file was copied in. Remove the duplicated functions and keep only your own additions.
- **Symptom: the Theme File Editor is missing from the Appearance menu.** This is normal on a block theme, where the code editor lives under **Tools** > **Theme File Editor**. If it is missing everywhere, the file editor has been disabled by `DISALLOW_FILE_EDIT` or `DISALLOW_FILE_MODS`, which is expected on a hardened site.
If you are unsure which method suits your change, or an edit has taken your site offline and you cannot get back in, open a support ticket with the Noiz support team. Include your domain, what you changed and how, and whether you are on a block or classic theme, and a technician will help you recover the site and set up a safe way to make the change stick.
# How to Set Up Google Analytics 4 on Your WordPress Site
Source: https://docs.noiz.ie/wordpress/how-to-set-up-google-analytics-4-on-your-wordpress-site/
This guide shows you how to set up Google Analytics 4 (GA4) on a WordPress site hosted with Noiz, so that you can see how many people visit, where they come from and which pages they read. It is written for site owners and editors who are comfortable in the WordPress dashboard but are not analytics specialists. Google Analytics 4 is often shortened to GA4, and the single tracking code you add to your site is called the **Google tag** (formerly `gtag.js`). Since 1 July 2024, GA4 is the only supported version of Google Analytics: the older Universal Analytics has been switched off, so any guide referring to "UA" or tracking IDs beginning `UA-` is out of date.
**Last reviewed:** 27 July 2026, against Google Analytics 4 (the current and only supported version of Google Analytics) and the Site Kit by Google plugin **1.183.0** (latest stable). This guide is written for Noiz hosting and is kept current against Google Analytics and WordPress. It complements, and does not replace, the official Google Analytics and Site Kit documentation linked below.
### Official Documentation Reference
- [Set up Analytics for a website (Google Analytics Help)](https://support.google.com/analytics/answer/9304153): Google's own procedure for creating a property, adding a web data stream and installing the Google tag.
- [Measurement ID (Google Analytics Help)](https://support.google.com/analytics/answer/12270356): what the `G-` ID is and where to find it.
- [Enhanced measurement events (Google Analytics Help)](https://support.google.com/analytics/answer/9216061): the interactions GA4 tracks automatically, such as scrolls, outbound clicks and file downloads.
- [Realtime report (Google Analytics Help)](https://support.google.com/analytics/answer/9271392): how to see visitors on your site as they happen, which you use to confirm tracking works.
- [Analytics Insights and custom insights (Google Analytics Help)](https://support.google.com/analytics/answer/9443595): how to have GA4 email you when your traffic changes unexpectedly.
- [Site Kit by Google (WordPress.org plugin page)](https://wordpress.org/plugins/google-site-kit/): the official Google plugin for WordPress, and its current version and requirements.
- [Site Kit by Google (official site)](https://sitekit.withgoogle.com/): Google's product page for Site Kit.
## Prerequisites
- A Google account. A free personal or Google Workspace account both work.
- Administrator access to your WordPress dashboard. If you are not sure how to sign in, see [How to login to WordPress (Admin Dashboard)](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- Your live site URL, for example `https://yourdomain.com` (replace with your own domain, this is an example placeholder).
- A few minutes to complete the Google-side setup, then up to 30 minutes for GA4 to start showing data.
## How the Pieces Fit Together
Adding analytics is not built into WordPress core, so there is no analytics field in a fresh WordPress install. The job has two halves, and it helps to keep them separate in your mind:
1. **The Google side:** you create a GA4 **property** and a **web data stream**. This gives you a **Measurement ID** that looks like `G-XXXXXXXXXX`.
2. **The WordPress side:** you place the Google tag (which carries that Measurement ID) on every page of your site. You can do this with a plugin or by editing your theme.
Once the tag is loading on your pages, GA4 begins collecting visits automatically. The rest of this guide walks through both halves.
## Step 1: Create a Google Analytics 4 Property
This is done entirely in Google Analytics, not in WordPress. The screens change from time to time, so treat the following as the shape of the process and rely on Google's [Set up Analytics for a website](https://support.google.com/analytics/answer/9304153) guide for the exact current wording.
1. Go to [analytics.google.com](https://analytics.google.com) and sign in with your Google account. If this is your first time, click **Start measuring**.
2. Create an **Account** (for example, your business name) and accept the data-sharing settings you are comfortable with.
3. Create a **Property**. Give it a clear name such as `yourdomain.com`, then set the reporting time zone to **South Africa** and the currency to **ZAR** so your reports match your day and your billing.
4. When prompted to choose a platform, select **Web** and add a **data stream**: enter your site URL (for example `https://yourdomain.com`) and a stream name such as `Main website`.
5. Leave **Enhanced measurement** switched on. It automatically records useful interactions such as scrolls, outbound link clicks, site searches and file downloads without any extra work. See [Enhanced measurement events](https://support.google.com/analytics/answer/9216061) for the full list.
6. Click **Create stream**.
If you plan to use the Site Kit plugin (Method A below), you can let it create the property for you during setup and skip most of this step. It is still worth understanding what it is creating on your behalf.
## Step 2: Find Your Measurement ID
The Measurement ID is the value that links your website to this GA4 property. You only need it if you are connecting your site manually or with a third-party plugin. The Site Kit plugin detects it for you.
1. In Google Analytics, click **Admin** (the gear icon, lower left).
2. Under the property column, click **Data streams**, then click your web stream.
3. In **Stream details**, copy the **Measurement ID** at the top right. It always starts with `G-`, for example `G-XXXXXXXXXX`.
An ID beginning `UA-` is a Universal Analytics ID and no longer works. If you only have one of those, create a fresh GA4 property as in Step 1.
## Step 3: Connect GA4 to WordPress
There are three common ways to get the Google tag onto your WordPress pages. Choose one, and one only. Installing GA4 through more than one method at the same time makes it count every visit two or three times, which quietly ruins your numbers.
### Method A: The Official Site Kit by Google Plugin (Recommended for Most People)
[Site Kit by Google](https://wordpress.org/plugins/google-site-kit/) is Google's own free WordPress plugin. It connects your site to GA4 (and, if you want, Search Console and PageSpeed Insights) and shows key figures right inside your WordPress dashboard. It is the least error-prone option because it handles the Measurement ID and the tag for you.
1. In your WordPress dashboard, go to **Plugins** > **Add New Plugin**, search for `Site Kit by Google`, then click **Install Now** and **Activate**.
2. Open the new **Site Kit** menu and click **Start Setup**.
3. Sign in with the same Google account that owns the GA4 property from Step 1, and grant the permissions it asks for.
4. When prompted, connect **Analytics** and select your existing GA4 property (or let Site Kit create one).
Each administrator who wants to see the dashboard figures signs in with their own Google account; this is normal and does not create duplicate tracking. The visitor tag is set once for the whole site.
### Method B: A Third-Party Analytics Plugin
Many analytics and SEO plugins can insert the Google tag for you, and some add their own reports inside WordPress. Examples include the plugins commonly listed under "Google Analytics" in the WordPress plugin directory; Noiz does not endorse any single one, so choose based on reviews, active-install count and how recently it was updated. Whichever you pick, the process is the same in shape:
1. Install and activate the plugin from **Plugins** > **Add New Plugin**.
2. Open the plugin's settings and either sign in with Google or paste the **Measurement ID** (`G-XXXXXXXXXX`) from Step 2 into its tracking-ID field.
3. Save. The plugin adds the tag to every page for you.
A lighter-weight route is a "header and footer scripts" plugin, which simply gives you a box to paste code into. That overlaps with Method C, below.
### Method C: Add the Google Tag to Your Theme Manually
If you would rather not add a plugin, you can paste the Google tag into your site's HTML yourself. This keeps things lean but is the easiest method to get wrong, so it suits confident users.
1. In Google Analytics, go to **Admin** > **Data streams** > your web stream, then click **View tag instructions** and choose **Install manually**.
2. Copy the whole snippet that begins with ``.
3. Paste it immediately after the opening `` tag so it loads on every page. How you do this depends on your theme:
- **Block themes** (the default in recent WordPress) have no editable `header.php` file, so use a header-scripts plugin or a small custom plugin to inject the code, rather than editing theme files.
- **Classic themes** have a `header.php` you can edit, but only ever edit it inside a **child theme**. If you edit the parent theme directly, the next theme update will overwrite your change and tracking will silently stop.
Some themes and page builders provide their own "custom code" or "header scripts" field in their settings; if yours does, that is the safest place to paste the tag manually.
## Step 4: Clear Your Cache
Your Noiz hosting, and any caching plugin or content delivery network (CDN) you use, may serve a saved copy of your pages to visitors. If that saved copy was generated before you added the tag, GA4 will see nothing. After completing Step 3, clear every cache in the chain: your caching or performance plugin, then any CDN, and finally your browser. Then load your site in a private or incognito window to fetch a fresh copy.
## Step 5: Confirm Tracking Is Working
Do not wait a day to find out whether it worked. GA4's [Realtime report](https://support.google.com/analytics/answer/9271392) shows activity within seconds.
1. Open your website in a separate browser tab or on your phone and click around a couple of pages.
2. In Google Analytics, go to **Reports** > **Realtime**.
3. You should see at least one active user, which is you, along with the pages you are viewing.
If you see yourself, tracking is live. Standard reports such as **Acquisition** and **Engagement** can take 24 to 48 hours to fill with meaningful figures, so do not be alarmed if they look empty at first.
## Where to View Your Traffic
Everyday reporting lives under **Reports** in the left-hand menu of Google Analytics. The three you will use most are:
- **Reports** > **Acquisition** > **Traffic acquisition**: where your visitors come from, grouped into channels such as Organic Search, Direct, Referral and Social. This answers "is my marketing working?".
- **Reports** > **Engagement** > **Pages and screens**: which pages and posts are read most, and how long people stay. This answers "what content is landing?".
- **Reports** > **Realtime**: who is on the site right now, useful when you publish a post or run a campaign.
The **Home** and **Reports snapshot** screens give a quick overview if you just want the headline numbers.
**A note on history:** by default GA4 keeps detailed event data for two months. If you want to explore longer trends in the **Explore** section, raise this to the maximum in **Admin** > **Data retention**. Your standard reports above are aggregated and are not limited by this setting.
## Get an Email When Your Traffic Changes
GA4 can watch your data and email you when something moves sharply, for example a drop in visitors that might mean your site is down, or a spike worth acting on. This is done with **custom insights** on the Google side, not in WordPress.
In brief: open the **Insights** card on your Reports or Home screen, click **View all insights**, then **Create**. Choose how often GA4 checks (hourly, daily, weekly or monthly), pick a metric, condition and threshold (such as active users decreasing by more than 20 percent), name it, and add the email addresses that should be alerted. Full details are in Google's [Analytics Insights](https://support.google.com/analytics/answer/9443595) guide.
## A Word on Privacy and Consent
Google Analytics sets cookies and collects data about your visitors, which brings it within the scope of South Africa's POPIA and, if you have European visitors, the GDPR. A responsible setup pairs GA4 with a clear privacy or cookie notice on your site, and many site owners add a consent banner that only loads the Google tag once a visitor agrees. This guide covers the tracking mechanics; treat consent as a separate task to complete before you rely on the data commercially, and take your own legal advice where needed.
## Troubleshooting
**Symptom: the Realtime report shows no active users even though you are on the site.** The tag is not loading. Check that you completed Step 4 and cleared all caches, then view your homepage source (right-click, **View Page Source**) and search for `gtag` or your `G-` ID. If it is missing, the plugin or manual snippet did not apply; re-check the method you chose in Step 3.
**Symptom: your visit numbers look far too high, or every visit is counted twice.** GA4 is almost certainly installed twice, for example through both a plugin and a manual snippet, or through two plugins. Pick a single method from Step 3 and remove the others.
**Symptom: your own visits are inflating the figures.** While testing this is expected. For a live site, exclude your own traffic by defining internal traffic in **Admin** > **Data streams** > **Configure tag settings**, then applying a data filter. Your day-to-day browsing of your own site will otherwise skew small sites noticeably.
**Symptom: Site Kit says it cannot verify ownership or connect Analytics.** Make sure you signed in with the exact Google account that owns the GA4 property, and that the property and data stream from Step 1 actually exist. Reconnect the Analytics service from **Site Kit** > **Settings** if needed.
**Symptom: standard reports are still empty after a day.** Confirm tracking in Realtime first. If Realtime works but Acquisition and Engagement do not fill, give it a full 48 hours, and check you are looking at the correct property and an appropriate date range at the top right.
If you would rather not do this yourself, the Noiz support team can help. On a Noiz managed WordPress plan, open a support ticket and the team can add and verify your Google tag for you; send through your Measurement ID (the `G-` value) and let the team know which pages you want tracked. If you are self-managed and get stuck at any step, open a ticket describing the method you used and what the Realtime report shows, and the team will help you get your traffic flowing into GA4.
# How to Set Up Two-Factor Authentication (2FA) in WordPress with All-In-One Security (AIOS)
Source: https://docs.noiz.ie/wordpress/how-to-set-up-two-factor-authentication-2fa-in-wordpress-with-all-in-one-securit/
Two-factor authentication (2FA) adds a second layer of protection to your WordPress login. Even if your password is guessed, leaked, or stolen, an attacker cannot log in without a time-based one-time code generated on your own device. This article walks through enabling and configuring 2FA using the All-In-One Security (AIOS) plugin, from login to your first protected sign-in.
## What You Need Before Starting
- A WordPress site with the **All-In-One Security (AIOS)** plugin installed and activated. The free version from the WordPress plugin directory includes 2FA for standard WordPress login forms.
- An administrator account on the site.
- A smartphone or tablet on which to install an authenticator app (see next section).
AIOS 2FA uses the open TOTP standard (time-based one-time passwords). The codes are generated locally on your device from a shared secret, so no network connection, SMS, or phone number is required, and no third party is involved in your logins.
## Step 1: Install an Authenticator App
Any TOTP-compatible authenticator app will work. Noiz recommends fully free and open-source (FOSS) options, as their code is publicly auditable and they do not tie your 2FA secrets to a vendor account:
- **FreeOTP+** (Android, available on F-Droid and Google Play) - the Noiz preferred option, with encrypted export/backup support.
- **Aegis Authenticator** (Android, F-Droid and Google Play) - FOSS, with encrypted vault and backup support.
- **FreeOTP** (iOS, App Store) - the original Red Hat FOSS authenticator.
Proprietary options such as Google Authenticator, Microsoft Authenticator, and Authy are also fully compatible if you already use one of them.
Install your chosen app before proceeding. You will need it in Step 3.
## Step 2: Enable Two-Factor Authentication in AIOS
1. Log in to your WordPress admin dashboard at `https://yourdomain.com/wp-admin` (or your custom login URL if AIOS login page rename is active).
2. In the left-hand admin menu, click **WP Security**.
3. Click **Two Factor Auth** in the WP Security submenu.
4. Open the **Admin settings** section. Here you control which user roles are allowed to activate 2FA on their accounts.
5. Tick the roles that should have 2FA available. At minimum, enable it for **Administrator**. Enabling it for Editor and other privileged roles is strongly recommended.
6. Click **Save Changes**.
This makes 2FA available for those roles. Each user then activates it on their own account, as follows.
## Step 3: Activate 2FA on Your Account
1. Still under **WP Security > Two Factor Auth**, locate the activation section for your own account and set two-factor authentication to **Enabled / Active**.
2. A QR code and a private key (a string of characters) will be displayed. These represent the shared secret between the site and your authenticator app.
3. Open your authenticator app and add a new account:
- **Scan the QR code** using the app's built-in scanner (fastest method), or
- **Enter the private key manually** if your device cannot scan the screen.
4. The app will immediately begin generating six-digit codes that refresh every 30 seconds.
5. **Important:** before logging out, confirm that the current code shown in your app matches the current code shown on the AIOS Two Factor Auth page. If they match, the pairing is correct. If they do not match, check that the date and time on your phone are set to automatic, as TOTP depends on accurate clocks.
6. Save the settings.
## Step 4: Test the Login
1. Log out of WordPress.
2. Log in again with your username and password as normal.
3. You will now be prompted for a **one-time password**. Open your authenticator app and enter the current six-digit code for the site.
4. You are logged in. From now on, every login requires both your password and a fresh code from your device.
## If You Get Locked Out
If you lose access to your authenticator device and cannot generate codes, 2FA can be temporarily disabled by anyone with file-level access to the site. Add the following line to `wp-config.php`, just above the line that says `/* That's all, stop editing! */`:
```
define('TWO_FACTOR_DISABLE', true);
```
Log in, reconfigure 2FA with your new device, then remove the line again so protection is restored. File access is available through your hosting control panel's file manager or over SFTP. If you are on a Noiz managed WordPress plan, contact the Noiz support team and this can be handled for you.
The premium version of AIOS additionally supports one-time emergency backup codes, which can be generated in advance and stored somewhere safe for exactly this situation.
## Free vs Premium 2FA Features
The free version covers standard WordPress login forms and is sufficient for most sites. AIOS Premium adds, among other things:
- 2FA on WooCommerce, Elementor Pro, and other custom login forms.
- Making 2FA **compulsory** for selected user roles, rather than optional.
- Emergency backup codes for account recovery.
- Trusted devices, so a code is only required every set number of days per device.
- WordPress multisite support.
## Official Documentation
For further detail on AIOS two-factor authentication, refer to the official resources maintained by the plugin developer, TeamUpdraft:
- [AIOS Two-Factor Authentication overview](https://teamupdraft.com/all-in-one-security/wordpress-two-factor-authentication/)
- [AIOS 2FA shortcodes documentation](https://teamupdraft.com/documentation/all-in-one-security/faqs/how-to-use-aios-tfa-shortcodes/) (for offering 2FA management to front-end users on membership or WooCommerce sites)
## Need Help?
If 2FA is not behaving as expected, codes are being rejected, or you would like 2FA rolled out across multiple users or sites, contact the Noiz support team. Please note that if you are not on a managed WordPress plan, this work may be billable.
# How to Speed Up Your WordPress Site
Source: https://docs.noiz.ie/wordpress/how-to-speed-up-your-wordpress-site/
This guide shows you how to make a WordPress site load faster, in plain language and in the order that actually gets results. A slow site costs you real visitors: people leave pages that take too long to appear, and since Google measures page-load experience through its Core Web Vitals, speed also affects where you rank in search. The work described here is often called **page speed**, **site speed**, **site performance** or **web performance optimisation**; they all mean the same thing. You will start by measuring your site honestly with the same tools professionals use, then work through the changes that give the biggest return for the least effort: running a current version of PHP, adding caching, optimising images, trimming plugins, choosing a lean theme, putting a CDN in front of your assets, cleaning up the database, and letting the browser lazy-load what it does not yet need. Most of it needs no code, and it is written for anyone running WordPress on Noiz hosting, from a solo blogger to a small team. Specific tools are named only as examples of a category, never as recommendations.
One thing to settle first: the **server and network layer**, the part that decides how fast the very first byte reaches the browser (opcode caching, HTTP/2, compression, fast storage, and the network path), is tuned for you at the Noiz hosting level. This guide concentrates on the **application layer**, the part you control from inside WordPress and your hosting control panel, because that is where most of the avoidable slowness on a WordPress site actually lives.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Optimization (Advanced Administration Handbook)](https://developer.wordpress.org/advanced-administration/performance/optimization/), the official overview of caching, database and image optimisation.
- [WordPress Requirements](https://wordpress.org/about/requirements/), the recommended and minimum PHP and database versions.
- [Image performance enhancements in WordPress 6.3](https://make.wordpress.org/core/2023/07/13/image-performance-enhancements-in-wordpress-6-3/), how core decides lazy-loading and `fetchpriority`.
- [Core Web Vitals (web.dev)](https://web.dev/articles/vitals), the definitions and target thresholds Google measures.
## Prerequisites
- Administrator access to your WordPress dashboard. If you are not sure how to reach it, see [How to log in to the WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A recent, restorable backup taken *before* you change anything. Several steps here (PHP version, caching, database cleanup) can expose an incompatibility, and a backup is what turns a scare into a five-minute rollback.
- Ideally a **staging site** (a private copy of your live site) to test changes on first. If you do not have one, test during a quiet period and be ready to undo.
- Access to your files by SFTP or the control panel File Manager, and to your database through phpMyAdmin. On a managed plan you can ask the Noiz support team to make server-side changes for you.
## Step 1: Measure before you touch anything
Optimising without measuring is guesswork. Take a baseline now so that every later change can be judged against it, and so you spend effort where it counts rather than on whatever the internet told you to worry about this week. The single most important idea here is the difference between two kinds of measurement.
- **Lab data (synthetic)** is a single test run in a controlled environment. It is repeatable and good for diagnosis, but it is not what your visitors experienced. Chrome's built-in Lighthouse, and tools that generate a waterfall chart of every request, produce lab data.
- **Field data (real users)** is collected from actual people who visited your site in real conditions. This is what Google uses to rank, and it is the number that ultimately matters.
A perfect lab score with poor field data is common and misleading, so always look at both. The tools worth knowing:
- **PageSpeed Insights** (`pagespeed.web.dev`) shows lab and field data side by side and is the closest thing to Google's own verdict on your pages. Test your home page and a typical inner page, on mobile and desktop.
- **Lighthouse**, built into Chrome's developer tools, runs a lab audit in your own browser and lists specific opportunities.
- A **waterfall tool** (the category includes several free web-based testers) shows every file the page loads, in order, so you can see exactly what is slow or oversized.
- **A query-profiling plugin** such as Query Monitor, a free developer tool, is the kind to reach for when a site feels sluggish for logged-in users. It breaks page-generation time down by plugin and shows slow database queries, so it tells you *which* component is the culprit instead of leaving you to guess. Deactivate it again once you have your answer.
The three **Core Web Vitals** are the metrics to write down. As of 2024 they are:
- **Largest Contentful Paint (LCP)**, how long the main content takes to appear. Aim for **2.5 seconds or less**.
- **Interaction to Next Paint (INP)**, how quickly the page responds when someone taps or clicks. Aim for **200 milliseconds or less**. INP replaced the older First Input Delay metric in 2024, so any guide still talking about "FID" is out of date.
- **Cumulative Layout Shift (CLS)**, how much the layout jumps around while loading. Aim for **0.1 or less**.
These targets are measured at the 75th percentile of your visitors, meaning three out of four page loads should meet them. Note your figures now, then re-run the same tests after each change so you can prove what helped.
## Step 2: Run a current version of PHP
This is the highest-value change on the list and the one most often overlooked. WordPress is written in a language called **PHP**, and every page your site builds is assembled by PHP on the server. Each major PHP release has been substantially faster than the one before, so simply moving from an old version to a current one can cut page-generation time noticeably with no change to your site's content or design. Newer versions also receive security fixes that end-of-life versions do not.
WordPress recommends **PHP 8.3 or greater**. It will still run on 7.4 and up, but those older versions have reached end of life and no longer get security updates, so treat them as something to move off, not a comfortable place to sit.
### Check the version you are on
In the dashboard go to **Tools > Site Health > Info**, open the **Server** section, and read the **PHP version**. Site Health will also warn you outright on its **Status** tab if the version is outdated.
### Change it on Noiz hosting
You set the PHP version per site in your hosting control panel, which one depending on your plan:
- **Plesk** (on neo.noiz.co.za): open your domain, then **PHP Settings**, and pick the version from the **PHP version** menu.
- **DirectAdmin**: use the PHP version selector for the domain.
- **ISPConfig**: edit the website and choose the version from its **PHP Version** field.
If you are on a Noiz managed plan, you do not need to touch the panel at all: ask the support team to move your site to the current PHP version and they will handle it.
**Before you switch:** update WordPress core, your theme and all plugins first, then test on staging if you can. The only thing that breaks under a newer PHP version is old, unmaintained code, so an up-to-date site almost always upgrades cleanly. If a page does error after the change, revert to the previous version in the same panel screen, identify the outdated plugin or theme responsible, and deal with that before trying again.
## Step 3: Add caching
Building a WordPress page from scratch means running PHP and querying the database on every single visit. **Caching** means saving the result of that work and handing out the saved copy instead of rebuilding it each time. It is usually the biggest front-end speed gain you can add, and there are several distinct kinds that solve different problems.
- **Page caching** saves the finished HTML of a page as a static file and serves that to visitors, skipping PHP and the database almost entirely. This is the big one for sites whose content does not change on every request, which is most sites. A page-caching plugin installs this in minutes.
- **Object caching** saves the results of individual database queries in fast memory so they are not repeated. A **persistent object cache** keeps those results between requests using an in-memory store such as Redis or Memcached, and pays off most on busy, dynamic or WooCommerce-style sites where full-page caching cannot be used. WordPress Site Health flags under **Performance** when a persistent object cache would help. This is a server capability, so on a managed plan ask Noiz support whether it can be enabled for your site.
- **Browser caching** tells visitors' browsers to keep a local copy of your images, CSS and JavaScript so repeat views load almost instantly. This is driven by HTTP headers and is generally configured for you at the hosting level.
- **Opcode caching** (OPcache) keeps PHP itself compiled and ready in memory. It is a server feature, enabled by Noiz, and needs nothing from you.

**Two rules that save a lot of pain.** First, never run two page-caching plugins at once; they fight each other and produce bizarre, hard-to-diagnose behaviour. Pick one. Second, whenever you make a change and do not see it on the front end, **clear the cache** before assuming the change failed, because you are very likely looking at a stored copy. Every caching plugin has a one-click purge for exactly this.
## Step 4: Optimise your images
On a typical page, images are the single largest thing the browser has to download, which makes them the most reliable place to claw back load time. Four habits do most of the work.
- **Resize before you upload.** A photo straight off a phone or camera can be several thousand pixels wide and several megabytes in size. If it is only ever displayed at 1200 pixels wide, uploading the full-size original wastes bandwidth on every view. Scale it down to a sensible maximum first.
- **Compress.** Image compression removes detail the eye cannot see and can shrink a file by half or more with no visible loss. Image-optimisation plugins do this automatically as you upload, or you can compress before uploading.
- **Use modern formats.** The **WebP** and **AVIF** formats produce much smaller files than the older JPEG and PNG at the same quality. WordPress core has accepted WebP uploads since 2021 and added AVIF support in version 6.5, so you can use them directly; many optimisation plugins will also generate modern-format copies of your existing library.
- **Serve the right size.** WordPress already creates several sizes of each upload and, through `srcset`, lets the browser pick the one that fits the visitor's screen. Deleting the intermediate sizes to "save space" undoes this, so leave them in place.
A media library full of unused, oversized originals also bloats your backups and your disk usage. Clearing it out is a performance and housekeeping job in its own right, covered in the companion guide [How to clean up your WordPress media library](/wordpress/how-to-clean-up-your-wordpress-media-library/).
### Lazy loading
Lazy loading means the browser only downloads an image when the visitor scrolls near it, rather than fetching everything up front. WordPress does this for you: since version 5.5 it automatically adds `loading="lazy"` to images below the fold. Version 6.3 refined it further, so that instead of lazy-loading the large image at the top of the page, core flags that one with `fetchpriority="high"` to fetch it first, which typically improves LCP. The two attributes are opposites and core never puts both on the same image, so the important thing is simply not to fight this with a plugin setting that force-lazy-loads *every* image, including the first one, as that pushes your LCP the wrong way. The same lazy-loading idea applies to embedded videos and iframes, which are heavy: load them on interaction, or use a lightweight preview thumbnail that only pulls in the real embed when clicked.
## Step 5: Use fewer, better plugins
It is not the number of plugins on its own that slows a site, it is what each one *does* on every request. A plugin that adds database queries, makes calls to an external service, or loads its own CSS and JavaScript on every page is a tax you pay on every view, whether that feature is used on the page or not. The goal is to keep only what earns its place.
- **Audit what is active.** Deactivating a plugin is not the same as removing it; deactivated plugins still sit in your install. Delete the ones you are genuinely not using.
- **Find the expensive ones.** This is where the query-profiling plugin from Step 1 earns its keep: it attributes page-build time to specific plugins, so you can see which one is actually costing you rather than guessing.
- **Prefer built-in features.** WordPress core now does natively many things people still reach for a plugin to do. Every plugin you can replace with a built-in feature or a small code snippet is one fewer thing loading on every page.
- **Be wary of do-everything plugins.** A single large "all-in-one" plugin can load more code than the three focused plugins it replaced. Judge by measured impact, not by plugin count.
Trimming plugins has a second benefit beyond speed: every plugin is also code that could carry a vulnerability, so a smaller, well-maintained set is a smaller attack surface as well as a faster site.
## Step 6: Choose a lean theme
Your theme decides how much code every visitor downloads before they see anything, so it has an outsized effect on front-end speed. The heavy end of the market is the "multipurpose" theme that bundles a page builder, sliders, icon fonts and several JavaScript libraries, and loads most of them on every page even when a given page uses none of it. The result looks impressive in a demo and drags on real Core Web Vitals.
The lightest option is a modern **block theme** (the kind edited through the Site Editor), including the default themes that ship with WordPress. Block themes tend to render leaner markup and lean on core features rather than bundling their own frameworks. If you are attached to a heavier theme, at least avoid stacking a bloated theme on top of a bloated page builder, since that doubles the weight. When you are choosing or changing a theme, test the candidate on staging and compare its Core Web Vitals against your current one before committing. A well-built lightweight theme with good content will out-perform a heavy, feature-stuffed one every time.
## Step 7: Put a CDN in front of your site
A **content delivery network** (CDN) is a network of servers spread around the world that keep copies of your static files (images, CSS, JavaScript, fonts) close to your visitors. Someone loading your site from another continent is then served those files from a nearby location instead of making the full round trip to the origin server, which cuts latency. Many CDNs go further and cache your full HTML pages at the edge, compress and convert images on the fly, and absorb sudden traffic spikes.
A CDN sits in front of your hosting rather than replacing it, and most providers offer a free tier that is more than enough for a typical site. It helps most when your audience is geographically spread out or your site is image-heavy. This guide stays neutral on which one to use; if you want a recommendation suited to your traffic and audience, the Noiz support team can advise.
## Step 8: Clean up the database
Over time a WordPress database accumulates data that no longer serves any purpose but still has to be read, backed up and searched through. Clearing it out keeps queries quick and backups small.
- **Post revisions.** WordPress saves a copy every time you save a draft, so a single much-edited page can hide dozens of old revisions. You can cap them by adding a line such as `define( 'WP_POST_REVISIONS', 5 );` to `wp-config.php` (keeping the five most recent), and clear the historic build-up with a maintenance tool.
- **Auto-drafts, trashed posts and trashed comments.** These linger until emptied.
- **Spam comments.** Delete them rather than leaving them queued.
- **Expired transients.** These are temporary cached values; stale ones pile up and can safely be cleared.
- **Autoloaded options.** This is the quiet one worth knowing about. A set of rows in the `wp_options` table is loaded on *every* page request, and plugins that were removed carelessly often leave large entries behind that are still being autoloaded for no reason. WordPress advises keeping the total autoloaded data under roughly **800KB**. A cleanup plugin, or Site Health, can show you when this has grown out of hand.
### Doing it on Noiz
The safe route for most people is a reputable database-maintenance plugin, which handles the above from inside the dashboard. If you prefer to work directly, you can reach your database through **phpMyAdmin** in your control panel: there you can run an **Optimize table** on your WordPress tables to reclaim space and tidy their storage. Whichever route you take, **export a backup of the database first**, from phpMyAdmin or through your panel's backup tools, because database edits are not something you want to undo by hand. Managed-plan clients can simply ask the Noiz support team to run the cleanup and optimisation.
## Step 9: Measure again and keep it that way
Re-run the exact tests from Step 1 on the same pages, and compare against the baseline you saved. Field data (real-user Core Web Vitals) takes time to catch up because it is gathered from actual visits over a rolling window, so give it a few weeks before judging the real-world outcome, while the lab tools will show the improvement immediately. Performance is not a one-off task: new plugins, a redesign, a heavier theme or a growing database can all erode it, so re-check after any significant change and revisit every few months.
## Troubleshooting
- **Symptom: the site broke or a page shows an error right after changing the PHP version.** An outdated plugin or theme does not support the newer PHP. Revert to the previous version in the same panel screen, then update or replace the component responsible before trying again.
- **Symptom: your change does not appear on the front end.** You are almost certainly seeing a cached copy. Purge the page cache (and your CDN cache, if you use one), then reload. Test in a private browser window to rule out your own browser cache.
- **Symptom: layout looks broken or scripts stop working after adding a caching or optimisation plugin.** Features that combine or defer CSS and JavaScript can occasionally clash with a theme or plugin. Turn those specific options off one at a time to find the culprit, and exclude that asset rather than disabling caching entirely.
- **Symptom: two caching plugins are installed.** Deactivate and delete one. Running two produces unpredictable results that are very hard to diagnose.
- **Symptom: a great lab score but the site still feels slow to visitors, or fails Core Web Vitals in Search Console.** You are comparing lab and field data. Trust the field data, and look especially at INP (real interactivity) and LCP on mobile, which lab tests on fast connections tend to flatter.
- **Symptom: Site Health warns that no persistent object cache is in use.** That store (Redis or Memcached) is a server feature. On a managed plan, ask Noiz support whether it can be enabled for your site; on a busy dynamic site it is worth having.
- **Symptom: images are still huge after installing an optimisation plugin.** Most plugins only optimise new uploads automatically. Run its bulk or "regenerate" action to process the images already in your library.
## Getting Noiz to help
Several of the highest-impact steps here (moving to a current PHP version, enabling server-side and object caching, and running a safe database cleanup) are exactly the kind of thing the Noiz team does day to day. If you are on a Noiz managed hosting plan, you do not need to perform them yourself: contact the support team and they will handle the server-side work and advise on the rest. If you self-manage your hosting, support can still help on a billable basis, and can point you to the right settings for your specific control panel.
# How to Stop Comment and Form Spam in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-stop-comment-and-form-spam-in-wordpress/
This guide shows you how to cut comment and form spam on your WordPress site down to a trickle, using a layered approach that starts with the free settings already built into WordPress and adds stronger defences only where you need them. It covers the settings on the Discussion screen, honeypot fields, CAPTCHA and invisible challenges, rate limiting, and hosted spam-filtering services, and it explains where each one helps and where each one falls short. Comment spam, contact-form spam, and fake user registrations are all the same problem wearing different clothes: unwanted, usually automated submissions aimed at your public forms. The advice here treats them together. It is written for Noiz clients who run their own WordPress site, and it deliberately names categories of tool and gives specific products only as examples, never as endorsements, because the right mix depends on your site.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Understanding comment spam (WordPress Documentation)](https://wordpress.org/documentation/article/understand-comment-spam/): WordPress's own overview of what comment spam is and the built-in settings for fighting it.
- [Settings Discussion screen (WordPress Documentation)](https://wordpress.org/documentation/article/settings-discussion-screen/): the full reference for every option under **Settings > Discussion**, including moderation, the link limit, and the disallowed keys box.
- [Comment moderation (WordPress Documentation)](https://wordpress.org/documentation/article/comment-moderation/): how the moderation queue works and the exact difference between the moderation list and the disallowed comment keys list.
- [Anti-spam plugins (WordPress Plugin Directory)](https://wordpress.org/plugins/tags/anti-spam): the directory's anti-spam tag, where you can compare plugins by last-updated date, compatibility, and support activity.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an **Administrator**. Changing discussion settings and installing plugins both need administrator rights.
- A recent, restorable backup of your site. None of the built-in settings here are risky, but you will be installing and configuring plugins, and a backup is your safety net.
- For CAPTCHA and some spam-filtering services, a free account with the provider (for example a Cloudflare account for Turnstile, or an Akismet key). You can set these up as you go.
## How Spam Reaches Your Site, and Why One Defence Is Never Enough
Almost every form you expose to the public is a target: the comment box under your posts, your contact form, the registration form if you allow sign-ups, and even the WordPress login page. The great majority of what hits them is not a person picking on you. It is bots working through millions of sites in bulk, filling in every field they can find, usually to plant links, harvest an inbox, or test stolen passwords. A smaller share is posted by hand, by people paid to place spam, and those submissions look far more like the real thing.
That split is the whole reason this guide is built in layers. No single measure stops everything. A honeypot quietly defeats simple bots but does nothing against a human spammer. A CAPTCHA raises the bar for automated tools but adds friction for real visitors and can be beaten by paid solving services. Content filtering catches the manual spam a honeypot misses but sends your visitors' words to a third party. Each layer covers a different gap, and the sensible goal is not a single perfect wall but several cheap, overlapping filters, so that anything slipping past one is usually caught by the next. Start with the free built-in settings, which cost nothing and already remove a surprising amount, then add the stronger layers only if spam is still getting through.
## Layer One: Tighten WordPress's Built-in Comment Settings
Before you install a single plugin, work through **Settings > Discussion**. Everything in this section is part of WordPress core, costs nothing, and on a low-traffic blog is often enough on its own. These settings decide what happens to a comment the moment it is submitted.

### Decide What Happens Before a Comment Appears
In the **Before a comment appears** section there are two checkboxes, and they set the tone for everything else.
- **An administrator must always approve the comment.** Tick this and nothing goes live until you approve it by hand. This is the single most effective anti-spam setting WordPress offers, because spam is never published, only queued. The trade-off is real work: every genuine comment also waits for you, and a busy comment section becomes a chore. It suits low-volume sites and sites where a delay before comments appear does not matter.
- **Comment author must have a previously approved comment.** A gentler middle ground. The first comment from any given email address is held for you to approve; once you have approved someone, their later comments appear straight away. This lets a real community flow while still catching the first submission from every new address, which is where most spam comes from.
If you would rather not check both, the second option alone is the better default for most sites: it filters newcomers without turning you into a full-time moderator.
### Require a Name and Email, and Consider Requiring Registration
Under **Other comment settings**, ticking **Comment author must fill out name and email** forces a little extra work on the submitter. It is worth knowing exactly what this does and does not do: WordPress does not verify the address in any way, so a bot can invent one. What it does is reject the crudest bots that submit with empty fields, at almost no cost to genuine commenters, who expect to give a name and email anyway.
A stronger option in the same box is **Users must be registered and logged in to comment**. This shuts out anonymous spam entirely, but it also shuts out most of your real readers, who will not create an account just to leave one comment. Reserve it for membership sites and internal sites where visitors already have logins. On an open blog it usually costs you more genuine engagement than it saves you spam.
### Hold Comments That Carry Too Many Links
Spam exists to place links, so the number of links in a comment is one of the oldest and most reliable signals. In the **Comment Moderation** section, the field **Hold a comment in the queue if it contains [X] or more links** holds anything with that many links or more. WordPress ships with this set to `2`. Because a normal comment rarely needs more than one link, lowering the threshold to `1` catches noticeably more junk, at the price of occasionally holding a legitimate comment that happened to include a couple of references. Held comments are not deleted, only queued, so this setting is low-risk: the worst case is a genuine comment waiting a little longer for you to approve it.
### Understand the Two Word Lists (and the Gotcha That Bites People)
WordPress gives you two separate text boxes for filtering by content, and confusing them is a genuine hazard. Both match against the comment text, author name, URL, email, IP address, and the browser's user-agent string, one entry per line.
- The **Comment Moderation** box (the larger text area in that section) *holds* matching comments for your review. Nothing is lost. This is the safe box, and the right place for words, phrases, spammy domains, or IP addresses you want a second look at rather than an automatic verdict.
- The **Disallowed Comment Keys** box (named Comment Blacklist before WordPress 5.4) *deletes* matching comments immediately and silently. There is no notification and no trash: the comment simply never exists as far as you are concerned.
That silent deletion is exactly the gotcha to respect. A genuine comment that happens to contain a word on your disallowed list vanishes without you or the author ever knowing. Use the disallowed box only for terms you would trash every single time without a second thought, such as a specific spam domain or a particular fake brand name that only ever appears in spam. Keep everyday words such as `free`, `deal`, or `buy` out of it entirely, and put anything you are less than certain about in the moderation box instead.
There is a second, subtler trap in both boxes: matching happens *inside* words, not just on whole words. WordPress's own documentation gives the example that `press` will match `WordPress`. So a short entry like `ass` would also flag `class`, `assessment`, and `passport`, quietly holding or deleting perfectly innocent comments. Prefer longer, distinctive strings, and after adding new moderation words use the **Check past comments against moderation list** link beneath the box to see what your rule would have caught, before it starts catching real comments.
### Close Comments on Older Posts
A large share of automated comment spam lands on old posts that no genuine reader is still discussing. In **Other comment settings**, **Automatically close comments on articles older than [X] days** switches the comment form off on any post past that age. Setting it to something like `30` or `60` days removes a huge target with almost no downside, since real conversation on a post nearly always happens in its first few weeks. Previously approved comments stay visible; only new ones are prevented.
### Turn Off Pingbacks and Trackbacks
This is the spam source people forget, because it does not look like a comment. Pingbacks and trackbacks are automatic notifications between blogs, and they are almost universally abused to inject spam links that then appear in your comment area. Unless you deliberately rely on them, untick **Allow link notifications from other blogs (pingbacks and trackbacks)** under **Default article settings**. Note the same catch WordPress documents for comments: this applies only to posts published from now on. To silence pingbacks on existing posts you either edit each one or make a bulk change, so it is best set early in a site's life.
### Disable Comments Where You Do Not Need Them
The most complete defence against comment spam is to have no comment form to attack. Many business sites, brochure sites, and landing pages have no reason to accept comments at all. You can turn comments off for new content by unticking **Allow people to post comments on new articles**, and switch them off on individual posts and pages through the **Discussion** panel in the editor, or in bulk from the Posts screen. If your site simply does not host discussion, closing comments site-wide removes an entire category of spam in one move.
## Layer Two: Add a Honeypot
Once the built-in settings are in place, a honeypot is usually the best next step, because it costs your real visitors nothing at all. A honeypot is a decoy form field that is hidden from people but visible to bots. A human never sees it, because it is concealed with CSS or positioned off-screen, so they never fill it in. Many automated bots read the raw HTML and dutifully complete every field they find, including the trap. If that hidden field arrives with anything in it, the submission is almost certainly a bot and is silently rejected. The bot moves on believing it succeeded, and you never see the spam.
The appeal of the honeypot is that it is invisible and frictionless: unlike a CAPTCHA, it asks nothing of your genuine visitors and does not slow them down. Many contact-form tools include a honeypot option you can simply switch on, and there are dedicated honeypot plugins that add the technique across comments and forms site-wide. Some also add a timing check, rejecting any form completed impossibly fast, since a human cannot read and fill a form in under a second but a bot submits instantly.
Two limitations keep the honeypot as a layer rather than a whole solution. First, more sophisticated bots have learned to detect and skip honeypot fields, so it no longer stops everything it once did. Second, a badly built honeypot can cause false positives: a browser password manager or autofill can populate a hidden field and flag a real visitor as spam. A well-made honeypot avoids this by giving the field an innocuous name and marking it correctly for assistive technology (for example with `aria-hidden` and a `tabindex` of `-1`) so screen readers and autofill leave it alone. If you build your own, get those details right; if you use a reputable plugin, they are handled for you.
## Layer Three: Add a CAPTCHA or Invisible Challenge
When bots are still getting through, a challenge that tries to tell humans and machines apart is the next layer, most often applied to comment, contact, registration, and login forms. The technology has moved on a long way from the twisted-letters image everyone remembers, and the choices in 2026 sit on a spectrum from fully invisible to actively interactive. WordPress does not include any of these in core, so all of them are added with a plugin, and each is a hosted service that needs a free account with its provider. The main options, given as examples rather than recommendations, are:
- **Invisible or low-friction challenges** run in the background and score how likely a visitor is to be a bot, only showing a puzzle when something looks suspicious. Cloudflare Turnstile is a widely used example: it is free with no monthly cap, works without tracking cookies, and for most low-risk and medium-risk forms it is the least intrusive option, which is why it is a common default. Google reCAPTCHA offers a similar invisible mode and is the most established name, though its free tier is capped and it relies on Google's cookies, which has privacy implications discussed below. hCaptcha is another established alternative that positions itself on privacy.
- **Interactive challenges** ask the visitor to tick a box, or occasionally to complete a small puzzle, when the risk score is high. They catch more determined bots on high-value forms, at the cost of visible friction for genuine users.
Three practical points matter more than which brand you pick. First, friction versus catch rate is a genuine trade-off: the harder a challenge is for bots, the more it annoys real people, and every extra step loses you some genuine submissions. Match the strength to the target, using a light invisible check on a comment box and reserving anything more aggressive for a login or checkout. Second, privacy and consent: any CAPTCHA sends some visitor data to a third party, and the tracking-based services in particular may require a cookie-consent notice under data-protection rules such as the POPIA and GDPR, whereas the cookieless options are generally easier to deploy without a consent banner. Third, accessibility: image and audio puzzles can be a real barrier for visitors with disabilities, which is another reason the invisible, score-based approach has become the sensible default for most sites.
## Layer Four: Rate Limiting and Timing Checks
Rate limiting attacks the volume of spam rather than its content. The idea is simple: a real person submits a form now and then, whereas a bot may hammer it dozens of times a minute. By capping how many submissions are accepted from one source in a given window, and by rejecting anything submitted suspiciously quickly, you blunt automated abuse without asking your visitors to do anything.
Rate limiting shows up in a few places, working together:
- **Form and login throttling** at the application level. Many form plugins and most security plugins can limit repeated submissions from the same address, and can lock out or slow down repeated failed logins, which is the same problem aimed at your login page rather than a comment box.
- **Timing checks** that reject a form completed faster than any human could manage, as mentioned under honeypots. This is a form of rate limiting on a single submission and catches instant-fire bots cheaply.
- **Server-level protection.** Noiz hosting includes abuse protection at the network and server layer that absorbs a good deal of automated traffic before it ever reaches WordPress, so much of the crudest, highest-volume flooding is filtered out for you. This does not replace the in-application layers above, which see the actual form contents, but it means the load reaching your site is lighter than the raw internet would otherwise throw at it.
The trade-off to watch is legitimate users sharing an address. Visitors behind a shared office connection, a mobile carrier, or a corporate network can all appear to come from one IP, so set limits generously enough that a genuine burst of real activity is not mistaken for an attack.
## Layer Five: A Spam-Filtering Service for the Spam That Looks Real
The layers so far are strongest against automated spam. What they struggle with is the hand-written spam that behaves like a real submission: correct fields, human timing, no obvious link flood. Catching that reliably means judging the *content*, and the practical way to do it is a hosted spam-filtering service that compares each submission against a constantly updated database of spam seen across many sites, combined with behavioural analysis.
Akismet is the best-known example and ships bundled with many WordPress installations, which makes it the default many people reach for; it is made by the company behind WordPress.com. It is offered here purely as an example of the category, not as an endorsement, and there are several comparable services, some of which advertise handling spam without sending as much data off-site. Two things are genuinely worth knowing before you turn one on:
- **Licensing.** Akismet's free tier is intended for personal, non-commercial sites. If your site sells anything, carries ads, or is otherwise a business, its terms require a paid plan. Read the current terms for whichever service you choose so a commercial site is correctly licensed.
- **Privacy.** These services work by sending the submitted content, along with details such as the commenter's IP address and email, to a third party for a verdict. That is how they achieve their accuracy, but it is a data-sharing decision you are making on your visitors' behalf, and it may need mentioning in your privacy policy to stay compliant with the POPIA and similar rules. The cookieless, less data-hungry alternatives exist partly to soften this.
Used well, a content-filtering service is the layer that mops up what everything else misses, sorting suspected spam into a dedicated queue you can empty in one click rather than moderating each comment by hand.
## Protecting Contact Forms and Other Forms, Not Just Comments
Everything above applies just as much to contact forms, quote requests, newsletter sign-ups, and registration forms as it does to the comment box, and it is easy to secure comments while leaving a contact form wide open. A few form-specific measures are worth adding:
- **Turn on the anti-spam features your form tool already has.** Most reputable form plugins include a honeypot and a CAPTCHA integration in their settings; the commonest mistake is simply never switching them on. Enable the honeypot at minimum, and add a CAPTCHA on forms that attract abuse.
- **Validate and constrain fields.** Requiring a properly formatted email, setting sensible minimum and maximum lengths, and rejecting fields that should never contain a URL all quietly defeat a lot of low-effort bots. The more specific your form is about what it accepts, the less generic spam fits through it.
- **Only ask for what you need.** Every extra open field is another thing for a bot to stuff with links. A lean form is a smaller target.
- **Guard the registration and login forms.** If you allow user registration, apply a CAPTCHA to the sign-up form, since fake accounts are a common goal. Protecting the login form with a challenge and with rate limiting also slows password-guessing, which sits alongside spam as part of the same automated nuisance.
## Putting It Together: A Sensible Stack
You do not need every layer, and piling all of them on at once adds friction and complication for little extra gain. Build up only as far as your spam problem requires.
- **Most small sites and blogs.** Configure the built-in Discussion settings well (require a previously approved comment, hold comments with one or more links, close comments on old posts, turn off pingbacks) and add a honeypot. This costs your visitors nothing and removes the overwhelming majority of spam.
- **Sites still getting spam, or with busy public forms.** Add an invisible CAPTCHA to comments and forms, and turn on rate limiting or a security plugin that provides it. This handles the more persistent bots.
- **Sites with real discussion, commercial sites, or anything still seeing hand-written spam.** Add a content-filtering service on top, correctly licensed and noted in your privacy policy, to catch the human-quality spam the automated layers cannot.
Spam control is one item on a wider list of things worth keeping tidy on a WordPress site. It sits alongside the other measures in the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/), which is worth working through in full.

## Troubleshooting
- **Symptom**: genuine comments are disappearing entirely, with no trace in the queue or trash. A word in the comment matched your **Disallowed Comment Keys** list, which deletes silently. Review that box, remove anything broad, and remember that matching happens inside words, so a short entry can catch innocent text. Move anything uncertain to the Comment Moderation box, which only holds rather than deletes.
- **Symptom**: every comment, even obviously real ones, is going to the moderation queue. Check **Settings > Discussion**: either **An administrator must always approve the comment** is ticked, or your link limit is set very low, or a common word is on your moderation list. Adjust whichever is over-catching.
- **Symptom**: real visitors report that your contact form rejects them as spam. A honeypot is likely being triggered by a browser autofill or password manager filling the hidden field, or a timing check is too aggressive. Update to a honeypot implementation that marks the field correctly for autofill and assistive technology, and loosen any minimum-time threshold.
- **Symptom**: you turned off comments in settings but old posts still receive spam. WordPress applies that change only to content published afterwards. Close comments on existing posts individually in the editor, or select them all on the Posts screen and use **Bulk actions > Edit** to set comments to **Do not allow**.
- **Symptom**: your CAPTCHA is visible and annoying real visitors on a low-risk form. You are probably using an interactive mode where an invisible, score-based mode would do. Switch the widget to its invisible or managed mode, and reserve visible challenges for high-value forms such as login or checkout.
- **Symptom**: spam stopped for a while, then came back. Spammers adapt, and a single layer that worked last year may have been defeated. Add another layer rather than replacing the one that slipped, since defence in depth is what holds up over time.
If spam is overwhelming your site, or you would like help choosing and configuring the right combination of these layers for your traffic, open a support ticket with the Noiz support team. Include your domain, which forms are being hit (comments, contact form, registrations, or login), and roughly how much spam you are seeing, and a technician can help you put a proportionate defence in place.
# How to Use WordPress Built-in Privacy Tools
Source: https://docs.noiz.ie/wordpress/how-to-use-wordpress-built-in-privacy-tools/
WordPress has a set of privacy tools built into every standard installation, and this guide shows you how to use them to handle the data-subject requests that data protection law expects a website owner to answer. You will set up a privacy policy page, respond to a request from someone who wants a copy of their personal data, and respond to a request from someone who wants their personal data deleted. All three tasks are done from the WordPress admin area with no extra plugin, because the features are part of WordPress core. This guide is written for Noiz clients who run their own WordPress site, and it explains not only which buttons to press but the two things the official documentation understates: exactly what these tools do and do not reach, and the practical hosting details that decide whether the whole process actually works.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Privacy (WordPress Documentation)](https://wordpress.org/documentation/article/wordpress-privacy/): the overview of the privacy features built into WordPress and the thinking behind them.
- [Settings Privacy screen (WordPress Documentation)](https://wordpress.org/documentation/article/settings-privacy-screen/): the built-in **Settings > Privacy** tool for creating or nominating a privacy policy page.
- [Tools Export Personal Data screen (WordPress Documentation)](https://wordpress.org/documentation/article/tools-export-personal-data-screen/): the official reference for producing a data export file.
- [Tools Erase Personal Data screen (WordPress Documentation)](https://wordpress.org/documentation/article/tools-erase-personal-data-screen/): the official reference for erasing a person's data.
- [Privacy (WordPress Developer Resources)](https://developer.wordpress.org/plugins/privacy/): how plugins plug their own data into these tools, useful background for understanding what "participating plugins" means.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an administrator. These tools are only visible to administrator accounts.
- Your site can send email reliably. The export and erase tools work by sending a confirmation link to the person making the request, so if your site cannot deliver email, the process stalls at the first step. This is the single most common reason these tools appear "broken", and it is covered in Troubleshooting below.
- A recent, restorable backup of your site, before you action any erasure. An erasure permanently removes data from your database and cannot be undone.
## What These Tools Do, and What They Do Not
Before touching any button, it is worth being clear about the boundary of what WordPress can do for you here, because misunderstanding it is how site owners end up thinking they have complied when they have not.
The built-in tools gather and remove personal data from **WordPress itself and from plugins that participate in the privacy system**. From WordPress core that means account details, the content and metadata of comments a person has left, media they uploaded, and session information. Many well-behaved plugins, for example contact form, e-commerce, membership and newsletter plugins, register their own data with these same tools, so a single export or erasure can sweep up form submissions or order records too. That is the good news, and it is genuinely useful.
The important limit is everything the tools cannot see. They do not reach data held in third-party services you send information to, such as an email marketing platform, a payment processor, an analytics service or a support desk. They do not touch server-level logs, and they deliberately do not alter your backups. A plugin that has not been written to participate in the privacy system will keep its data untouched and give you no warning that it has done so. So treat these tools as the WordPress-shaped part of a larger job, not as a complete answer to a legal request.
## Why This Matters for a South African Site
If your site collects any personal information from visitors, for example through a contact form, a comment box, an account signup or a shop checkout, then data protection law gives the people that information belongs to certain rights over it. For a South African site the relevant law is the Protection of Personal Information Act (POPIA), which among other things lets a person ask what personal information you hold about them and ask you to correct or delete it. If your site also serves visitors in the European Union or United Kingdom, the General Data Protection Regulation (GDPR) gives comparable rights of access and erasure. The WordPress export and erase tools exist precisely to help you answer those two kinds of request in a consistent, repeatable way.
One honest caveat. Neither WordPress nor this guide is legal advice, and using these tools does not by itself make your site compliant with POPIA, GDPR or any other law. What content your privacy policy must contain, how quickly you must respond to a request, and how you verify who is really asking are legal questions for you or your advisor to answer. What follows is the mechanical how-to for the WordPress side.
## Setting Up Your Privacy Policy Page
A privacy policy tells visitors what personal information your site collects and what you do with it, and having one is a baseline expectation under both POPIA and GDPR. WordPress helps you start one from a built-in template.
### Create or Nominate the Page
Go to **Settings > Privacy** in your admin area. You have two choices here:
- Click **Create New Page** to have WordPress generate a fresh draft page titled Privacy Policy, pre-filled with template text.
- Or, if you already have a privacy policy page, choose it from the **Select a Privacy Policy page** dropdown and click **Use This Page**. This tells WordPress which page is your official policy so it can link to it in the right places.

### Use the Policy Guide, Do Not Just Publish the Template
This is where most people go wrong. The page WordPress creates is a **starting template with placeholder guidance**, not a finished policy, and publishing it as-is leaves you with a document full of prompts that do not describe your actual site. On the Settings > Privacy screen, switch to the **Policy Guide** tab, which WordPress also links to from the draft policy page it generates. The guide assembles suggested wording drawn from WordPress and from every participating plugin you have installed, so a site running a shop or a form builder will see extra suggested sections that reflect the data those plugins collect. Copy the parts that apply, adapt the wording to describe what your site really does, delete the rest, and only then publish. It remains your responsibility to keep the policy accurate as your site changes.

### Make Sure Visitors Can Find It
Once a policy page is nominated, WordPress automatically links to it from your login and registration pages, and most modern themes offer a way to place the policy link in the site footer so it appears on every page. Check your theme's footer or menu settings and add the link if it is not already there, since a policy nobody can find serves little purpose.
## Handling a Request to Export Someone's Data
When a person asks for a copy of the personal data your site holds about them (an access request under POPIA, or a subject access request under GDPR), the Export Personal Data tool produces a downloadable file you can hand over.
### Start the Request
Go to **Tools > Export Personal Data**. Enter the person's username or email address and click **Send Request**. The request now appears in the table below with a **Status** of *Pending*, and WordPress emails the person a confirmation link with the subject line "Confirm Action: Export Personal Data".

### Wait for Confirmation, Then Send the Data
The confirmation step is a deliberate safeguard: it means data is only released to someone who can prove they control that email address, which protects you from handing a stranger somebody else's information. When the person clicks the link, the request status changes to *Confirmed* and a **Email Data** button appears under **Next steps**. Click it, and WordPress builds a `.zip` archive and emails the person a private download link. The status then moves to *Completed*. The download link is time-limited and the file is deleted automatically after three days by default, so the person should download it promptly.
The export itself is a `.zip` containing an `index.html` file that opens in any web browser and lays the data out in readable sections covering the site, the user's account information, their comments and their media, plus anything contributed by participating plugins.
### When You Need to Skip the Email
If you would rather download the file yourself, for example to review it or to send it through a channel you consider more secure, hover over the requester's email address in the table and click **Download Personal Data**. This works even while a request is still *Pending*, so use it with care: it bypasses the email confirmation, and the responsibility for confirming the person's identity by some other means then falls to you.
## Handling a Request to Erase Someone's Data
When a person asks you to delete the personal data your site holds about them (a deletion request under POPIA, or the right to erasure under GDPR), the Erase Personal Data tool removes it. Because this is permanent, take that backup first.
### Start and Confirm the Request
Go to **Tools > Erase Personal Data**, enter the username or email address, and click **Send Request**. As with exports, the person receives a confirmation email, this time headed "Confirm Action: Erase Personal Data", and the request sits at *Pending* until they click the link, at which point it becomes *Confirmed*.
### Perform the Erasure
With the request confirmed, an **Erase Personal Data** button appears under **Next steps**. Be aware that **there is no second confirmation prompt**: the moment you click that button the data is erased from your database, permanently, and the action cannot be reversed. The status then changes to *Completed*. As with the export tool, if you need to act without the email round trip you can hover over the requester's address and choose **Force Erase Personal Data**, which again places the burden of verifying identity on you.
### Understand What "Erase" Actually Removes
Two details here catch people out and are worth stating plainly. First, comments are **anonymised rather than deleted**: the comment text usually remains on your site, but the personal details attached to it, such as the author's name, email and IP address, are stripped and the author is shown as "Anonymous". This keeps the shape of a discussion intact while removing the personal data from it. Second, erasing a person's data does **not delete their WordPress user account**. If the request is that the account itself be removed, you still need to do that separately under **Users**, choosing what to do with any content they authored. The erase tool clears the personal data; it does not close the account.
Finally, remember the boundary from the start of this guide. Erasure removes data from WordPress and participating plugins only. It does not remove the person's information from your backups, and it cannot reach data you have already copied to third-party services. If you later restore your site from a backup taken before the erasure, that person's data will come back, and you would need to honour the erasure again.
## Keeping a Record
Every request you raise stays listed in the table on the Export or Erase screen, with its status and dates, until you remove it. This list is a useful informal audit trail, evidence that you received a request and acted on it, so consider leaving completed requests in place for a while rather than clearing them immediately. When you do want to tidy up, tick the request and choose **Remove** from the **Bulk actions** dropdown. Removing a request from this table only deletes the record of the request; on the export side it does not touch the person's data, and on the erase side the data is already gone.
## Troubleshooting
- **Symptom**: a request is stuck at *Pending* and the person says no confirmation email arrived. This is almost always email delivery, not the privacy tool. WordPress sends these confirmations as ordinary site email, so if that email is not being delivered the process cannot proceed. Ask the person to check their spam folder first. If the mail genuinely is not arriving, your site's email delivery needs attention, and the Noiz support team can help you get reliable email sending in place. In the meantime you can use **Download Personal Data** or **Force Erase Personal Data** to proceed manually, provided you have verified the person's identity another way.
- **Symptom**: you cannot see **Tools > Export Personal Data** or the Privacy settings at all. These screens are only available to administrator accounts. Confirm you are logged in as an administrator rather than an editor or author.
- **Symptom**: the export file seems to be missing data you know a plugin collected. That plugin has most likely not been written to participate in the WordPress privacy system, so its data is invisible to the tool. You will need to export or delete that data through the plugin's own tools, or by asking its developer how their data is handled.
- **Symptom**: the download link in the export email has stopped working. Export files are deleted automatically after a few days for security. Simply raise the request again, or use the **Download Personal Data** option to generate a fresh copy.
- **Symptom**: you erased someone's data but it reappeared. You have almost certainly restored the site from a backup made before the erasure. The privacy tools never alter backups, so an erasure must be repeated after any such restore.
If you are unsure how to respond to a data-subject request, or you want help making sure your WordPress site can send the confirmation emails these tools depend on, open a support ticket with the Noiz support team. Include your domain and a short description of the request you have received. For the wider picture of locking down your site, it is also worth working through the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/).
# How to Use the WordPress Block Editor Efficiently
Source: https://docs.noiz.ie/wordpress/how-to-use-the-wordpress-block-editor-efficiently/
This guide shows you how to get real work done faster in the WordPress block editor, the standard editor that opens whenever you add or edit a post or page. The block editor is also called the WordPress editor or Gutenberg, and its building blocks are simply called blocks. The aim here is practical: to help you compose, arrange and reuse content quickly using features that are already built in, so you install fewer plugins for jobs WordPress can already do. Every Noiz WordPress site ships with this editor, so nothing needs to be installed to follow along.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Block Editor (WordPress Documentation)](https://wordpress.org/documentation/article/wordpress-block-editor/): the official tour of the workspace, top toolbar, sidebar and Options menu.
- [Use keyboard shortcuts, Block Editor (WordPress Documentation)](https://wordpress.org/documentation/article/block-editor-keyboard-shortcuts/): the complete, canonical list of shortcuts for Windows, Linux and Mac.
- [Block patterns (WordPress Documentation)](https://wordpress.org/documentation/article/block-pattern/): how to insert and manage ready made layouts.
- [Synced patterns, formerly reusable blocks (WordPress Documentation)](https://wordpress.org/documentation/article/reusable-blocks/): how to create content that updates everywhere at once.
- [Use the List View (WordPress Documentation)](https://wordpress.org/documentation/article/list-view/): navigating, selecting and reordering blocks by their structure.
- [Core Blocks Reference (Block Editor Handbook)](https://developer.wordpress.org/block-editor/reference-guides/core-blocks/): the full list of blocks that ship with WordPress, useful before you reach for a plugin.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A post or page open for editing. Go to **Posts** or **Pages** in the left admin menu, then click **Add New** or open an existing item.
- A current, mainstream browser. The editor works best on the latest Chrome, Firefox, Edge or Safari.
## Add Blocks Without Reaching for the Mouse
Everything in a post is a block: a paragraph, a heading, an image, a list. The slow way to add one is to click the blue **+** inserter in the top left. The fast way is to stay on the keyboard.
### The Slash Command
On any empty line, type `/` followed by the block name, for example `/image`, `/heading`, `/list`, `/table` or `/columns`, then press **Enter**. A short menu of matching blocks appears as you type, so you rarely need the full name. This is the single biggest speed gain for most writers, because it inserts the right block exactly where the cursor is.
### Markdown Style Shortcuts While Typing
The editor recognises several plain-text patterns and converts them to the correct block as soon as you press **Space** or **Enter**. You do not need a Markdown plugin for any of these:
- Type `##` then a space for a Heading 2, `###` for Heading 3, and so on up to `######` for Heading 6.
- Type `*` or `-` then a space to start a bulleted list.
- Type `1.` then a space to start a numbered list.
- Type `>` then a space to start a quote.
- Type `---` (three hyphens) to insert a horizontal separator.
- Type three backticks to start a code block.
- Select some text and press the backtick key to turn it into inline code.
Two more autocompleters save time inside text: type `@` to mention a user, and type `[[` to search your existing posts and pages and drop in a link to one without leaving the keyboard.
## Insert Ready Made Layouts With Patterns
A pattern is a pre-arranged group of blocks, for example a hero header, a three-column feature row, a pricing table or a call-to-action banner. Patterns let you drop in a finished, styled layout and then replace the placeholder text and images, instead of building the structure block by block.
1. Click the **+** block inserter in the top left.
2. Select the **Patterns** tab.
3. Browse the categories, or use the search box. Your active theme supplies its own patterns, and WordPress also lists community patterns from the pattern directory.
4. Click a pattern to insert it at the cursor, then edit the placeholder content in place.
Patterns inserted this way are unsynced: each copy is independent, so editing one has no effect on the others. That is what you want for page layouts you intend to customise. When you want the opposite behaviour, see synced patterns below.
## Reuse Content Everywhere With Synced Patterns
Synced patterns are what were called reusable blocks until WordPress 6.3. A synced pattern is a saved block or group of blocks that stays identical everywhere you use it. Edit it once and every instance across your site updates automatically. This is ideal for a standard sign-off, an author bio, a promotional banner, or contact details that must never drift out of step. There is no need for a content-snippet plugin to do this.
### Create a Synced Pattern
1. Select the block or blocks you want to reuse. To select several, hold **Shift** and click each one, or drag across them in the List View.
2. Click the three-dot **Options** icon on the block toolbar and choose **Create pattern**.
3. Give the pattern a clear name, leave **Synced** switched on, and click **Create**.
To reuse it, open the inserter, go to the **Patterns** tab and look under **My patterns**, or type `/` and start typing the pattern name.
### Edit or Detach a Synced Pattern
Editing the content of a synced pattern anywhere changes it everywhere, so make deliberate edits with that in mind. If you want a one-off variation on a single page, select the pattern, open the **Options** menu and choose **Detach**. This turns that instance back into ordinary blocks you can change freely, while every other instance stays synced. To rename or delete synced patterns in one place, open the **Options** menu in the top right of the editor and choose **Manage patterns**.
## Navigate and Reorder With the List View
The List View is a collapsible tree of every block on the page, shown down the left side. It is the fastest way to work with long or deeply nested content, and it removes most of the fiddly clicking that trips people up in the main canvas.
- Open it from the **Document Overview** icon (the list icon) at the top left, or press `Shift + Alt + O` on Windows and Linux, or `Ctrl + Option + O` on a Mac.
- Click any entry to jump straight to that block, which is far quicker than scrolling.
- Drag entries up or down to reorder blocks, including moving a block into or out of a group or column.
- Click the three-dot menu on any entry to duplicate, delete or lock that block.
- Switch to the **Outline** tab in the same panel to see your heading structure, word count and reading time. Use it to check that headings step down in order without skipping a level, which matters for readers and for search engines.
## Jump Anywhere With the Command Palette
The command palette is a search box for actions and destinations. Press `Ctrl + K` on Windows and Linux, or `Cmd + K` on a Mac, then start typing what you want, for example "add heading", "duplicate", "code editor", or the title of another page to open it. It is the quickest route to commands that are otherwise buried in menus.
**One gotcha worth knowing:** when your cursor is inside text and you have some text selected, `Ctrl + K` or `Cmd + K` creates a link on that text instead of opening the palette, because link creation shares the same shortcut. To open the palette reliably, click into open canvas first, or click the search or command field in the centre of the top toolbar.
## Keyboard Shortcuts Worth Memorising
You can see the full list at any time by pressing `Shift + Alt + H` on Windows and Linux, or `Ctrl + Option + H` on a Mac. The shortcuts below are the ones that pay off in daily writing. As a rule, where Windows and Linux use **Ctrl**, a Mac uses **Cmd**, but note the exceptions listed, because the **Shift + Alt** combinations map to **Ctrl + Option** on a Mac rather than a simple swap.
### Everyday Actions
- **Save draft**: `Ctrl + S`, or `Cmd + S` on a Mac.
- **Undo**: `Ctrl + Z`. **Redo**: `Ctrl + Shift + Z`.
- **Bold, italic, underline**: `Ctrl + B`, `Ctrl + I`, `Ctrl + U`.
- **Add or edit a link**: select text, then `Ctrl + K`. **Remove a link**: `Ctrl + Shift + K`.
- **Inline code**: select text, then `Ctrl + Alt + X` (Mac: `Cmd + Alt + X`), or simply press the backtick key.
### Working With Blocks
- **Duplicate the selected block**: `Ctrl + Shift + D`.
- **Delete the selected block**: `Shift + Alt + Z` on Windows and Linux, or `Ctrl + Option + Z` on a Mac.
- **Group the selected blocks**: `Ctrl + G`. This wraps them in a single Group block you can style or move as a unit.
- **Insert a block before or after the current one**: `Ctrl + Alt + T` and `Ctrl + Alt + Y` (Mac: `Option + Cmd + T` and `Option + Cmd + Y`).
- **Convert a paragraph to a heading**: `Shift + Alt + 1` to `6` for the heading level (Mac: `Cmd + Alt + 1` to `6`); `Shift + Alt + 0` turns a heading back into a paragraph.
- **Copy styles and paste styles**: use **Copy styles** from a block's **Options** menu, select another block of the same type, then paste with `Ctrl + Alt + V` (Mac: `Cmd + Alt + V`). This copies the colour, spacing and typography without copying the content.
### Moving Around the Editor
- **Open or close the settings sidebar**: `Ctrl + Shift + ,` (comma), or `Cmd + Shift + ,` on a Mac.
- **Open the List View**: `Shift + Alt + O`, or `Ctrl + Option + O` on a Mac.
- **Switch between the visual editor and the code editor**: `Ctrl + Shift + Alt + M` (Mac: `Shift + Option + Cmd + M`).
- **Toggle fullscreen**: `Ctrl + Shift + Alt + F` (Mac: `Shift + Option + Cmd + F`).
## Focus Modes That Cut the Clutter
The editor has several viewing modes, reached from the three-dot **Options** menu in the top right, under **View**. None require a plugin.
- **Distraction free**: hides the sidebars, block toolbars and inserter so only your words remain. The controls fade back in when you move the mouse to the top of the screen. Ideal for drafting.
- **Spotlight mode**: dims every block except the one you are editing, which helps you concentrate on a single passage in a long page.
- **Top toolbar**: pins each block's toolbar to the top of the editor instead of floating it above the block. Many people find this steadier, because the toolbar stops jumping around as they scroll.
- **Fullscreen mode**: hides the WordPress admin menu so the editor fills the window. It is on by default; turn it off here if you prefer to keep the admin menu in view.
## Built-In Features That Replace Common Plugins
Before adding a plugin for a formatting or layout job, check whether a core block already does it. Fewer plugins means a lighter, faster site with a smaller attack surface to keep patched, which is exactly the principle behind the [WordPress Security Checklist](/wordpress/wordpress-security-checklist/). The following are all built in and need nothing extra installed.
- **Accordions and expandable sections**: the **Details** block creates a click-to-expand panel with a summary line and hidden content, so you do not need an accordion or toggle plugin for a simple FAQ.
- **Footnotes**: select a word, open the block toolbar's more-formatting menu and choose **Footnote**. WordPress numbers the note, links it, and collects all footnotes at the end of the content automatically.
- **Free, licence-safe images**: in the inserter's **Media** tab, search **Openverse** for openly licensed images and insert them straight into the page. WordPress saves a copy to your media library at the same time, so no stock-image plugin is required.
- **Multi-column and stacked layouts**: the **Columns**, **Group**, **Row** and **Stack** blocks handle side-by-side and vertical arrangements, including how they collapse on mobile, without a page-builder plugin.
- **Buttons, covers and media-and-text**: the **Buttons**, **Cover** and **Media & Text** blocks cover call-to-action buttons and image-with-overlay hero sections natively.
- **Automatic lists of posts**: the **Query Loop** block displays a filtered list of your posts, for example the latest articles in a category, which many people install a separate "recent posts" plugin to achieve.
## Lock Blocks and Limit Editing
When more than one person edits a site, it helps to protect the parts of a layout that should not move. Select a block, open the three-dot **Options** menu and choose **Lock**. You can prevent the block from being moved, prevent it from being removed, or both. To let colleagues change the words inside a layout but not its structure, select the outer group, open **Options** and choose **Content only**: only the text and images inside remain editable, and the arrangement stays put.
## Troubleshooting
- **Symptom**: pressing `Ctrl + K` creates a link instead of opening the command palette. Your cursor is inside a text field with text selected, so the link shortcut takes priority. Click into empty canvas first, or click the command field in the centre of the top toolbar to open the palette.
- **Symptom**: editing a saved block changed it on other pages too. That block is a synced pattern, which is designed to update everywhere. If you wanted a one-off change, undo it, then select the pattern, open **Options** and choose **Detach** before editing that single copy.
- **Symptom**: a keyboard shortcut does nothing. Some shortcuts only act on a selected block, so click the block first. A few combinations are also intercepted by the browser or operating system; if one is, use the equivalent button in the toolbar or the **Options** menu instead.
- **Symptom**: the toolbar keeps floating over your text and getting in the way. Turn on **Top toolbar** from the **Options** menu under **View** to pin it in a fixed position.
- **Symptom**: a block you want does not appear in the inserter search. It may be provided by a plugin or theme that is not active, or it may simply not exist in core. Check the Core Blocks Reference linked above before assuming you need a plugin, and open the inserter's **Patterns** tab in case a pattern already covers the layout.
If you get stuck building a layout or reusing content across your Noiz WordPress site, open a support ticket with the Noiz support team and include your site address, the page you are working on and a short description of what you are trying to achieve.
# How to Write and Publish Your First Blog Post in WordPress
Source: https://docs.noiz.ie/wordpress/how-to-write-and-publish-your-first-blog-post-in-wordpress/
Writing your first blog post is one of the more satisfying moments in setting up a new website. This guide walks you through creating, categorising, tagging and publishing a post in the WordPress block editor on your Noiz hosting account, and explains the two or three small things that catch first-time authors out.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress Block Editor](https://wordpress.org/documentation/article/wordpress-block-editor/) (the editing workspace and top toolbar)
- [Page/Post Settings sidebar](https://wordpress.org/documentation/article/settings-sidebar/) (Categories, Tags, Excerpt, Featured image, Status)
- [Posts Categories screen](https://wordpress.org/documentation/article/posts-categories-screen/)
- [Posts Tags screen](https://wordpress.org/documentation/article/posts-tags-screen/)
- [Editor Preferences overview](https://wordpress.org/documentation/article/preferences-overview/) (including the pre-publish checklist)
## Prerequisites
- A WordPress site installed on your Noiz hosting account.
- An account on that site with the Author, Editor or Administrator role. Contributors can write posts but cannot publish them.
- Your WordPress dashboard sign-in details. If you are not sure how to get in, see [How to log in to WordPress (Admin Dashboard)](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
The screenshots below show the standard WordPress admin. The WordPress 7.0 admin refresh changed some colours and spacing, but the menu names, panels and steps are the same.
## Write and Publish the Post
1. Log in to your WordPress dashboard at `yourdomain.com/wp-admin` (replace `yourdomain.com` with your own domain).
2. In the left-hand menu, go to **Posts** and click **Add New**. Depending on your WordPress version this item may read **Add New Post**. 
3. Enter your post title in the **Add title** field at the top, then click below it and start writing. Each paragraph, heading, image or list you add is a separate block. Press `Enter` to start a new block, or click the **+** button to choose a specific block type such as **Image** or **Heading**. 
4. Open the settings sidebar if it is not already showing: click the **Settings** (gear) icon in the top-right of the editor, then select the **Post** tab.
5. Expand **Tags**, type a tag into the **Add New Tag** box and press `Enter`. Repeat for each tag you want. Existing tags autocomplete as you type, so you reuse them rather than creating near-duplicates. 
6. Expand **Categories** and tick the category the post belongs to. To create one on the spot, click **Add New Category**, type the name, optionally pick a parent category, then click the **Add New Category** button. If you tick nothing, WordPress files the post under **Uncategorized**.
7. Click **Publish** in the top-right of the editor. WordPress then shows a confirmation panel headed **Are you ready to publish?**, listing the visibility, publish date, categories and tags. Check them and click **Publish** again to make the post live. 
8. Click **View Post** in the confirmation message to see the published post on your site.
## Why Publish Takes Two Clicks
The second click is not a glitch. It is the **pre-publish checklist**, a deliberate safety step that gives you one last look at visibility, schedule, categories and tags before anything goes public. It is the single most common point of confusion for new authors, who click **Publish** once, see a panel appear, and assume the post is already live.
If you would rather publish in one click, open the three-dot **Options** menu in the top-right, choose **Preferences**, and under **General** switch off **Include pre-publish checklist**. On a site with more than one author, Noiz suggests leaving it switched on. Recovering an accidentally published draft is far more work than one extra click.
## Categories and Tags: What the Difference Is
Both group your posts, but they are not interchangeable, and getting this right from your very first post saves a messy clean-up later.
- **Categories** are the broad sections of your site, like chapters in a book. Every post gets one, and a post should usually sit in a single category. They can be nested under a parent. Keep the list short: five to ten categories suits most sites.
- **Tags** are specific keywords describing what a post mentions, like an index at the back of a book. They are optional, flat (no hierarchy), and a post can carry several.
The mistake to avoid is creating a tag that is used exactly once. Every tag generates its own archive page, so a pile of single-use tags produces a pile of near-empty pages that dilute your site rather than help anyone find anything. A useful test: if you cannot imagine writing three more posts that would carry the same tag, do not create it.
For more on structuring these properly, see [How to Add a New Category in WordPress](/wordpress/how-to-add-a-new-category-in-wordpress/) and [How to Manage WordPress Categories the Right Way](/wordpress/how-to-manage-wordpress-categories-the-right-way/).
## Worth Setting Before You Publish
These live in the same **Post** tab of the settings sidebar and take seconds, but they are awkward to fix afterwards:
- **Slug**: the last part of the post URL. WordPress builds it from your title, so a long title becomes a long, ugly link. Shorten it to a few keywords *before* you publish. Changing a slug after publishing breaks any link already shared to that post.
- **Featured image**: most themes use this as the thumbnail on your blog index and in social media previews. Without one, your post often looks blank when shared.
- **Excerpt**: a one or two sentence summary. If you leave it empty, WordPress uses the first 55 words of the post, which rarely reads like a proper summary.
- **Publish date**: click the date under **Publish** to schedule the post for a future date and time instead of publishing immediately.
Use the **View** or preview button in the top toolbar to check how the post looks on desktop, tablet and mobile before you commit.
## Troubleshooting
**There is no Publish button, only Submit for Review**: your user account has the Contributor role, which can write but not publish. Ask a site administrator to publish the post or to raise your role to Author.
**The post is published but does not appear on the front page**: check the **Status** setting is **Published** and not **Private** or **Password protected**, confirm the publish date is not set in the future, and check under **Settings** > **Reading** that your front page is set to show your latest posts rather than a static page.
**Publishing fails with an "Updating failed" or "publishing failed" message**: this is almost always the connection to the site dropping mid-save, or a security plugin or firewall blocking the editor's requests. Your text is not lost. Copy your content out, reload the editor and try again. If it keeps happening, deactivate plugins one at a time to find the culprit.
**You lost work when the browser closed**: WordPress autosaves drafts as you type. Reopen the post and look for the revisions notice near the top of the settings sidebar to restore an earlier version.
**The editor looks unfamiliar or blocks are missing**: a plugin such as Classic Editor may be active, replacing the block editor. Check **Plugins** for anything editor-related and deactivate it if you want the block editor back. For getting faster in the block editor, see [How to Use the WordPress Block Editor Efficiently](/wordpress/how-to-use-the-wordpress-block-editor-efficiently/).
## Need a Hand?
Congratulations on your first blog post. If something in the editor is not behaving as described here, or you are on a Noiz managed hosting plan and would like the site checked over, open a support ticket from your [Noiz client area](https://www.noiz.co.za) and the support team will take a look.
# Practical Ways to Use AI with WordPress
Source: https://docs.noiz.ie/wordpress/practical-ways-to-use-ai-with-wordpress/
This guide is a practical, plain-language tour of the useful ways you can put artificial intelligence to work on a WordPress site in 2026: drafting and editing content, writing alt text for images, getting help with code, spinning up a starter site, and fitting all of it into a sensible editorial workflow. Just as importantly, it sets out the cautions that matter, accuracy, honesty with your audience, and the privacy of your data and your visitors' data. Artificial intelligence is often shortened to AI, and the writing tools behind most of these features are large language models (LLMs); an AI writing tool is sometimes called an assistant or a copilot. This article is for anyone running a WordPress site on Noiz hosting, from a solo blogger to a small editorial team, and it stays neutral: specific products are named only as examples of a category, never as a recommendation.
**Last reviewed:** 27 July 2026, against WordPress **7.0 "Armstrong"** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [WordPress 7.0 "Armstrong" release announcement](https://wordpress.org/news/2026/05/armstrong/): the official summary of the AI Client, Connectors, and collaboration features now built into WordPress core.
- [Introducing the AI Client in WordPress 7.0 (Make WordPress Core)](https://make.wordpress.org/core/2026/03/24/introducing-the-ai-client-in-wordpress-7-0/): how the provider-agnostic AI Client and Abilities API work under the bonnet.
- [WordPress AI team blog (make.wordpress.org/ai)](https://make.wordpress.org/ai/): ongoing updates on AI features being developed for WordPress core.
- [Google Search's guidance about AI-generated content](https://developers.google.com/search/blog/2023/02/google-search-and-ai-content): Google's position on quality, helpfulness, and when disclosure is appropriate.
- [W3C Web Accessibility Initiative: Images Tutorial](https://www.w3.org/WAI/tutorials/images/): the authoritative guidance on writing good alt text, including the decision tree for decorative versus meaningful images.
## Prerequisites
- A WordPress site on your Noiz hosting account, and the ability to [log in to the WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/) as an administrator, which you need to install plugins and to connect an AI provider.
- For the built-in AI features, WordPress 7.0 or later. Older versions rely entirely on plugins or on separate tools used in your browser.
- For anything that generates content or images, an account with an AI provider (for example Anthropic, Google, or OpenAI) or a plugin subscription. Almost every option is paid or metered once you go beyond a small free allowance.
## How AI Fits Into WordPress in 2026
There is no single "WordPress AI". Instead there are three layers you can draw on, often at the same time. Knowing which layer you are using helps you understand where your data goes and who is charging you for it.
- **Built into WordPress core.** Since WordPress 7.0 "Armstrong" (May 2026), WordPress ships a provider-agnostic **AI Client** and an **Abilities API**. In plain terms, WordPress can now talk to a generative AI model in a consistent way, and core uses this to suggest titles and excerpts, propose alt text for images, and generate or edit images. Crucially, nothing is sent anywhere until you connect a provider of your choice under **Settings > Connectors**. Out of the box, no AI feature is active and no content leaves your site.
- **Added by plugins.** A large and crowded field of plugins bolts AI onto specific jobs: long-form writing assistants inside the block editor, SEO helpers, chatbots and support widgets, bulk alt-text generators, and translation tools. Each plugin brings its own provider and its own billing, whether that is a monthly subscription or an API key you supply.
- **Separate tools you use alongside WordPress.** Many people never install an AI plugin at all. They draft in a standalone assistant in the browser, then paste the polished result into WordPress. A related option is a hosted AI site builder that generates a whole starter site from a description before you move in and refine it.
The practical takeaway is that you do not need to buy any one product to get value from AI on WordPress. A lot of the basic help is now in core or available free, and you can mix layers as it suits you.
## Drafting and Editing Content
Writing assistance is where most site owners start, and it is genuinely useful when treated as a first draft rather than a finished article. Sensible tasks to hand to AI include:
- Turning a rough set of notes into an outline, or an outline into a first draft.
- Rewriting a clumsy paragraph, tightening waffle, or shifting the tone to be more formal or more friendly.
- Summarising a long post into an introduction, a meta description, or social copy.
- Suggesting headline options and generating an **excerpt** for a post, which WordPress 7.0 can do natively once a provider is connected.
- Producing a rough translation to review, rather than starting a second-language version from scratch.
The gotcha is quality, not capability. An AI draft reads fluently even when it is wrong, generic, or padded. Google is explicit that it does not favour human-written or AI-written content on principle; it rewards content that is genuinely helpful and demonstrates real experience and expertise, and its 2026 updates specifically target thin, robotic, low-value text. So the value you add after the draft, your own knowledge, real examples, correct facts, and a distinct voice, is exactly what separates a page that ranks and helps from one that does not. Never publish a first draft as-is.
## Writing Alt Text for Images
Alt text is the short written description attached to an image. It is read aloud by screen readers for people who cannot see the image, shown when an image fails to load, and used by search engines to understand your pictures. Good alt text is one of the simplest accessibility wins on any site, and it is exactly the kind of repetitive job AI is well suited to.
WordPress 7.0 can **suggest alt text** for an image directly, once a provider is connected, and several plugins can generate descriptions in bulk across an entire media library, which is a real time-saver on a site with hundreds of un-described images.
Two cautions keep AI alt text honest:
- **AI describes what is in the picture, not what it means on your page.** A photo of a person at a laptop might be captioned literally by AI, when the point of the image on your page is that your support team responds within an hour. Read every suggestion and edit it to fit the context.
- **Decorative images should have empty alt text, not a description.** A background flourish or a divider adds nothing for a screen-reader user, so it should be marked as decorative rather than described. AI tools tend to describe everything. The W3C Images Tutorial linked above has a clear decision tree for this.
## Getting Help With Code and Troubleshooting
AI is a capable coding companion for the small customisations WordPress site owners often need: a snippet for `functions.php`, a rule of custom CSS, a tweak to a template, or an explanation of a cryptic error message. It is also good at spot-checking unfamiliar code, for example reviewing a snippet you found on a forum before you trust it.
This is also where the sharpest cautions apply, because code runs with full access to your site:
- **Never paste AI-generated PHP straight onto a live site.** Try it on a staging or test copy first, and take a backup before you make the change. A single bad snippet in `functions.php` can take a whole site offline.
- **AI can produce insecure code.** The most common WordPress vulnerabilities, cross-site scripting and SQL injection, come from code that fails to sanitise input or escape output. AI sometimes skips those safeguards. If you ask for database code, explicitly ask it to use `$wpdb->prepare()`, proper sanitisation and escaping, and a nonce for form handling, then have the result reviewed.
- **AI can target the wrong version.** A model may suggest a function or hook that was deprecated years ago, or one that only exists in a newer release than you run. Cross-check anything unfamiliar against the official developer documentation.
A newer development is AI agents that can act on a WordPress site directly, through emerging integrations, rather than just handing you code to paste. These are powerful, and precisely because they can change files and the database, they should only ever be pointed at a staging environment first, never your live site. If you are unsure how to set up a safe staging copy, Noiz support can help.
## Building a Whole Site With AI
Hosted AI site builders take a different approach: you describe the site you want in a sentence or two, answer a few questions, and the tool generates a complete starting layout with placeholder content and images in minutes. It is a fast way to get past the blank page, and you can keep refining by chatting to the tool or by editing in the normal block editor afterwards.
Treat the output as a scaffold, not a finished product. Generated copy still needs your real business details, your genuine expertise, and your own images where accuracy matters. It will not know your prices, your policies, or your legal pages, and stock AI images can make a site feel generic. The builder saves you the first hour; it does not replace the judgement that makes a site trustworthy.
## Fitting AI Into an Editorial Workflow
If more than one person touches your content, decide deliberately where AI is allowed and where a human must sign off, then build that into your process rather than leaving it to chance. WordPress 7.0 helps here: it adds asynchronous collaboration tools including block-level **Notes**, a **Suggestions** mode, and **@mentions**, which give you a natural place for a human to review, comment on, and approve AI-assisted drafts before they go live.
A workable rule of thumb for most teams:
- **Fine to delegate to AI, with a light review:** outlines, first drafts, rewording, alt text, tag and category suggestions, translation drafts.
- **A human must verify and own:** facts, figures, quotes, product claims, legal and medical or financial information, and anything published under a named author's byline.
The consistent thread is a human editor in the loop: AI drafts, a person edits and checks, a reviewer approves, and only then does it publish. AI changes how the first draft appears; it does not remove your responsibility for what you publish.
## Cautions Every Site Owner Should Weigh
The benefits above are real, but they come with responsibilities that are easy to overlook when a tool makes everything feel effortless.
### Accuracy and made-up facts
AI models generate plausible text, and plausible is not the same as correct. They can invent statistics, misattribute quotes, cite sources that do not exist, and describe features a plugin does not have. Verify every fact, figure, and code sample against a trustworthy source before you rely on it. The more confident the AI sounds, the more it is worth checking.
### Honesty and disclosure
Google does not require you to label every AI-assisted page, and it does not penalise AI content simply for being AI content. It does expect content to be helpful and honest. In some contexts disclosure is the right thing to do anyway: reviews and testimonials, regulated advice, and product listings where an AI-generated image or description could mislead a buyer. If a reader would reasonably want to know how something was made, tell them. Being straight with your audience protects the trust your site depends on.
### Privacy and data protection
This is the caution most often missed. When an AI plugin or connected provider processes your content, that content is sent to a third-party server, and it may include personal data: visitor comments, contact-form entries, support-chat messages, or customer details. As the site owner you remain responsible for that data under South Africa's Protection of Personal Information Act (POPIA) and, if you serve visitors in Europe, the GDPR. Practical steps:
- Check the provider's data-retention and model-training policy before you connect it. Some retain inputs unless you opt out; a provider that trains on your submissions is a very different proposition to one that does not.
- Never paste personal, confidential, or customer data into a general-purpose AI tool that you have not vetted for this.
- Update your website privacy policy to disclose the third-party AI processing, and obtain consent at the point visitor data would be sent, for example before a chatbot forwards a visitor's message. A line buried in a privacy policy is not, on its own, valid consent.
- Where data sensitivity is high, prefer a provider with a clear no-training commitment, or a self-hosted model, both of which WordPress 7.0's provider-agnostic design supports.
### Cost, security, and lock-in
AI is rarely free at scale. Subscriptions recur and API usage is metered, so image generation and high-volume writing can add up quickly; keep an eye on your provider's billing. On the security side, keep current backups before letting any AI make changes, grant tools only the access they need, and lean on your existing hardening habits. The [WordPress Security Checklist](/wordpress/wordpress-security-checklist/) covers the backups, least-privilege user roles, and update discipline that make AI experimentation safe to undo. Finally, because WordPress core keeps AI provider-agnostic, you can switch providers without rebuilding your site, which is a genuine hedge against being locked in to one vendor's pricing.
## Common Pitfalls
- **AI options are greyed out or do nothing in the editor**: on WordPress 7.0, no provider is connected under **Settings > Connectors**, so core has nothing to send prompts to. With a plugin, it usually means an API key has not been entered or a subscription is inactive.
- **An AI plugin reports a quota, credit, or billing error**: the connected API key has run out of credit or hit its usage cap. Top up with the provider, or check your subscription status.
- **Published content reads generic or robotic**: it was published too close to the raw draft. Rewrite in your own voice, add specific examples and first-hand detail, and cut anything that could appear on any site in your niche.
- **You are unsure who can see your data**: stop and check the provider's retention and training policy before sending anything further, and never submit personal or customer data you have not cleared for third-party processing.
- **AI-generated code broke your site**: restore the backup you took beforehand, or remove the last snippet you added to `functions.php`. In future, test code on a staging copy first. If you are locked out entirely, Noiz support can help you recover access.
AI can save you real time on a WordPress site when you use it as a capable assistant and stay the editor in charge. If you would like help setting up a safe staging environment to test AI-generated code, sorting out backups before you experiment, or checking that your privacy policy reflects the tools you use, open a support ticket with the Noiz support team and describe what you are trying to achieve.
# When to Replace an Outdated or Abandoned WordPress Plugin
Source: https://docs.noiz.ie/wordpress/when-to-replace-an-outdated-or-abandoned-wordpress-plugin/
This guide helps you decide when an outdated WordPress plugin has become a liability worth replacing, and how to replace it safely once you have made that call. It covers the signals that separate a plugin that is simply a little behind from one that is genuinely abandoned, a plain decision framework for what to do about each, and the practical options for replacing a plugin, including swapping in a maintained alternative, using functionality that is now built into WordPress, or dropping a small single-purpose plugin in favour of a short code snippet. An abandoned plugin is also called an unmaintained, orphaned or discontinued plugin; the advice here applies to all of them. It is written for Noiz clients who run their own WordPress site and manage their own plugins, and it deliberately names plugin categories rather than endorsing any single plugin.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation linked below.
### Official Documentation Reference
- [Manage Plugins (WordPress Documentation)](https://wordpress.org/documentation/article/manage-plugins/): the official guide to installing, updating, deactivating and deleting plugins, including plugin compatibility notices.
- [Site Health screen (WordPress Documentation)](https://wordpress.org/documentation/article/site-health-screen/): the built-in **Tools > Site Health** diagnostics, which list your active and inactive plugins and flag plugins waiting to be updated.
- [Plugin and themes auto-updates (WordPress Documentation)](https://wordpress.org/documentation/article/plugins-themes-auto-updates/): how to switch on automatic updates plugin by plugin, a feature built into WordPress core since version 5.5.
- [Detailed Plugin Guidelines (WordPress Developer Resources)](https://developer.wordpress.org/plugins/wordpress-org/detailed-plugin-guidelines/): the rules a directory plugin must follow, and the basis on which a plugin is closed for a guideline or security problem.
- [WordPress Plugin Directory](https://wordpress.org/plugins/): each plugin's public page shows its last-updated date, active-install range, tested-up-to version and support activity.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A recent, restorable backup of your site (files and database). Removing or replacing a plugin can change how your site behaves, so a backup is your safety net before you start.
- Ideally a staging copy of the site where you can test a replacement before touching the live site. If you do not have staging, the Noiz support team can help you set one up.
## What "Outdated" and "Abandoned" Actually Mean
Not every plugin that shows an old date is a problem, and this is where a lot of well-meaning advice goes wrong. A small, stable plugin that does one narrow job can go a year or two without an update simply because it still works and there is nothing to change. The version number sitting still is not, on its own, proof of neglect.
What matters is the difference between a plugin that is **merely behind** and one that is **genuinely abandoned**. A plugin is genuinely abandoned when the developer has stopped responding, stopped fixing reported bugs, and stopped keeping pace with WordPress and PHP. That is the situation that turns into a security and compatibility risk over time, because when a vulnerability is found in an abandoned plugin, nobody ships a fix. The job of this guide is to help you tell those two cases apart using evidence rather than a gut feeling about the date.
## The Signals That Tell You a Plugin Is in Trouble
No single number decides this. Weigh the signals below together. One amber flag on an otherwise healthy plugin is usually nothing; several of them at once is a plugin to replace. You can read most of these directly from the plugin's public page in the WordPress Plugin Directory, and some from your own dashboard.
### Last Updated Date
On the plugin's directory page, the **Last updated** date tells you when the developer last shipped anything. Read it in context of what the plugin does: a complex plugin that touches security, payments, forms or anything that interacts with WordPress internals should be updated regularly, so a gap of a year is a real concern. For a tiny cosmetic plugin the same gap means much less. As a rough rule, once a plugin has gone more than a year without any update, start paying closer attention to the other signals below.
### Active Installations Trend
The directory shows active installs as a range, for example "10,000+ active installations". The number itself is less useful than the direction. A plugin whose install range has visibly fallen over successive visits is one that other site owners are leaving, and they are usually leaving for a reason. Note that once a plugin is formally closed by WordPress.org, the directory stops publishing its install count entirely, so a plugin whose statistics have vanished is a warning in its own right.
### "Tested Up To" and the Latest Releases Warning
Every directory plugin declares a **Tested up to** value, the most recent WordPress version the developer says they have checked it against. This is the developer's own claim, not a guarantee, and a plugin can work perfectly on a newer version than it was tested against. Its absence, though, is a strong signal of neglect.
WordPress makes this easy to spot. When a plugin has not been tested with the latest three major releases of WordPress, its directory page and your dashboard show the warning "This plugin hasn't been tested with the latest 3 major releases of WordPress." Reaching that point means the developer has sat out three major cycles without confirming the plugin still works, and it is a reliable marker that a plugin has drifted into the abandoned category. Treat that warning as a prompt to check the other signals and plan a replacement, not as proof the plugin is broken today.
You can see the flip side of this before you ever install anything. On **Plugins > Add New**, each plugin is labelled "Compatible with your version of WordPress" or "Untested with your version of WordPress", and clicking **More Details** shows the full compatibility information.
### Support Forum Activity
On the plugin's directory page, open the **Support** tab and the reviews. A healthy plugin has recent threads with replies from the developer and a reasonable share of resolved topics. A plugin in trouble shows a wall of unanswered questions, months-old bug reports with no response, and recent one-star reviews saying the developer has gone quiet. Developer silence in the support forum is often the earliest visible sign of abandonment, appearing well before the update date looks alarming.
### Known Vulnerabilities and Directory Closures
This is the signal that overrides all the others. Two situations demand action regardless of how the plugin looks otherwise.
First, a **known unpatched vulnerability**. Public vulnerability databases track security issues in WordPress plugins, and many security plugins and services will alert you if an installed plugin has a reported flaw. If a plugin has a known vulnerability and no fixed version has been released, it is a live risk and should be replaced without waiting.
Second, and this is the one that catches people out, a plugin that has been **closed or removed from the directory**. WordPress.org closes a plugin when it breaks the plugin guidelines or when a security issue is found in it, and while it is closed nobody can download it and it receives no updates. The critical gotcha is that WordPress core gives you **no warning in your admin area** when a plugin you already have installed is closed or removed. The plugin keeps running, keeps whatever vulnerability caused the closure, and simply stops receiving updates silently. Because of this blind spot, it is worth checking the directory page of your important plugins from time to time: if the page now says the plugin has been closed, or the page has disappeared, remove that plugin from your site straight away and find a maintained replacement.
### Required WordPress and PHP Versions
A directory plugin also declares the minimum WordPress version and minimum PHP version it needs. These matter in the opposite direction from the others: a well-maintained plugin keeps its requirements current, whereas a plugin that still lists a very old minimum PHP version has usually not been modernised in a long time. You can see the PHP version your site actually runs under **Tools > Site Health > Info**, in the **Server** section. If a plugin requires a newer PHP version than your site provides, WordPress will refuse to activate it and tell you why.
## A Simple Decision Framework
Put the signals together and most plugins fall into one of three buckets.
- **Keep it.** Recently updated, tested against a current WordPress version, an active support forum, no known security issues. Nothing to do beyond keeping it updated. Switching on automatic updates for this kind of plugin, plugin by plugin, on **Plugins > Installed Plugins**, is a sensible way to stay current with security fixes.
- **Watch it.** A single amber flag, for example an update gap approaching a year, or a "tested up to" value one major version behind, but otherwise healthy and doing a job you rely on. Note it, keep a maintained alternative in mind, and re-check in a few months. Do not rush to rip out something that works.
- **Replace it now.** Any of the hard triggers: a known unpatched vulnerability; the plugin has been closed or removed from the directory; it shows the "hasn't been tested with the latest 3 major releases" warning alongside a silent support forum; or it has stopped working correctly on your current WordPress version. These are not "watch and wait" situations.
## How to Replace an Outdated Plugin
Once a plugin is in the replace-now bucket, work through the options below in order. The first fit is usually the best one.
### Check Whether the Job Is Now Built Into WordPress
Plugins are often written to fill a gap that WordPress later closes in core. Several tasks that used to need a dedicated plugin are now standard WordPress features, for example enabling automatic plugin and theme updates, or diagnosing site problems through **Tools > Site Health**. Before you reach for a replacement plugin, check whether the thing the old plugin did is something current WordPress already does on its own. If it is, you can retire the plugin without adding anything back.
### Find and Vet a Maintained Alternative
For most plugins the answer is a like-for-like replacement that is actively maintained. The important discipline here is to judge the candidate by exactly the same signals you used to condemn the old one: recent updates, tested against a current WordPress version, a responsive support forum, a healthy install trend and no open security issues. There is no point replacing one abandoned plugin with another that is six months behind it on the same road. Where a task is well served by several comparable plugins, pick on maintenance and reputation rather than feature count, and prefer the option that adds the least to your site.
### Migrate, Deactivate, Test, Then Delete
Replace in a safe order so you can always step back:
1. Take a fresh backup, and do this on your staging copy first if you have one.
2. Install and configure the replacement plugin. If the old plugin stored content or settings, export or migrate that data before you remove it.
3. Deactivate the old plugin and confirm the site and the replacement behave correctly.
4. Once you are satisfied, **delete** the old plugin, do not simply leave it deactivated.
That last point is a real and widely underestimated gotcha. Deactivating a plugin does not remove it: its files stay on your server, and some vulnerabilities in plugin files can be exploited even while the plugin is switched off. A deactivated plugin is only fully out of harm's way once it is deleted. WordPress's own Site Health lists your inactive plugins for exactly this reason and recommends removing anything you are not using.

## Replacing a Small Plugin With a Code Snippet
Some plugins do so little that a few lines of code do the same job with none of the maintenance risk. A plugin that only injects a verification tag into your site header, adds one small tweak, or disables a single feature is a good candidate. Removing it and adding a short snippet means one fewer plugin to keep updated, patch and worry about. This route is for people comfortable editing code; if that is not you, a maintained plugin or a quick word with Noiz support is the safer choice, and there is no shame in that.
If you do go the snippet route, add the code as a small **site-specific plugin** rather than editing your theme's `functions.php`. A site-specific plugin is just a single PHP file in `wp-content/plugins` (or in `wp-content/mu-plugins`, the must-use folder, where it loads automatically and cannot be switched off by accident). The advantage over editing the theme is that your customisations survive theme changes and updates, and stay separate from the theme's own code. Here is the shape of one:
```
,
// a job often handled by a dedicated "header code" plugin.
// Replace the name and content values with your own.
add_action( 'wp_head', function () {
echo '' . "\n";
} );
```
Two warnings before you paste anything live. First, a single PHP syntax error in a snippet like this can take your whole site down with a white screen, so always test on staging and keep that backup ready. Second, only use snippets you understand or that come from a source you trust; a snippet is code running with full access to your site, exactly like a plugin. If you would rather not touch files at all, there is a whole category of snippet-manager plugins that let you paste and toggle small pieces of code from the dashboard with some protection against fatal errors; that is a reasonable middle ground, though it does mean keeping one such plugin installed.
## Reducing Your Plugin Count
Every plugin you run is code with deep access to your site, another thing to keep updated, and another potential way in for an attacker. Fewer plugins means a smaller attack surface, fewer update conflicts, and often a faster site. Replacing abandoned plugins is a good moment to trim the list as a whole.
- **Audit regularly.** Once or twice a year, read down **Plugins > Installed Plugins** and ask of each one whether it is still doing a job you actually need. Plugins installed to try something out have a habit of never being removed.
- **Delete inactive plugins.** Anything sitting deactivated is doing nothing but adding risk. Delete it; you can always reinstall later. Site Health's **Info** tab lists your inactive plugins to make them easy to find.
- **Prefer one capable plugin over several narrow ones** where a single well-maintained plugin covers what two or three separate ones were doing, and prefer core WordPress features or a small snippet over a plugin for trivial jobs.
Keeping the plugin list lean and current is one of the highest-value things you can do for site security. It sits alongside the other measures in the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/), which is worth working through in full.

## Troubleshooting
- **Symptom**: after deleting a plugin, its shortcodes now show as raw text like `[old_shortcode]` on your pages. The feature that produced them has gone with the plugin. Replace those shortcodes with the equivalent from your new plugin, or remove them from the affected content.
- **Symptom**: you deleted a plugin but leftover settings or database tables remain. Many plugins deliberately keep their data on deletion so you can reinstall without losing it. This is usually harmless, but if you want it gone, check whether the plugin offered a "remove all data on uninstall" option before you deleted it, or ask Noiz support to help clean up orphaned data.
- **Symptom**: the site shows a blank white page or a critical error after you swapped or replaced a plugin. WordPress usually emails the site administrator a recovery link when this happens. If it does not, connect via your file manager or SFTP, go to `wp-content/plugins`, and rename the folder of the plugin you just changed; that deactivates it and should restore access so you can investigate.
- **Symptom**: you cannot tell whether a plugin is abandoned or just quiet. Work the signals above together rather than relying on the date alone, and if it is still unclear, send the plugin name to Noiz support and ask for a second opinion before you remove anything important.
If you are unsure whether a plugin has become a risk, or you would like an outdated plugin replaced without downtime, open a support ticket with the Noiz support team. Include your domain, the name of the plugin in question, and what it does for your site, and mention whether you have a staging copy available.
# WordPress Cookies and Consent: Staying Privacy-Compliant
Source: https://docs.noiz.ie/wordpress/wordpress-cookies-and-consent-staying-privacy-compliant/
This guide explains what cookies and trackers your WordPress site really sets, how to find them, and how to put a consent mechanism in place that actually satisfies privacy law rather than just looking the part. It covers the plain-language basics of the three regimes most Noiz clients need to think about, the European Union's GDPR and ePrivacy rules, South Africa's POPIA, and California's CCPA/CPRA, and it explains the single most common and most expensive mistake site owners make: showing a consent banner while the tracking scripts keep running underneath it. Cookie consent is sometimes called a cookie notice, a cookie banner or a consent management platform (CMP); the advice here applies to all of them. It is written for Noiz clients who run their own WordPress site, and it deliberately describes what a consent tool must do rather than endorsing any single plugin.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress documentation and the legal texts linked below. It is general guidance, not legal advice; where compliance is business-critical, confirm your obligations with a qualified data-protection adviser.
### Official Documentation Reference
- [WordPress Privacy (WordPress Documentation)](https://wordpress.org/documentation/article/wordpress-privacy/): the built-in privacy features, including the Privacy Policy page tool and the personal-data export and erasure tools.
- [WordPress Cookies (WordPress Developer Resources)](https://developer.wordpress.org/advanced-administration/wordpress/cookies/): exactly which cookies WordPress core sets for logged-in users and for commenters, and what each one is for.
- [Regulation (EU) 2016/679 (GDPR, EUR-Lex)](https://eur-lex.europa.eu/eli/reg/2016/679/oj): the primary text of the General Data Protection Regulation, including the definition of valid consent.
- [Directive 2002/58/EC (ePrivacy Directive, EUR-Lex)](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32002L0058): the "cookie law" that actually requires prior consent before non-essential cookies are stored on a visitor's device.
- [Information Regulator (South Africa)](https://inforegulator.org.za/): the body that supervises and enforces POPIA, with guidance notes and the Act itself.
- [California Consumer Privacy Act (California Attorney General)](https://oag.ca.gov/privacy/ccpa): the official overview of consumer rights and business duties under the CCPA as amended by the CPRA.
## Prerequisites
- You can [log in to your WordPress admin dashboard](/wordpress/how-to-log-in-to-the-wordpress-dashboard/).
- A web browser with developer tools, which every modern browser has built in. You will use it to see what your own site stores on a visitor's device.
- A rough idea of who visits your site and where they are. The law that applies to you is driven by where your visitors are, not by where your server sits, so this matters more than it first appears.
## Why This Matters, and Which Laws Apply to You
The first thing to understand is that these laws follow your visitors, not your hosting. A site hosted with Noiz in South Africa or Ireland that has visitors in the European Union is squarely within the reach of EU law; a site aimed at South Africans is within POPIA wherever it is hosted. Most small sites end up needing to satisfy more than one regime at once, simply because their audience is spread across borders. The good news is that the three regimes below overlap heavily, so a single well-built consent setup usually covers all of them.
### The European Union: GDPR and the ePrivacy Directive
People talk about "GDPR consent" for cookies, but the requirement to ask before storing cookies actually comes from the older ePrivacy Directive, the so-called cookie law, which each EU country writes into its own national law. What the GDPR adds is the definition of what counts as real consent: it must be freely given, specific, informed and unambiguous, and given by a clear affirmative action. In plain terms, a pre-ticked box is not consent, "by continuing to browse you accept" is not consent, and silence is not consent. The visitor has to actively choose.
The rule that catches people out is the timing. Non-essential cookies and scripts must not run **before** the visitor has agreed. A banner that appears while your analytics and advertising scripts have already loaded and already dropped their cookies does not make you compliant; it simply documents the violation. This is not a theoretical risk. In September 2025 the French regulator issued a fine of 150 million euro against a site that placed advertising cookies the moment visitors arrived, before they had touched the banner, and pre-consent loading is among the most frequently cited findings in enforcement actions across Europe. GDPR penalties reach up to 20 million euro, or four per cent of a company's worldwide annual turnover, whichever is higher.
### South Africa: POPIA
For Noiz clients based in South Africa this is usually the most directly relevant law. The Protection of Personal Information Act took full effect on 1 July 2021 and is enforced by the Information Regulator. POPIA does not mention cookies by name, but it defines personal information very broadly, and that definition captures online identifiers such as IP addresses and the profiles that tracking cookies build. Where a cookie processes personal information and is not strictly necessary to provide the service the visitor asked for, POPIA's conditions for lawful processing apply, which in practice means telling visitors what you collect and why, and obtaining consent for non-essential tracking. Non-compliance can attract an administrative fine of up to R10 million, and certain offences carry the possibility of imprisonment, so this is not a box-ticking nicety.
### California: CCPA and CPRA
California works on a different model, and it is worth understanding the difference. Instead of asking visitors to opt in before tracking, the CCPA (as strengthened by the CPRA) gives consumers the right to opt out of the "sale" or "sharing" of their personal information, where "sharing" includes handing data to advertising networks for cross-context behavioural advertising. In practice a site that reaches Californians and meets the CCPA thresholds needs a clear "Do Not Sell or Share My Personal Information" link, and it must honour the Global Privacy Control (GPC), a signal some browsers send automatically to say the visitor has opted out. As of 2026, regulators expect the site to confirm to the visitor that an opt-out has actually taken effect. Penalties are charged per violation and mount quickly across many visitors.
Because the EU and POPIA both lean towards opt-in and California leans towards opt-out, a good consent tool lets you switch behaviour based on where the visitor is. You do not have to reconcile the regimes by hand.
## What Cookies and Trackers Actually Are
A cookie is a small file a website asks the browser to store, so the site can recognise the same browser on a later visit. Not all cookies are equal in the eyes of the law, and the whole of consent hinges on one distinction.
- **Strictly necessary cookies** are the ones a site genuinely cannot work without: keeping you logged in, remembering the contents of a shopping basket, holding a security token, balancing traffic across servers. These do not require consent, because the visitor has effectively asked for them by using the feature.
- **Non-essential cookies** are everything else: analytics that count visitors, advertising and remarketing pixels, embedded video and social widgets, personalisation, A/B testing. These do require prior consent under the EU and POPIA regimes.
A second distinction matters just as much. **First-party** cookies are set by your own domain. **Third-party** cookies and scripts are pulled in from someone else's domain, and they are where most of the risk lives, because they hand data to a company you do not control. Crucially, a "cookie" is really shorthand for any tracking technology: modern trackers also use browser storage, tracking pixels and device fingerprinting, and the law treats those the same way. A tool that only looks for classic cookies will miss half the picture.
## What WordPress Itself Sets
It helps to know that WordPress core is not the source of your compliance problem. Left to itself, a plain WordPress install sets only a small, well-behaved set of cookies, and they are functional rather than tracking.
- For **logged-in users**, WordPress sets authentication cookies (their names begin `wordpress_` and `wordpress_logged_in_`) plus a `wp-settings-` cookie that remembers admin-screen preferences. The authentication cookies are strictly necessary; nobody could log in without them.
- For **commenters**, WordPress can set three cookies (their names begin `comment_author_`) so a returning visitor does not have to retype their name, email and website. These are a convenience, not a necessity.
The comment cookies are worth a closer look, because WordPress already handles them correctly for you. Since WordPress 4.9.6 the comment form can show an opt-in checkbox, "Save my name, email, and website in this browser for the next time I comment", and the cookies are only set if the visitor ticks it and posts a comment. This is a small, built-in piece of GDPR-friendly design. Make sure it is switched on under **Settings > Discussion**, where the option is labelled **Show comments cookies opt-in checkbox**.

So if WordPress core is well-behaved, where do the tracking cookies come from? Almost always from things you or a plugin added: analytics, marketing and advertising plugins, embedded media, social buttons, chat widgets, and fonts or scripts loaded from other companies' servers. Those are what you need to find and control.
## Finding Out What Your Site Really Sets
You cannot get consent right until you know what you are asking consent for, and this is the step most people skip. Do not rely on memory or on the plugin list alone, because a single marketing or page-builder plugin can quietly load several third-party trackers. Instead, look at what actually reaches the browser.
### Inspect Your Own Site in the Browser
Open your site in a private or incognito window, so you are testing as a first-time visitor with no existing cookies, and open your browser's developer tools (F12 in most browsers). Two panels tell you almost everything:
- The **Application** (or **Storage**) panel lists **Cookies** and other local storage, grouped by the domain that set them. Anything grouped under a domain that is not yours is a third-party tracker.
- The **Network** panel shows every request the page makes as it loads. Look for requests going out to domains that are not yours, for example analytics endpoints, advertising networks, font providers, video hosts and social platforms. Each of those is a third party receiving data about your visitor, and often at least the visitor's IP address.
The revealing test is to load the page **before** interacting with any consent banner. If trackers appear in these panels the moment the page loads, they are firing before consent, which is precisely the problem this guide exists to fix.
### The Usual Hiding Places
On a typical WordPress site, non-essential trackers usually arrive through one of these routes. Knowing the list makes the audit far quicker:
- **Analytics and tag managers**, which are the most common by far and set cookies as soon as they load.
- **Advertising and remarketing pixels** from ad networks and social platforms.
- **Embedded media**: a single embedded video or map can set several third-party cookies before the visitor even presses play.
- **Social sharing and follow buttons** that load code directly from the social network.
- **Live chat, reviews and other widgets** that load from a vendor's servers.
- **Fonts and scripts loaded from another company's servers.** This one is easy to miss and has real legal history behind it: a German court ruled in 2022 that loading fonts directly from a font provider's servers, which passes the visitor's IP address to that provider without consent, breached the GDPR. Self-hosting your fonts avoids the transfer entirely and is covered later in this guide.
## The Consent Banner Trap
Here is the heart of the matter, and the point on which most WordPress sites quietly fail. Installing a plugin that displays a cookie banner is not, on its own, compliance. A great many banner setups do exactly one thing: they show a notice and record the click. Meanwhile the analytics, advertising and embed scripts have already loaded with the page and already set their cookies, regardless of what the visitor clicks. The banner becomes a piece of theatre that, if anything, proves you knew tracking was happening and let it run anyway.
Real consent has to change what the site does. Under the EU and POPIA regimes, "prior consent" means the non-essential scripts must be held back and only allowed to run **after** the visitor agrees. That single requirement, blocking before consent, is what separates a compliant setup from a decorative one, and it is the requirement most site owners do not realise they are missing.
## Blocking Third-Party Scripts Before Consent
A consent mechanism that does the job properly works roughly like this, and it is worth understanding the shape of it even though a plugin will handle the mechanics.
- **It categorises trackers.** Cookies and scripts are grouped, typically into necessary, analytics/statistics, and marketing/advertising, so visitors can accept some categories and refuse others rather than facing an all-or-nothing choice.
- **It blocks the non-essential categories by default.** Until the visitor consents, scripts in those categories are prevented from loading and setting cookies. This is the part cheap banners skip.
- **It offers a genuine choice.** Accepting and rejecting must be equally easy. A prominent "Accept all" beside a buried or missing "Reject" is itself a compliance failure, and regulators have said so repeatedly.
- **It records and stores the consent.** You need to be able to show, later, what a visitor agreed to and when. Keeping that record on your own server rather than a third party's is the more privacy-respecting approach, and one worth preferring.
- **It lets visitors change their mind.** Withdrawing consent must be as easy as giving it, so the banner or a persistent link needs to reopen the preferences at any time.
- **It can adapt to the visitor's region.** The same tool can present an opt-in experience to EU and South African visitors and an opt-out "Do Not Sell or Share" experience to Californians, and honour the Global Privacy Control signal where required.
WordPress core does not include any of this: it has no built-in consent banner and no built-in script blocker, which is why this specific job needs a plugin. The category of plugin you want is usually described as a **consent management platform** or a **cookie consent** plugin. Several capable options exist, free and paid, so choose on the criteria below rather than on brand, and prefer one that stores consent records on your own site.
### What to Look For in a Consent Plugin
- It **actually blocks** non-essential scripts before consent, rather than only displaying a notice. This is non-negotiable and is the first thing to verify, ideally by re-running the browser test above after you set it up.
- It can **scan your site** to discover the cookies and trackers you found in the audit, and keep that list current as you add plugins.
- It supports **granular categories** and an equally easy accept and reject.
- It **logs consent** in a way you can retrieve, and ideally stores that log on your own server.
- It can **differentiate by region** if your audience spans the opt-in and opt-out regimes.
- It is **actively maintained**, tested against current WordPress, and does not itself load from a third party in a way that reintroduces the very problem you are solving.
## WordPress's Built-in Privacy Tools (No Plugin Needed)
Consent is only part of privacy compliance. WordPress core also gives you several genuinely useful privacy tools that need no plugin at all, and they are easy to overlook. They do not, by themselves, make you compliant, but they cover duties that these laws impose alongside cookie consent.
### The Privacy Policy Page
Under **Settings > Privacy**, WordPress helps you create or nominate a privacy policy page and provides an editing helper that assembles starter text from WordPress core and from any installed plugins that supply it. Treat the generated text strictly as a starting point: it is drafted around GDPR expectations, it cannot know about third-party services you have added, and the wording and completeness of the final policy are your responsibility. A privacy policy is expected under all three regimes, and it should honestly describe the cookies and trackers you found in your audit.

### Handling Data Requests: Export and Erase
Both the GDPR and POPIA give people the right to see the personal data you hold about them and to ask for it to be deleted. WordPress builds in tools for exactly this, under **Tools > Export Personal Data** and **Tools > Erase Personal Data**. Each works from a verified email request: the visitor's request is confirmed by email, you approve it, and WordPress then either compiles a downloadable file of the data it holds or removes it. Two limits are important to understand. First, these tools only reach data held inside WordPress and participating plugins, so anything held in a third-party service you use will need handling separately. Second, an erasure is permanent and is not undone in your backups, so restoring an old backup could bring deleted data back; honour any outstanding erasure again if you restore.

## Reducing What You Have to Consent For
The least risky tracker is the one you never load. Before you spend effort perfecting a consent banner, it is worth shrinking the problem, and often you can remove trackers entirely without losing anything visitors value.
- **Self-host your fonts.** Instead of loading fonts from an external provider, which passes visitor IP addresses to that provider, serve the font files from your own site. This removes a genuine legal exposure (the German court ruling above) and usually loads faster too. Many themes and a small plugin can localise fonts for you.
- **Reconsider analytics.** If you only need visitor numbers, privacy-respecting, cookieless analytics options exist that avoid the whole consent question for that purpose. If you keep a full analytics suite, it must sit behind consent.
- **Load embeds only on request.** Replace auto-loading video, map and social embeds with a placeholder that only loads the third-party content, and its cookies, once the visitor clicks. This keeps those trackers from firing before consent and speeds up the page.
- **Remove what you do not use.** Marketing pixels left over from a campaign, an analytics tag you forgot, a social widget nobody clicks: each is a tracker you are liable for and gain nothing from. Delete the plugins and tags you no longer need.
Every tracker you remove is one fewer thing to disclose, one fewer thing to block before consent, and one fewer thing that can leak data. This trimming sits alongside the wider measures in the [Noiz WordPress Security Checklist](/wordpress/wordpress-security-checklist/).
## A Practical Compliance Checklist
Pulling the guide together, a reasonable order of work looks like this:
1. **Audit.** Use the incognito-plus-developer-tools method to list every cookie and third-party request your site makes on load.
2. **Reduce.** Remove trackers you do not need, self-host fonts, and switch embeds to click-to-load.
3. **Classify.** Sort what remains into strictly necessary and non-essential.
4. **Block before consent.** Put a consent tool in place that actually holds back the non-essential scripts until the visitor agrees, then re-run the audit to prove it works.
5. **Offer a real choice.** Make accepting and rejecting equally easy, allow per-category choices, and let visitors change their mind.
6. **Record consent**, preferably on your own server.
7. **Publish an honest privacy policy** using the built-in tool, describing the trackers you actually run.
8. **Be ready for data requests** using the built-in export and erase tools, and know where your third-party data lives.
9. **Adapt by region** if your audience spans opt-in and opt-out regimes, and honour Global Privacy Control where it applies.
10. **Re-check periodically**, because every new plugin can add a tracker.
## Troubleshooting
- **Symptom**: your consent banner appears, but trackers still show up in developer tools before you click anything. The banner is display-only and is not blocking scripts. This is the core compliance failure. Move to a consent tool that blocks non-essential scripts by default, or enable its script-blocking feature, and re-test in an incognito window.
- **Symptom**: analytics stopped recording visitors after you added consent. That is expected, because the script now waits for consent; it will record visitors who accept. If numbers dropped sharply, that gap reflects how many visitors were previously tracked without consent.
- **Symptom**: you cannot see any cookies in developer tools but you know you use analytics. You may be testing with an ad-blocker or privacy browser active, or your session already granted consent. Test in a clean incognito window with extensions disabled.
- **Symptom**: an embedded video or map disappeared after you enabled blocking. The embed is being held back until consent, which is correct. Add a click-to-load placeholder so visitors can choose to load it, or ensure that embed's category is offered in the banner.
- **Symptom**: the comment form saves visitor details without asking. Turn on **Show comments cookies opt-in checkbox** under **Settings > Discussion** so those convenience cookies are only set when the visitor ticks the box.
If you are not sure what your site is loading, or you would like help auditing your cookies, self-hosting fonts, or setting up a consent tool that genuinely blocks trackers before consent, open a support ticket with the Noiz support team. Include your domain and a note of the main plugins and third-party services you use, and mention which countries most of your visitors come from so the advice fits the law that applies to you.
# WordPress Security Checklist
Source: https://docs.noiz.ie/wordpress/wordpress-security-checklist/
WordPress powers a large share of the web, which makes it a constant target for automated attacks. The checklist below covers the hardening measures that matter most for a WordPress site running on Noiz hosting: locking down files, tightening the WordPress configuration, blocking dangerous requests, and protecting the login. Work through it whether you are securing a brand new install or auditing an existing site.
**Last reviewed:** 27 July 2026, against WordPress **7.0.2** (latest stable). This guide is written for Noiz hosting and is kept current against WordPress. It complements, and does not replace, the official WordPress hardening documentation linked below.
### Official Documentation Reference
- [Hardening WordPress](https://wordpress.org/documentation/article/hardening-wordpress/): the canonical security guide from the WordPress project.
- [Brute Force Attacks](https://wordpress.org/documentation/article/brute-force-attacks/): protecting the login and XML-RPC.
- [FAQ: My Site Was Hacked](https://wordpress.org/documentation/article/faq-my-site-was-hacked/): what to do if a site is already compromised.
## Prerequisites
- Administrator access to the WordPress dashboard.
- Access to your site files, either through the File Manager in your Noiz control panel, SFTP, or SSH.
- A recent, verified backup. Several measures below (changing the table prefix, altering permissions, editing server config) can break a live site if applied carelessly, so always back up before you start.
Many of these measures can be applied automatically by the WordPress management tools built into your Noiz hosting control panel, and the rest can be applied by hand as described. If any step is unfamiliar, contact Noiz support before making the change on a production site.
## File and Directory Security
**Restrict file and directory permissions**
Overly permissive files can be read or altered by other processes on the server or by an attacker who gains a foothold. Set `wp-config.php` to `600`, other files to `644`, and directories to `755`. Never set anything to `777`.
**Disable directory browsing**
If directory listing is enabled, a visitor can open a folder that has no index file and see everything inside it, which reveals plugin names, versions, and file layout that attackers use to fingerprint your site. Directory browsing is off by default on most Noiz servers, but confirm it and disable it in your server configuration if needed. On Apache this is handled with an `Options -Indexes` directive in `.htaccess`. Note that custom directives already present in `.htaccess` can override this.
**Forbid PHP execution in wp-includes**
The `wp-includes` directory is not meant to serve PHP directly to visitors. Blocking PHP execution there stops an attacker who manages to drop a malicious file into it from running that file. This is applied through the server configuration (an `.htaccess` or nginx rule).
**Forbid PHP execution in wp-content/uploads**
The uploads directory holds media, not code. Preventing PHP execution there closes one of the most common ways a malicious upload becomes remote code execution. A simple `.htaccess` file inside `wp-content/uploads` does the job on Apache:
```
Require all denied
```
**Protect wp-config.php**
The `wp-config.php` file contains your database credentials and secret keys. If PHP processing is ever disabled on the server, its raw contents could be served as plain text. Block direct web access to it in your server configuration. On Apache:
```
Require all denied
```
**Disable PHP execution in cache directories**
If a compromised PHP file lands in a caching plugin's cache directory and can be executed, the whole site is at risk. Block PHP execution in cache directories. Be aware that a small number of poorly behaved plugins or themes store genuine PHP in their cache directory against WordPress guidance; if such a plugin stops working, you may need to relax this for that path only.
## WordPress Configuration Hardening
**Set strong security keys and salts**
WordPress uses a set of secret keys and salts (`AUTH_KEY`, `SECURE_AUTH_KEY`, `LOGGED_IN_KEY`, `NONCE_KEY` and their salt counterparts) to encrypt the information stored in login cookies. These should be long (60 characters or more), random, and unique to your site. Generate a fresh set from the official [WordPress salt generator](https://api.wordpress.org/secret-key/1.1/salt/) and paste them into `wp-config.php`. Rotating the keys immediately invalidates every existing login session, which is a useful first step if you suspect a session has been stolen.
**Disable the built-in file editor**
The dashboard's Theme and Plugin editors let anyone with administrator access edit live PHP straight from the browser. If an admin account is ever compromised, that is an instant path to injecting malicious code. Turn the editor off by adding this to `wp-config.php`:
```
define('DISALLOW_FILE_EDIT', true);
```
**Disable admin script concatenation**
WordPress bundles admin scripts together for speed, but the endpoint that does this has been abused in denial-of-service attacks. Disabling concatenation removes that vector. The trade-off is a small performance cost in the admin area only; visitors are unaffected. Add to `wp-config.php`:
```
define('CONCATENATE_SCRIPTS', false);
```
**Change the default database table prefix**
By default every WordPress install names its tables with the `wp_` prefix, which makes the database structure predictable and simplifies automated SQL injection. Using a different prefix removes that assumption. Changing the prefix on a site that already holds data is risky, so back up first and prefer setting a custom prefix at install time.
**Turn off pingbacks and XML-RPC abuse**
Pingbacks let other sites leave automatic comments when they link to your posts, but the same XML-RPC feature is routinely abused to launch distributed denial-of-service and brute-force attacks through your site. Disable XML-RPC pingbacks site-wide and turn off pingbacks on existing posts unless you have a specific reason to keep them.
**Disable unused scripting languages**
WordPress runs on PHP. Support for other scripting languages such as Perl or Python is not needed by the application, so switching it off in the server configuration removes an unnecessary attack surface.
## Access Control and Request Filtering
**Block access to sensitive files**
Certain files can expose connection credentials or reveal which known exploits apply to your site. Deny public access to configuration files, backups, and similar sensitive resources at the server level.
**Block access to potentially sensitive files**
Log files, shell scripts, and other executables sometimes end up in a site's directories. Denying public access to these file types prevents them from being read or run by an attacker.
**Block access to .htaccess and .htpasswd**
These files control server behaviour and can hold password hashes. If an attacker can read them, they gain a range of exploitation options. Web servers usually deny access to dot-files by default; confirm this is enforced on your site.
**Enable bot and brute-force protection**
Malicious bots scan sites for vulnerabilities and flood them with requests, driving up resource use. A bot protection or web application firewall layer blocks these before they reach WordPress. If you plan to run a legitimate security scanner against your own site, you may need to temporarily allow it, since scanners behave like bots.
## Login and Account Security
**Block author enumeration scans**
Attackers probe the `?author=` query and the REST API to discover valid usernames, then brute-force the passwords. Blocking author enumeration hides those usernames. Depending on your permalink setup, this can also affect author archive pages, so test that legitimate author listings still work.
**Avoid the default admin username**
A fresh install often creates an administrator called `admin`, which is the first username every brute-force tool tries. Create a new administrator account with a unique, non-obvious username, reassign any content owned by `admin` to it, and delete the `admin` account. Combine this with a strong, unique password and, ideally, two-factor authentication.
## Getting Help
Worked through methodically, this checklist closes off the great majority of automated WordPress attacks. Most of it is straightforward for a competent WordPress developer to apply and maintain as part of a routine maintenance plan.
If you are concerned about your site's security and do not have the time or the technical knowledge to attend to the above, reach out to Noiz support about moving your site onto a [Managed WordPress](https://www.noiz.co.za/wordpress.php) plan, where this hardening and ongoing maintenance is handled for you.
# How to Access Softaculous in DirectAdmin
Source: https://docs.noiz.ie/softaculous/how-to-access-softaculous-in-directadmin/
Softaculous is the one-click application installer that puts WordPress, Joomla, Drupal, PrestaShop, Moodle and several hundred other applications onto your hosting without any manual setup. On Noiz shared hosting it is already installed at server level, so there is nothing for you to enable. The only question is where DirectAdmin puts it, and that is the part people get stuck on, because DirectAdmin's Evolution interface does not always show it in the same place.
This guide covers what you actually see on a Noiz DirectAdmin account: where the entry sits in the Evolution menu, the fastest way to find it when it is not on screen, the two domain selectors that decide where your application ends up, and what it means when Softaculous is missing altogether. It does not repeat the DirectAdmin or Softaculous manuals, which are linked below for the detail.
**Last reviewed:** 27 July 2026, against the current DirectAdmin release and its Evolution interface, and the current Softaculous release. This guide is written for Noiz hosting and is kept current against DirectAdmin and Softaculous. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [DirectAdmin Docs: the Evolution skin](https://docs.directadmin.com/directadmin/skins-and-templates/evolution.html)
- [DirectAdmin Docs: general usage and access levels](https://docs.directadmin.com/directadmin/general-usage/)
- [Softaculous Docs: the end user guide](https://www.softaculous.com/docs/enduser)
- [Softaculous Docs: installing a script](https://www.softaculous.com/docs/enduser/install-a-script)
- [The full Softaculous application library](https://www.softaculous.com/apps/)
## Prerequisites
- An active Noiz shared hosting account on the DirectAdmin platform.
- Your DirectAdmin login URL, username and password, all of which are in your Noiz welcome email and available again from your Noiz client area.
- At least one domain already added to the account. Softaculous can only install onto a domain, subdomain or alias that DirectAdmin already knows about.
## First, Confirm Which Panel Your Account Uses
Noiz runs two shared hosting platforms and they use different control panels. DirectAdmin runs on the Ireland platform; Plesk runs on the South African platform. Softaculous is present on both, but the route to it is completely different, so it is worth thirty seconds of certainty before you start hunting for a menu entry that was never going to be there.
Your welcome email names the panel and gives you the login URL for it. If you no longer have it, log in to the Noiz client area, open the hosting service, and the control panel login is shown against the service. If the panel you land on has a dark left-hand sidebar with sections such as **Account Manager**, **E-mail Manager** and **Extra Features**, you are on DirectAdmin and this article applies. If you land on Plesk instead, use **Applications** in the left-hand menu and see [What Is Softaculous?](/softaculous/what-is-softaculous/) for the platform overview.
## Open Softaculous in DirectAdmin
### Step 1: Log in and check your access level
Log in to DirectAdmin with the URL and credentials from your welcome email.
This is the single most common reason Softaculous appears to be missing, and it catches resellers and anyone whose account was created with more than one role. DirectAdmin has three access levels: **Admin**, **Reseller** and **User**. Softaculous is a user-level tool, so it is only on the menu at User level. If your account has more than one level, DirectAdmin may drop you at the highest one, and the menu you are looking at simply does not contain it.
Look at the top right of the page. If there is a level switcher showing **Admin** or **Reseller**, change it to **User** and the menu rebuilds. Accounts with a single role have no switcher at all, which is the normal case for a standard Noiz shared hosting account, and you can move straight on.
### Step 2: Look in Extra Features
Softaculous is a plugin rather than a built-in DirectAdmin feature, and Evolution groups plugins together. In the left-hand sidebar, open **Extra Features** and look for **Softaculous Apps Installer**.
The label is not fixed. Depending on the Softaculous release and how the plugin has been presented, the same tool can appear as any of the following, and all of them open Softaculous:
- **Softaculous Apps Installer**
- **Softaculous Auto Installer**, or simply **Softaculous**
- A short list of individual applications, such as **WordPress**, **Joomla** and **PrestaShop**, each with its own entry. Clicking any one of them opens Softaculous with that application already selected, which saves a step if it is the one you wanted.
Evolution also remembers a collapsed sidebar between visits, and a section you collapsed weeks ago stays collapsed. If **Extra Features** looks like a heading with nothing under it, click the heading itself to expand it.
### Step 3: Use the navigation filter when it is not obvious
Scrolling the sidebar is the slow way to do this, and it fails whenever the entry has been renamed or moved. The filter box at the top of the Evolution sidebar is the reliable route. Click into it and start typing; the menu narrows as you type and you click the result.
Two things about the filter are worth knowing, because they turn a "it is not there" into a result:
- **Type a fragment, not the whole word.** Try `soft` first. If nothing comes back, try `install`. The filter matches the label that is actually on the menu, so if the plugin is presented as **Apps Installer** without the Softaculous name in front of it, searching for the full product name returns nothing while `install` finds it immediately.
- **An empty result is meaningful.** The filter searches the whole menu for your current access level, not just the visible part of it. If both `soft` and `install` return nothing, the tool genuinely is not on your menu, and Step 1 or the troubleshooting section below is where to look next.
### Step 4: Confirm Softaculous has actually loaded
Softaculous opens inside the DirectAdmin page rather than in a new tab or a separate window. You know you are in the right place when the DirectAdmin sidebar is still down the left, and the main area has changed to a second, narrower column of application categories such as **Blogs**, **Portals/CMS** and **E-Commerce**, with a row of the most popular applications across the top.
A short delay on the first load of the day is normal, because Softaculous checks in with its update service and refreshes the application list. A blank white panel that never resolves is not normal, and the troubleshooting section covers it.
To leave Softaculous, use the DirectAdmin sidebar rather than the browser back button. Because the interface is loaded inside the panel, going back can land you part way through a form you had already submitted.
## The Two Domain Selectors, and Which One Decides
This is the part that quietly goes wrong, and it is worth understanding before you install anything, because putting an application on the wrong domain means uninstalling and starting again.
There are two separate selectors in play, and they are not the same control:
- **The DirectAdmin domain selector.** Evolution shows the currently selected domain near the top of the page, and it applies across the whole panel. Every domain-scoped tool you open, including Softaculous, inherits it. Change it here and DirectAdmin remembers the choice for the rest of the session.
- **The Softaculous *Choose Domain* field.** This sits on the install form itself, alongside **Choose Protocol**. It is pre-filled from whatever DirectAdmin had selected, and it is the one that actually determines where the files and database go.
The practical rule is short: the DirectAdmin selector sets the default, the Softaculous field makes the decision. Read the **Choose Domain** value on the install form every single time, immediately before you click **Install**. If you have one domain on the account the two can never disagree. If you have several, they disagree the moment you open Softaculous from a bookmark or come back to a tab you left open earlier.
Two related points on that same form:
- **The list only contains names DirectAdmin already has.** Domains, subdomains, aliases and pointers appear in **Choose Domain** only once they exist in DirectAdmin. If the target is missing, add it first and reload Softaculous. For a subdomain, see [How to Add a Subdomain in DirectAdmin](/directadmin/how-to-add-a-subdomain-in-directadmin/).
- **Clear the *In Directory* field to install at the top level.** Softaculous pre-fills it with a folder name such as `wp`, which would put the site at `yourdomain.com/wp` rather than `yourdomain.com`. Replace `yourdomain.com` with your own domain throughout. Empty the field unless you genuinely want the application in a subfolder.
## Shared Hosting Versus a Self-Managed VPS
Softaculous is licensed per server, and that licence is what decides whether the tool exists at all. The distinction matters when you are comparing Noiz products:
- **Noiz shared hosting.** Softaculous is installed and licensed on the servers, and the cost is part of the hosting. Nothing to buy, nothing to install, and it is available to every account on the server.
- **A self-managed VPS.** The server is yours, and so is the software on it. Softaculous is not included, and a DirectAdmin licence does not cover it. If you want it on a VPS you buy a Softaculous licence for that server and install it yourself, against your own control panel. Pricing and licence types are on the [Softaculous pricing page](https://www.softaculous.com/pricing/), and the vendor's [DirectAdmin installation guide](https://www.softaculous.com/docs/admin/installing-softaculous-in-directadmin) covers the server-side work.
If you are on a VPS and you would rather not run the installer yourself, ask Noiz support about a managed plan before you buy anything, so the licence is sized correctly for what you actually need.
## Troubleshooting
**Symptom**: the filter finds nothing for `soft` or `install`. Check your access level first, as described in Step 1, because a Reseller or Admin menu will never list it. If you are definitely at User level and it is still absent, the account is on a server without the plugin, or on a VPS without a licence. Open a ticket with Noiz support quoting your domain name and the support team will confirm what your service includes.
**Symptom**: the Softaculous panel loads blank, or spins indefinitely. Almost always a browser extension interfering with content loaded inside the panel. Try a private window with extensions disabled, then a different browser, before reporting it. An ad blocker or a script blocker is the usual culprit.
**Symptom**: a licence warning appears in place of the application list. This is a server-level condition and there is nothing you can fix from inside your account. Report it to Noiz support and quote the exact wording of the message.
**Symptom**: the domain you want is not in the **Choose Domain** list. It has not been added to DirectAdmin yet, or it was added after Softaculous was opened. Add the domain or subdomain, then reload the Softaculous page so the list is rebuilt.
**Symptom**: the installer refuses to continue because the target directory is not empty. Softaculous will not write over existing files, which is protecting you rather than obstructing you. Choose a different directory, or clear the existing contents in **File Manager** first, taking a backup before you delete anything.
**Symptom**: the application installs but shows a PHP error, or refuses to install on version grounds. The account is running a PHP branch the application does not support. Change it and try again: see [How to Change the PHP Version via CloudLinux Selector in DirectAdmin](/directadmin/how-to-change-the-php-version-via-cloudlinux-selector-in-directadmin/).
**Symptom**: an install fails partway and leaves files behind. Open the Softaculous **Installations** list, remove the broken entry so that the files, the database and the database user are all cleaned up together, then install again. Installing a second copy on top of the wreckage is what turns a small problem into a support ticket.
## If the Server Also Offers Another Installer
Some DirectAdmin servers carry a second auto-installer alongside Softaculous. Both will install the same applications, and neither one recognises or manages sites created by the other. Pick one installer for a given site and stay with it, otherwise upgrades and backups end up split between two tools that each believe they are in charge.
## Related Guides
- [What Is Softaculous?](/softaculous/what-is-softaculous/)
- [How to Install WordPress with Softaculous](/softaculous/how-to-install-wordpress-with-softaculous/)
- [How to Access Softaculous in cPanel](/softaculous/how-to-access-softaculous-in-cpanel/)
- [How to Add a Subdomain in DirectAdmin](/directadmin/how-to-add-a-subdomain-in-directadmin/)
## Need a Hand?
If Softaculous is not on your DirectAdmin menu and the checks above have not explained why, open a ticket from your Noiz client area with your domain name and a note of which access level you are logged in at. If you would rather an application was installed and configured for you on the right domain first time, say so in the ticket and Noiz support will set it up on your behalf.
# How to Access Softaculous in ISPConfig
Source: https://docs.noiz.ie/softaculous/how-to-access-softaculous-in-ispconfig/
Softaculous is the one-click application installer that puts WordPress, Joomla, Drupal, Nextcloud, Moodle and several hundred other web applications onto your hosting account without any manual file uploading or database work. Noiz offers it across the control panels Noiz runs, ISPConfig included, although whether it is present is settled per server rather than per plan. This guide is for Noiz clients on an ISPConfig plan who have read about Softaculous, or seen it in a cPanel or Plesk screenshot, and want to know where it actually lives on their own account. The short version: where it is present it does not look or behave quite like the cPanel and Plesk versions, and this article explains the differences before you go hunting for an icon that is not shaped the way you expect.
**Last reviewed:** 27 July 2026, against the current Softaculous release and ISPConfig **3.3.1p1** (the version Noiz runs). This guide is written for Noiz hosting and is kept current against Softaculous and ISPConfig. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [Softaculous: Installing Softaculous in ISPConfig](https://www.softaculous.com/docs/admin/installing-softaculous-in-ispconfig): the vendor's own page for the ISPConfig integration. It is written for the server administrator rather than for you, but it is the authoritative statement that the integration exists and how it is put together.
- [Softaculous documentation home](https://www.softaculous.com/docs/): the full documentation index, including the end user section covering installing, upgrading, backing up and cloning.
- [The Softaculous application library](https://www.softaculous.com/apps/): the authoritative list of what can be installed.
- [ISPConfig documentation overview](https://www.ispconfig.org/documentation/): the official ISPConfig documentation index.
## Prerequisites
- An active Noiz hosting plan on ISPConfig, and your panel login. If you have not signed in to the panel before, start with [How to Log In to the ISPConfig Control Panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/).
- A website already created on your account for the application to be installed into. If you do not have one yet, see [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/).
- The welcome email that was sent when your hosting was set up. It carries the addresses for your account, and one of the routes below uses an address from it.
- Nothing to install or enable yourself. Softaculous is a server-side component, so it is either present for every account on a server or for none of them. There is no switch for it in your own panel.
## Why Softaculous Looks Different on ISPConfig
This is the part worth reading before you start clicking, because it explains most of the confusion clients report.
On cPanel and on Plesk, Softaculous is a native panel plugin. It gets its own tile in the panel's home screen (the **Software** section in cPanel, **Applications** in Plesk), and it draws itself inside the panel's own frame, so it feels like a built-in feature of the control panel.
ISPConfig is put together differently. Softaculous ships its ISPConfig support as a separate component rather than as a tile bolted into the panel's site management screens. The practical consequences for you:
- **It is a panel of its own, not a section of ISPConfig.** Once it opens, you are looking at the Softaculous end user interface, which is the same interface a cPanel user sees. Everything you read in the Softaculous documentation about installing, upgrading, backing up and cloning applies unchanged from that point on.
- **There is a direct address as well as a route through the panel.** Softaculous serves its own end user panel on the server at a dedicated address with a `/softaculous` path. That address is specific to the server your account is on, so it is not something this article can print; it comes from your welcome email or from Noiz support. Bookmark it once you have it, because it is the route that does not depend on where an icon happens to sit in a given panel version.
- **The vendor documents the entry point in a picture rather than in words.** Softaculous's own ISPConfig page says only that the panel is reachable "after logging into the ISPConfig panel", then shows a screenshot in which the Softaculous link sits under the **Tools** module, in the **Auto Installer** group of the left-hand menu. That screenshot is the vendor's illustration of its own integration, not a picture of a Noiz server, so treat it as where the integration places itself rather than as a guarantee of the exact wording on your panel. Where what you see does not match, use the direct address below or ask Noiz support, rather than guessing.
- **Availability is decided per server, not per plan feature.** Softaculous states that its ISPConfig integration does not cover multi-server ISPConfig setups. That is one of several reasons Softaculous availability is a property of the machine your account lives on rather than a tick box on your account.
## Reach Softaculous from Your ISPConfig Account
Try these in order. The first is the one to reach for day to day; the second is the reliable fallback and the one to bookmark.
### Route 1: From Inside the ISPConfig Panel
1. Sign in to your ISPConfig control panel with your panel username and password.
2. Look across the top-level module tabs for **Tools**, then down the left-hand menu inside it for an **Auto Installer** group holding a **Softaculous** entry. That is where the screenshot in Softaculous's own ISPConfig documentation places it. A stock ISPConfig puts nothing under **Tools** but **User Settings**, so an **Auto Installer** group there is something the Softaculous integration has added, and a **Tools** tab carrying only **User Settings** is a fair sign the integration is not reaching your login. Softaculous is a destination in its own right rather than an option inside an individual website's settings, so if the labels on your panel do not match, scan the remaining top-level tabs for **Softaculous** rather than opening a website and looking inside it.
3. Click it. Softaculous opens on its front page, with application categories down the left side and the most popular installers in the main area.
**If nothing matching that description is there, stop looking rather than hunting through the Sites module for something installer-shaped.** The next section explains why older ISPConfig guides send you there and why that advice no longer applies. Use Route 2 instead, or ask Noiz support to send you the exact entry point for your server. Two things can hide the entry point without anything being wrong: the permissions on your panel user, and the version and theme of the panel itself. A support agent looking at your actual account can settle it in one line.
### Route 2: The Direct Softaculous Address
Softaculous publishes its end user panel at a server address ending in `/softaculous`, independent of the ISPConfig panel's navigation. This route works even when you cannot find the entry point in the panel, and it does not depend on your own domain resolving, which makes it the dependable option for a domain that has only just been pointed at Noiz.
The exact address for your account is server specific. It is in your hosting welcome email, and if you no longer have that email, Noiz support will send it to you. Once it loads, bookmark it.
## The Gotcha: The APS Installer Is Switched Off, and Older Guides Still Send You to It
A great deal of the ISPConfig material on the web, the ISPConfig 3.1 manual included, tells you that ISPConfig carries a built-in one-click installer of its own called the **APS Installer**, sitting in the **Sites** module as a menu group of its own holding **Available packages**, **Installed packages** and **Update Packagelist**. Go looking for it on a Noiz ISPConfig plan and you will not find it. Nothing is broken and nothing is missing from your plan.
ISPConfig retired APS in version 3.2, saying in [its own release announcement](https://www.ispconfig.org/blog/ispconfig-3-2-released/) that the APS project was dead. The accurate position on 3.3.1p1, which is what Noiz runs, is worth stating precisely, because it is not quite deletion: the APS screens are still present in the panel, but the menu group is hidden unless a server administrator deliberately switches it on, and the note ISPConfig prints beside that switch says APS will be removed from the panel in the near future. A second gate sits behind the first, a per-client limit on the number of APS instances an account may hold, so even on a server with the menu turned on an individual account can be left without it. The outcome on your account is the same either way: Softaculous is the application installer, and there is no second installer to mistake it for.
Two consequences worth knowing:
- **Instructions written for ISPConfig 3.1 or earlier will not match your panel**, and that reaches wider than the installer. If a guide has you clicking something in the Sites module that plainly is not there, check the date on the guide before concluding that your panel is misconfigured.
- **If an application was installed on your account before this, or carried across from an older server, Softaculous will not be tracking it.** The files and the site keep working, but no installer holds a record of them, so Softaculous will not upgrade, back up or clone them. You can adopt an existing installation into Softaculous's records with its [import function](https://www.softaculous.com/docs/enduser/how-to-import-an-installation/).
**The rule to follow:** install through Softaculous, and remove an installation through Softaculous rather than by deleting files. Deleting the files by hand leaves the Softaculous record behind, along with the database and the database user. Softaculous is what carries the large application library and the ongoing upgrade, backup and clone tooling described in [What Is Softaculous](/softaculous/what-is-softaculous/).
## How to Tell It Worked
You are in the right place when all three of these are true:
- The page is branded **Softaculous** and shows a search box with categories such as Blogs, Portals, Forums and E-Commerce down one side.
- There is an **Installations** view (often a box or cart icon in the toolbar) that lists what is already installed on your account. On a fresh account it is empty, and an empty list is a correct result, not a fault.
- Opening any application, WordPress for example, gives you an **Install** button and a form whose domain dropdown lists *your* domains. If the dropdown is empty, Softaculous is running but it cannot see a website on your account yet, which means the website itself has not been created.
From here the process is identical to every other panel, so there is nothing ISPConfig-specific left to learn. Follow [How to Install WordPress with Softaculous](/softaculous/how-to-install-wordpress-with-softaculous/) for a full walkthrough of the install form. Two fields deserve your attention whichever application you choose: leave **In Directory** *empty* to install at the top level of your domain (Softaculous pre-fills something like `wp`, which would put the site at `yourdomain.com/wp` instead, replacing `yourdomain.com` with your own domain), and set an administrator username that is not `admin` with a long, unique password. That login is exposed to the internet the moment the install finishes.
Select `https://` as the protocol only if the domain already has a working certificate. If it does not, see [How to Secure a Website with a Free SSL Certificate in ISPConfig](/ispconfig/how-to-secure-a-website-with-a-free-ssl-certificate-in-ispconfig/) first, because changing an application's address after installation is more work than getting it right at install time.
## A Note on Logins
ISPConfig accounts commonly carry three separate sets of credentials, and mixing them up accounts for a good share of failed logins:
- Your **ISPConfig control panel** username and password, which is what Route 1 uses.
- Your **Noiz client area** (billing) login, which is a different account entirely and is never used to reach a hosting tool.
- A **mailbox** address and password, used only for email. The same trap is covered in detail in [How to Access Your Webmail in ISPConfig](/ispconfig/how-to-access-your-webmail-in-ispconfig/), and it is worth reading if you have hit it once, because the pattern repeats across every tool on the account.
If the direct Softaculous address asks you for credentials and your panel details are rejected, do not keep retrying and risk a temporary block. Contact Noiz support and ask which login that address expects for your account.
## Troubleshooting
**Symptom**: you have signed in to ISPConfig and there is no Softaculous entry anywhere in the navigation. Do not assume it is missing from the server. Use the direct address from your welcome email first, since the panel entry point and the direct panel are two routes to the same software and the second can work when the first is not visible to your user level. If the direct address also fails, contact Noiz support to confirm what is available on your server.
**Symptom**: the Softaculous page loads blank, or spins indefinitely. This is nearly always a browser extension or ad blocker interfering, not a server fault. Try a private or incognito window, then a different browser, before opening a ticket.
**Symptom**: a "404 Not Found" at the `/softaculous` address. Check the address character for character against the one in your welcome email, including the port number if there is one, before reporting it. If it is correct and still returns 404, that is a server-side condition worth a ticket.
**Symptom**: Softaculous opens but the domain dropdown on the install form is empty or does not list the domain you expect. Softaculous can only install onto a website that exists on your account. Create the website first, then return to Softaculous; the new domain appears without any further action.
**Symptom**: the installer refuses to continue because the target directory is not empty. Softaculous will not write over existing files, which is protective rather than obstructive. Choose a directory that does not exist yet, or clear the existing contents first, taking a backup before you delete anything.
**Symptom**: an install fails partway and leaves files behind. Do not install a second copy on top of it. Open the Softaculous **Installations** list, remove the broken entry so the files, the database and the database user are all cleared together, then run the install again. If you would rather tidy up the database side yourself, see [How to Create a Database and Database User in ISPConfig](/ispconfig/how-to-create-a-database-and-database-user-in-ispconfig/) for where those objects live.
**Symptom**: an application you installed is not listed in Softaculous at all. Check whether it was uploaded by hand, installed over SSH, or brought across from a previous host or an older server. Softaculous only tracks what it installed itself, so use its import function to adopt the existing installation into its records.
## Related Guides
- [What Is Softaculous](/softaculous/what-is-softaculous/)
- [How to Access Softaculous in cPanel](/softaculous/how-to-access-softaculous-in-cpanel/)
- [How to Install WordPress with Softaculous](/softaculous/how-to-install-wordpress-with-softaculous/)
- [How to Log In to the ISPConfig Control Panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/)
- [How to Create a Website in ISPConfig](/ispconfig/how-to-create-a-website-in-ispconfig/)
If you cannot find Softaculous on your ISPConfig account after trying both routes, open a ticket from your Noiz client area. Quote your domain and say that you are on an ISPConfig plan, and the support team will send you the exact entry point for your server. On Noiz managed plans the team can also install and configure an application on your behalf, so if you would rather hand the whole job over than work through an install form, just say which application you want and which domain it belongs on.
# How to Access Softaculous in Plesk
Source: https://docs.noiz.ie/softaculous/how-to-access-softaculous-in-plesk/
Softaculous is the one-click application installer that Noiz runs on its shared Plesk servers. It builds WordPress, Joomla, Nextcloud, PrestaShop and hundreds of other applications for you, creating the files, the database and the configuration in a single pass. Finding it is where Plesk differs from other control panels. Plesk has no fixed **Software** section the way cPanel does, so depending on how your subscription is displayed, Softaculous can appear as an entry in the left-hand menu, as a control on a domain's card, or as both. This guide shows you every place it surfaces in a Noiz Plesk subscription, how to open it against the right domain when your account holds several, and what to check when you cannot see it at all.
A word on names first, because it accounts for a good share of the "I cannot find it" tickets. The same tool is labelled **Softaculous**, **Applications**, **Apps Installer** or **Softaculous Auto Installer** (the name it carries in the Plesk extensions catalogue) depending on the Plesk release and how the panel has been themed. They are all the same installer, and any of them opens the same interface.
**Last reviewed:** 27 July 2026, against the current Plesk and Softaculous releases. This guide is written for Noiz hosting and is kept current against Plesk and Softaculous. It complements, and does not replace, the official Plesk and Softaculous documentation linked below.
### Official Documentation Reference
- [Softaculous end-user documentation](https://www.softaculous.com/docs/enduser): the authoritative reference for everything you do once Softaculous is open, including installing, cloning, staging, backing up and removing an application.
- [Softaculous for Plesk](https://www.softaculous.com/plesk/): the vendor's overview of the Plesk integration and the current application count.
- [Softaculous Auto Installer in the Plesk Extensions Catalogue](https://www.plesk.com/extensions/softaculous-auto-installer/): the extension listing, relevant if you run your own Plesk server and need to install it yourself.
- [Softaculous application list](https://www.softaculous.com/apps/): check here before you go looking, to confirm the application you want is one Softaculous carries.
- [Overview of the Plesk Interface (Plesk Customer's Guide)](https://docs.plesk.com/en-US/obsidian/customer-guide/overview-of-plesk-interface.74282/): useful background on the left-hand menu and the **Websites & Domains** page referred to throughout this guide.
## Prerequisites
- An active Noiz hosting subscription on Plesk, and the ability to [log in to Plesk](/plesk/how-to-log-in-to-plesk/). The panel address and your login are in your Noiz welcome email and in the Noiz client area.
- At least one domain already added to the subscription. Softaculous installs onto a domain, so if the subscription is empty there is nothing for it to install onto. See [how to add a new domain in Plesk](/plesk/how-to-add-a-new-domain-in-plesk/) or [how to add a subdomain](/plesk/how-to-add-a-subdomain-in-plesk/) first.
- The main subscription login rather than an additional user account you created underneath it. Additional users inherit only the permissions you granted them, and extension access is one of the things that can be withheld.
- If you are new to the tool itself, [What Is Softaculous?](/softaculous/what-is-softaculous/) explains what it does before you go looking for it.
## Is Softaculous Available on Your Noiz Plan?
This is worth settling before you spend time hunting through the interface, because the answer depends on what kind of hosting you have with Noiz.
**On Noiz shared hosting, yes.** Softaculous is installed and licensed by Noiz on the shared Plesk servers, and on the Noiz shared servers generally. There is nothing for you to buy, install or switch on, and it costs you nothing extra. If you hold a shared hosting subscription and cannot see Softaculous, treat that as something to diagnose (the troubleshooting section below covers it) rather than as a sign that your plan excludes it.
**On your own VPS or dedicated server, no, not automatically.** Softaculous is licensed per server, and the Noiz licence covers the Noiz shared servers. It does not automatically extend to a server you administer yourself. If you run your own unmanaged Plesk server and want Softaculous on it, you buy your own Softaculous licence and add the extension yourself from the Plesk extensions catalogue, as the vendor listing linked above describes. You then become the server administrator for it, which means the server-level Softaculous Admin Panel and its settings are yours to manage. If your VPS is on a Noiz managed plan, ask Noiz support what is already included before buying anything.
## Where Softaculous Appears in Plesk
Plesk surfaces Softaculous in more than one place, and which of them you see depends on your Plesk release, your view mode and whether you are looking at the subscription as a whole or at one domain. Any of the following routes opens the same installer, so use whichever appears for you.
### Route 1: The left-hand menu
Look down the left-hand navigation menu of Plesk for an entry named **Applications**. On the Noiz Plesk servers this is the usual home for Softaculous, and it is the fastest route. Opening it puts you into the Softaculous front page, scoped to your subscription, with the application categories listed down one side and the popular installers on the front page.
Do not expect a separate icon labelled "Softaculous" sitting on its own. Plesk presents the installer as a normal menu entry belonging to the subscription, alongside **Websites & Domains**, **Mail** and **Databases**, rather than as a tile in a grid of tools. If you are coming to Plesk from cPanel, that difference is the single most common reason people conclude the installer is missing when it is not.

### Route 2: From the domain on Websites & Domains
Open **Websites & Domains** and find the card or row for the domain you want to work on. Alongside the other per-domain controls you may see an entry for **Applications**, **Install Applications** or **Softaculous**. This route has a real advantage over the menu: it opens Softaculous with that domain already selected, so there is no chance of installing onto the wrong one.
What you can see on this page is affected by your view mode. Plesk offers more than one way of presenting **Websites & Domains**, and the compact presentations hide controls behind an expander or a menu rather than showing them all at once. If a domain's card looks unusually bare, that is the likely cause, and [changing the view mode in Plesk](/plesk/how-to-change-view-mode-in-plesk/) will bring the full set of controls back.

### Route 3: Plesk's own search box
Type `Softaculous`, or `Applications`, into the search box at the top of the Plesk interface. This is the most reliable route of the three, because it does not care where in the menu structure the entry currently sits or what the theme has renamed it to. Use it first if the other two routes come up empty, and use it whenever a Plesk update has moved things around.
## Opening Softaculous Against the Right Domain
Almost every Noiz Plesk subscription that causes trouble here is one holding several domains or subdomains. Softaculous is scoped to a subscription, not to a domain, so entering it from the left-hand menu gives you an installer that can reach every domain and subdomain in that subscription. That is convenient and it is also how sites end up in the wrong place.
- **Enter through the domain wherever you can.** Route 2 above pre-selects the domain for you, which removes the decision entirely. On a multi-domain subscription this is the safer habit.
- **If you entered through the menu, check the domain field on the install form.** Softaculous presents a domain selector (commonly labelled **Choose Domain**) on the installation form, pre-filled with one of your domains. It will not necessarily be the one you had in mind. Read it before you click **Install**, every time.
- **Check the directory field in the same glance.** The field that controls the subfolder is the one people get wrong most often, and it interacts with the domain choice: the wrong domain plus a pre-filled subfolder puts a site somewhere nobody will find it. [How to Install WordPress with Softaculous](/softaculous/how-to-install-wordpress-with-softaculous/) walks through both fields properly.
- **Subdomains appear as installable targets in their own right.** A subdomain you added in Plesk has its own document root, so installing onto `blog.yourdomain.com` (replace with your own domain) is a genuine, separate installation and not the same as installing into a `/blog` folder on the main domain.
- **Do not install onto a domain alias.** If an alias appears in the domain list, avoid it. An alias exists to point visitors at another domain's content and has no document root of its own, so an installation aimed at one does not end up where you expect.
- **If your login holds more than one subscription**, Plesk shows a subscription selector at the top of **Websites & Domains**. Softaculous only ever sees the domains in the subscription you currently have open, so if a domain you expected is missing from the domain list, you are almost certainly in the other subscription. Switch first, then open Softaculous again.
## How to Tell It Actually Opened
Softaculous loads inside the Plesk interface rather than replacing it, so a partial load can look like a broken page. You have reached it properly when all of the following are true:
- The application categories are listed down the side, and a search field for applications sits at the top of the Softaculous area. Note that this search field searches applications, not Plesk, and is a different box from the Plesk search described in Route 3.
- There is a way back to Plesk visible in the Softaculous toolbar. Use it rather than the browser back button, which can drop you part way through an install form.
- An **Installations** view (sometimes shown as a small box or list icon in the toolbar) opens and lists what is already installed under this subscription. On a new subscription this list is legitimately empty, and an empty list is a working Softaculous, not a broken one.
If the page renders but every panel is empty, or it spins indefinitely, that is a loading problem rather than an access problem. Go to the troubleshooting section below.

## Troubleshooting: You Cannot See Softaculous
**Symptom**: no **Applications** entry in the left-hand menu. Try the Plesk search box (Route 3) before concluding anything. Menu entries move between Plesk releases and can be renamed by a theme, but the search index still finds them.
**Symptom**: the domain card on **Websites & Domains** shows only a handful of controls. This is a view mode effect rather than a missing feature. Switch to a fuller view mode and the per-domain controls reappear.
**Symptom**: a domain you expected is not in the list. You are looking at the wrong subscription. Use the subscription selector at the top of **Websites & Domains** to switch, then reopen Softaculous.
**Symptom**: you are logged in as an additional user and see fewer options than the account owner does. Additional user accounts in Plesk carry only the permissions granted to them, and access to extensions is one of the permissions that can be withheld. Log in with the main subscription login to confirm, then adjust the additional user's role if you want them to have it.
**Symptom**: the Softaculous area loads blank, spins forever, or shows a broken frame. This is nearly always a browser extension, a privacy add-on or an ad blocker interfering with the framed interface. Test in a private or incognito window first, then in a different browser, before reporting a fault.
**Symptom**: you are bounced back to the Plesk login part way through. Plesk sessions expire, and an install form left sitting open while you fetch a password is long enough for it to happen. Log back in and start the form again rather than resubmitting the stale page.
**Symptom**: none of the above and it is genuinely absent on a Noiz shared subscription. Contact Noiz support with your domain name and what you have already tried. Softaculous is a server-side component, so its presence is not something you can switch on from inside your subscription, and this is a case for Noiz to check at the server level.
Separately, if Softaculous opens perfectly well but an installation fails part way through, that is a different problem with a different answer: see [where to find the Softaculous error log in a Plesk subscription](/softaculous/where-to-find-the-softaculous-error-log-in-a-plesk-subscription/).
## Softaculous and WordPress Toolkit on the Same Server
Plesk servers frequently carry **WordPress Toolkit** as well, and it appears in the same left-hand menu. Both will install WordPress and neither manages sites created by the other, so decide which one owns a given site and stay with it. Softaculous is the better choice when you want one installer covering hundreds of different applications. WordPress Toolkit is stronger for ongoing WordPress work such as cloning, staging and bulk plugin updates across many sites. Installing the same site twice, once with each, leaves you with two sites and two databases rather than one managed site.

## What to Do Next
With Softaculous open, pick your application and work through its installation form. The two fields that decide where the site actually lands are the domain selector and the directory field, and the Softaculous end-user documentation linked above covers the rest of the form in detail. For a guided run through the most common case, follow [how to install WordPress with Softaculous](/softaculous/how-to-install-wordpress-with-softaculous/). If you are still deciding whether Softaculous is the right route for what you are building, [What Is Softaculous?](/softaculous/what-is-softaculous/) sets out what it handles beyond the initial install. If your hosting is on cPanel rather than Plesk, the equivalent guide is [how to access Softaculous in cPanel](/softaculous/how-to-access-softaculous-in-cpanel/).
If Softaculous still will not appear on your Noiz shared subscription, or you would rather an application was installed and configured for you on the correct domain, open a ticket from your Noiz client area with the domain name and the application you want, and Noiz support will take it from there.
# How to Access Softaculous in cPanel
Source: https://docs.noiz.ie/softaculous/how-to-access-softaculous-in-cpanel/
Softaculous is the one-click application installer built into cPanel. It automates the setup of popular web applications such as WordPress, Joomla, Drupal, Magento and hundreds of others, handling the files, the database and the configuration for you, so there is no manual installation to do. This guide shows you how to open Softaculous from your cPanel account and what to expect once it loads.
**Last reviewed:** 27 July 2026, against the current cPanel **Jupiter** theme and the **Softaculous Apps Installer** plugin. This guide is written for Noiz hosting and is kept current against cPanel and Softaculous. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [Softaculous documentation home](https://www.softaculous.com/docs/)
- [Softaculous for cPanel: product overview and application list](https://www.softaculous.com/cpanel/)
## Prerequisites
- An active Noiz hosting plan that uses cPanel.
- Your cPanel username and password, from your welcome email or the Noiz client area.
- Softaculous enabled on the server. It is a server-side plugin, so it either appears for every account on that server or for none. If it is missing entirely, that is a server setting rather than something you can switch on yourself.
## Open Softaculous from cPanel
1. Log in to your cPanel account.
2. Scroll to the **Software** section and click **Softaculous Apps Installer**. 
3. cPanel opens the Softaculous interface inside the panel, with the application categories down the left side and the most popular installers on the front page. 
**Faster route:** instead of scrolling, type `Softaculous` into the search box at the top of the cPanel home page. The Jupiter theme filters the tool tiles as you type and the installer appears after a few characters. This is the more reliable way to find it, because the home page sections can be reordered or renamed.
### If the Icon Is Named Something Else
The tile is not always labelled the same way. Depending on the cPanel version and how the panel has been branded, the same tool can appear as any of the following, and all of them open Softaculous:
- **Softaculous Apps Installer**
- **Softaculous**
- **Script Installer** or **Apps Installer**
- A grouped **Softaculous** block that lists individual applications, such as **WordPress**, **Joomla** and **PrestaShop**, as their own icons. Clicking any one of those opens Softaculous with that application already selected.
## Return to cPanel
Softaculous runs inside the cPanel frame, so the browser back button can behave oddly and drop you part way through an installer form. To leave cleanly, click the **cPanel** icon in the Softaculous toolbar and you go straight back to the cPanel home page.

## What to Do Next
Once Softaculous is open, choose an application and click **Install**. Softaculous asks for a short set of details, then does the rest automatically:
- **Protocol and domain**: pick `https://` if the domain already has a working SSL certificate, then select the domain or subdomain you are installing onto.
- **Directory**: this is the single field people get wrong. Leave it **empty** to install at the root of the domain, for example `yourdomain.com` (replace with your own domain). Softaculous pre-fills it with something like `wp`, which would put the site at `yourdomain.com/wp` instead. Clear the field unless you genuinely want the application in a subfolder.
- **Administrator account**: set a username that is not `admin`, and a long, unique password. This login is exposed to the internet from the moment the install finishes.
- **Database name and prefix**: the defaults are fine. Softaculous creates the database and the database user for you.
Installation usually takes under a minute. Softaculous then shows the site address and the administration URL, and it emails them to you if you fill in the notification address.
## Troubleshooting
**Symptom**: there is no **Software** section and searching for Softaculous returns nothing. Softaculous is not installed on that server, or your plan does not include it. Contact Noiz support to confirm what is available on your account.
**Symptom**: the Softaculous page loads blank, or spins forever. This is usually a browser extension or an ad blocker interfering with the framed interface. Try a private or incognito window first, then a different browser, before reporting a fault.
**Symptom**: the installer refuses to continue because the target directory is not empty. Softaculous will not overwrite existing files. Either choose a different directory, or clear the existing contents in **File Manager** first, taking a backup before you delete anything.
**Symptom**: the install fails partway and leaves files behind. Open the Softaculous **Installations** list, remove the broken entry so the files and database are cleaned up, then run the install again rather than installing a second copy on top.
## A Note on WordPress
Some cPanel servers also carry **WordPress Toolkit** alongside Softaculous. Both will install WordPress, and neither one manages sites created by the other, so pick one and stay with it for a given site. Softaculous is the better choice when you want a single installer covering hundreds of different applications. WordPress Toolkit is stronger for ongoing WordPress work such as cloning, staging and bulk plugin updates across many sites.
For background on what Softaculous can do beyond installing, see [What is Softaculous](/softaculous/what-is-softaculous/). If your plan does not show Softaculous, or you would rather an application was installed and configured for you, contact Noiz support and the team will set it up on your behalf.
# How to Install Drupal with Softaculous
Source: https://docs.noiz.ie/softaculous/how-to-install-drupal-with-softaculous/
This guide shows you how to install Drupal on your hosting account using Softaculous, the one-click application installer (sometimes called an apps installer or auto-installer) included in your hosting control panel. Softaculous creates the database, copies the Drupal files and completes the initial setup for you, so there is nothing to upload or configure by hand. It is written for anyone setting up a new Drupal site on a Noiz hosting plan, and no Drupal experience is needed. By the end you will have a working Drupal site and know where to log in to its administration area.
**Last reviewed:** 27 July 2026, against Softaculous **6.3.7** (latest stable), installing Drupal core **11.4** (latest stable). This article reproduces the official Softaculous procedure for installing a script, applied to Drupal. Both products release frequently, so always cross-reference the current version of the official documentation before starting: direct links to every section used in this guide are provided below.
### Official Documentation Reference
- [Softaculous: Install a Script](https://www.softaculous.com/docs/enduser/install-a-script/)
- [Softaculous: Quick Install a Script](https://www.softaculous.com/docs/enduser/quick-install-a-script/)
- [Drupal core releases (current stable version)](https://www.drupal.org/project/drupal)
- [Drupal: PHP requirements](https://www.drupal.org/docs/getting-started/system-requirements/php-requirements)
- [Drupal CMS project page](https://www.drupal.org/project/cms)
## Prerequisites
- A Noiz hosting plan that includes the Softaculous apps installer.
- A domain or subdomain that already points to your hosting account.
- Your control panel login details. If your plan uses Plesk, see [How to log in to Plesk](/plesk/how-to-log-in-to-plesk/).
- PHP `8.3` or newer enabled for the domain. Drupal 11 does not install on older PHP versions.
## Step 1: Open Softaculous
1. Log in to your hosting control panel.
2. Find and open **Softaculous Apps Installer**. Depending on your panel it may appear as an icon on the main page or as a menu item labelled **Applications** or **Softaculous**.
## Step 2: Choose the Right Drupal Package
In the Softaculous category list on the left, open **Portal/CMS**, or type `Drupal` into the search box at the top. Softaculous currently lists two Drupal packages:
- **Drupal Core** (sometimes listed simply as Drupal): the standard Drupal installation. This guide follows this option.
- **Drupal CMS**: a ready-to-use bundle built on Drupal 11 core, pre-configured with media management, SEO and other features aimed at marketing teams and site builders. Once installed it is still ordinary Drupal underneath, and the Softaculous form is essentially the same, so you can follow this guide for either package.
Click the package you want to install.
## Step 3: Start the Installation
1. On the Drupal overview page, click the **Install** tab (or the **Install Now** button).
2. If a small arrow next to **Install** offers a choice between **Quick Install** and **Custom Install**, choose **Custom Install**. Quick Install fills most settings with defaults, while Custom Install shows every field described below.
## Step 4: Complete the Installation Form
### Software Setup
- **Choose the version you want to install**: leave the newest version selected (the 11.4 branch at the time of writing) unless you have a specific reason to install an older supported branch.
- **Choose Installation URL**: set the protocol to `https://` if your domain has an SSL certificate (all Noiz hosting plans include one), then pick your domain from the list.
- **In Directory**: leave this blank to install Drupal on the root of the domain, for example `https://yourdomain.com` (replace `yourdomain.com` with your own domain throughout this guide). Only enter a folder name here if you want the site at an address such as `https://yourdomain.com/drupal`.
- **Cron Job**: leave the default value. Drupal relies on scheduled cron runs for maintenance tasks, and Softaculous sets this up for you.
### Site Settings
- **Site Name**: enter the name of your website, for example `My First Website`. You can change this later inside Drupal.
### Admin Account
- **Admin Username**: choose a username for the Drupal administrator. For security, do not use `admin` or `administrator`.
- **Admin Password**: use a strong, unique password. The key icon next to the field generates one for you.
- **Admin Email**: enter an email address you can actually receive mail at, because Drupal sends password resets and notifications there.
**Note:** record the admin username and password somewhere safe, ideally in a password manager. You will need them to log in to your Drupal administration area.
### Choose Language
- **Select Language**: leave **English** selected, or pick the language you want Drupal installed in.
### Advanced Options (Optional)
Expand **Advanced Options** only if you need to change these settings. The defaults are safe:
- **Database Name**: Softaculous generates a database name automatically. Leave it as it is unless you have a naming convention to follow.
- **Automated backups** and **Backup Rotation**: you can ask Softaculous to take scheduled backups of this installation. Keep in mind that backups count towards your hosting plan's disk space.
At the bottom of the form, you can enter an address in **Email installation details to** to receive a summary of the installation, including the URLs and admin username.
## Step 5: Run the Installer and Log In
1. Scroll to the bottom of the form and click **Install**.
2. Wait while Softaculous copies the files and creates the database. This usually takes under a minute; do not close the browser tab while the progress bar is running.
3. When the installation completes, Softaculous shows two links: one to your new website and one to its administration area.
4. You can reach the Drupal login page at any time at `https://yourdomain.com/user/login` (again, replace `yourdomain.com` with your own domain). Log in with the admin username and password you set in Step 4.
## Troubleshooting
**You cannot find Softaculous in your control panel**: not every hosting plan includes the installer. Open a support ticket with the Noiz support team to confirm whether your plan includes Softaculous.
**The installer reports that files already exist in the target directory**: Softaculous refuses to overwrite an existing site. Either install into a different directory, or remove the old files first, but only after taking a backup of anything you still need.
**The installer reports an unsupported PHP version**: Drupal 11 requires PHP `8.3` or newer. Change the PHP version for the domain in your control panel, or ask the Noiz support team to do it, then run the installation again.
**You cannot find the Drupal login page**: unlike some other content management systems, Drupal does not link to its login page from the site itself by default. Go directly to `https://yourdomain.com/user/login`.
If you get stuck at any point, open a support ticket with the Noiz support team and include your domain name and the step where the installation failed. The team can confirm Softaculous availability, adjust PHP versions and check the installation logs for you.
# How to Install Joomla with Softaculous
Source: https://docs.noiz.ie/softaculous/how-to-install-joomla-with-softaculous/
This guide shows you how to install Joomla, a popular free content management system (CMS), on your hosting plan using Softaculous. Softaculous is an app installer, sometimes called a one-click or auto installer, that is built into your hosting control panel. It creates the database, copies the Joomla files, and configures the site for you, so no manual uploading or database work is needed. This guide is written for anyone setting up a new Joomla website on a Noiz hosting plan, and no technical experience is required.
**Last reviewed:** 27 July 2026, against Joomla **6.1.2** (latest stable), which is the version currently offered by the Softaculous app installer. This article reproduces the official Softaculous procedure for installing a script, applied to Joomla. Softaculous and Joomla both release frequently, so always cross-reference the current version of the official documentation before starting - direct links to every section used in this guide are provided below.
### Official Documentation Reference
- [Softaculous end-user docs: Install a Script](https://www.softaculous.com/docs/enduser/install-a-script/) - the official install procedure this guide follows
- [Softaculous end-user documentation index](https://www.softaculous.com/docs/enduser/) - upgrades, backups, cloning, and password resets
- [Joomla on Softaculous](https://www.softaculous.com/apps/portals_cms/Joomla) - the Joomla versions Softaculous currently offers
- [Joomla official downloads](https://downloads.joomla.org/) - confirms the latest stable Joomla release
- [Joomla Manual: Technical Requirements](https://manual.joomla.org/docs/next/get-started/technical-requirements) - PHP and database versions Joomla supports
## Prerequisites
- A Noiz hosting plan that includes the Softaculous app installer.
- Login details for your hosting control panel. If your plan uses Plesk, see [How to log in to Plesk](/plesk/how-to-log-in-to-plesk/).
- A domain name that already points to your hosting plan.
- An active SSL certificate on the domain, so the site can be installed over `https://`.
- PHP `8.3` or newer enabled for the domain. Joomla 6 requires PHP 8.3.0 as a minimum, and the Joomla project recommends PHP 8.4.
## Step 1: Open Softaculous
1. Log in to your hosting control panel.
2. Find the **Softaculous Apps Installer** icon or link. It is usually listed under an **Applications** or **Software** section of the panel.
3. Click it to open the Softaculous interface. You will see script categories in the left sidebar and the most popular scripts in the centre of the page.
## Step 2: Find Joomla and Start the Installer
1. In the left sidebar, click the **Portal/CMS** category, then click **Joomla**. You can also type `Joomla` into the search box at the top of the sidebar.
2. The Joomla overview page opens, showing ratings, screenshots, and a demo.
3. Click the **Install** button (or the **Install** tab) to open the installation form.
## Step 3: Complete the Installation Form
The form is divided into sections. Most fields have sensible defaults, and the ones that matter are covered below.
### Software Setup
1. Under **Choose Installation URL**, select the protocol. Choose `https://` if your domain has an SSL certificate, which is strongly recommended.
2. Select the domain you want to install Joomla on, for example `yourdomain.com` (replace this with your own domain throughout).
3. In the **In Directory** field, leave the box **blank** to install Joomla at the root of the domain, so the site loads at `https://yourdomain.com`. Only enter a directory name, for example `joomla`, if you want the site at `https://yourdomain.com/joomla`.
4. Under **Choose the version you want to install**, keep the latest version selected (currently `6.1.2`) unless you have a specific reason to install an older supported branch.
### Site Settings
- **Site Name**: the name of your website, for example `My First Website`. You can change this later in Joomla.
- **Site Description**: a short description or slogan for the site. This can also be changed later.
### Admin Account
- **Admin Username**: choose something unique. Avoid `admin` or `administrator`, as automated attacks try those names first.
- **Admin Password**: use a long, strong password. The key icon next to the field generates one for you, and the meter shows the password strength.
- **Real Name**: your name as it should appear in Joomla.
- **Admin Email**: a working email address. Joomla uses it for password recovery, so make sure you can receive mail there.
Record the admin username and password in a password manager before you continue. You will need them to log in to your Joomla administrator area.
### Choose Language
- Select the language for your Joomla site. The default is **English**, and additional languages can be added inside Joomla later.
### Advanced Options
Click **Advanced Options** to expand this section. The defaults are fine for most installations, but it is worth knowing what is here:
- **Database Name** and **Table Prefix**: Softaculous generates safe values automatically. Only change them if you have a naming convention to follow.
- **Automated backups**: you can have Softaculous back the installation up on a schedule, with a rotation limit. Backups count towards your disk space, so keep the rotation small.
- **Auto Upgrade**: optionally let Softaculous apply Joomla updates automatically.
### Email Installation Details
- At the bottom of the form, enter your email address in the **Email installation details to** field to receive a summary of the installation, including the URLs.
## Step 4: Run the Installation
1. Click the **Install** button at the bottom of the form.
2. A progress bar appears. Installation normally takes under a minute, though the time varies. Do not close the browser window until it finishes.
3. When the installation completes, Softaculous shows a success message with two links: the address of your new site and the address of its administrator area.
## Step 5: Log in to Your New Joomla Site
1. Open the administrator link from the success screen. For a root installation it looks like `https://yourdomain.com/administrator` (using your own domain).
2. Log in with the **Admin Username** and **Admin Password** you set in Step 3.
3. You are now in the Joomla administrator dashboard, where you can choose a template, create articles, and build menus. Your public site is live at `https://yourdomain.com`.
## Troubleshooting
- **The installer reports that files already exist in the target directory**: another site or an earlier installation attempt is occupying that location. Either choose a different **In Directory** value, or back up and remove the existing files first, then run the installer again.
- **The installation fails with a database error**: your plan may have reached its database limit, or a database with the generated name already exists. Remove an unused database, or expand **Advanced Options** and set a different **Database Name**.
- **Joomla reports an unsupported PHP version**: Joomla 6 needs PHP 8.3.0 or newer. Raise the PHP version for the domain in your hosting control panel, or select a supported older Joomla branch from the version dropdown before installing.
- **The site loads over http instead of https**: confirm the domain has a valid SSL certificate, then use **Edit Installation** (the pencil icon next to the installation in Softaculous) to change the installation URL to `https://`.
- **You have lost the admin password**: in Softaculous, open **All Installations**, find the Joomla installation, and use the admin password reset option to set a new one.
Softaculous is included on Noiz hosting plans that ship with the app installer, and everything above happens inside your own control panel. If you get stuck at any step, open a support ticket with the Noiz support team, including your domain name and the point where the installation failed, and they will help you get your Joomla site running.
# How to Install WordPress with Softaculous
Source: https://docs.noiz.ie/softaculous/how-to-install-wordpress-with-softaculous/
This guide shows you how to install WordPress on your hosting account using Softaculous, the one-click application installer (sometimes called an auto-installer or app installer) included with many Noiz hosting plans. Softaculous handles the file copying, database creation, and initial configuration for you, so you do not need to upload anything manually. By the end of this guide you will have a working WordPress website and know how to log in to its admin area. No coding knowledge is required.
**Last reviewed:** 27 July 2026, against Softaculous **6.3.7** (latest stable). This article reproduces the official Softaculous procedure for installing WordPress, which was at version **7.0.2** (latest stable) at the time of review. Softaculous releases frequently, so always cross-reference the current version of the official documentation before starting - direct links to every section used in this guide are provided below.
### Official Documentation Reference
- [Softaculous: Install WordPress using Softaculous](https://www.softaculous.com/docs/enduser/install-wordpress-using-softaculous/) - the official WordPress installation walkthrough
- [Softaculous: Install a Script](https://www.softaculous.com/docs/Install_a_Script) - the generic installation form and its fields
- [Softaculous: WordPress Manager](https://www.softaculous.com/docs/enduser/wordpress-manager/) - managing your installation after setup
- [WordPress: Release announcements](https://wordpress.org/news/category/releases/) - confirm the current WordPress version
## Prerequisites
- An active Noiz hosting plan that includes the Softaculous app installer.
- The login details for your hosting control panel. If your plan uses Plesk, see [How to Log in to Plesk](/plesk/how-to-log-in-to-plesk/).
- A domain name that already points to your Noiz hosting account.
- A working email address to use for the WordPress admin account.
## Step 1: Open Softaculous in Your Control Panel
1. Log in to your hosting control panel.
2. Find the **Softaculous Apps Installer** icon. It normally sits in an applications or software section of the panel, and its exact location varies between control panels. If you cannot find it, use the panel's search box and search for `Softaculous`.
3. Click the icon to open the Softaculous interface.

## Step 2: Find WordPress and Start the Installer
1. In Softaculous, type `WordPress` into the search box, or open the **Blogs** category in the left-hand menu and click **WordPress**.
2. On the WordPress overview page, click **Install**. The installation form opens.

Depending on how Softaculous is configured on your plan, some of the fields described below may be pre-filled or tucked away behind an expandable section. The defaults are safe to accept; the settings below are the ones worth checking before you install.
## Step 3: Complete the Installation Form
### Software Setup
- **Choose Installation URL**: select the protocol and the domain you want WordPress installed on. Choose `https://` if your domain has an SSL certificate, which is the case on Noiz hosting plans.
- **In Directory**: leave this field **blank** to install WordPress at the root of your domain, for example `https://yourdomain.com` (replace `yourdomain.com` with your own domain throughout this guide). Only enter a directory name here if you deliberately want WordPress in a subfolder, for example `blog` for `https://yourdomain.com/blog`.
- **Choose the version you want to install**: leave this at the newest version offered unless you have a specific reason to install an older release.

### Site Settings
- **Site Name**: the name of your website, for example `My First Website`. You can change this later inside WordPress.
- **Site Description**: a short tagline for the site. This can also be changed later.
- **Enable Multisite (WPMU)**: leave this **unticked** unless you specifically need a WordPress multisite network.
### Admin Account
- **Admin Username**: choose a username for the WordPress administrator. For security, do not use `admin` or `administrator`, as automated attacks try these first.
- **Admin Password**: use a long, unique password. Click the key icon next to the field to have Softaculous generate a strong one for you.
- **Admin Email**: enter a working email address. WordPress sends password resets and important notifications here, so make sure you can receive mail at this address.
Record the admin username and password somewhere safe, ideally in a password manager. You will need them to log in to your WordPress admin area.

### Choose Language
- **Select Language**: pick the language for your WordPress dashboard and site. The default is English.
### Select Plugins and Theme
- **Select Plugin(s)**: Softaculous may offer to install optional plugins, such as a login-protection plugin, during setup. These are optional; you can skip them all and add plugins from inside WordPress later.
- **Select Theme**: you can pick a theme now, or leave the selection empty and WordPress will use its current default theme. Themes are easy to change afterwards from the WordPress dashboard.
### Advanced Options
Click **Advanced Options** to expand this section. The defaults are fine for most installations, but the following settings are worth knowing about:
- **Database Name** and **Table Prefix**: Softaculous generates these automatically. Leave them as they are unless you have a specific naming requirement.
- **Auto Upgrade**: controls whether Softaculous automatically updates WordPress core, and separate options cover automatic updates for plugins and themes. Enabling automatic updates keeps your site patched against security issues.
- **Automated backups** and **Backup Rotation**: Softaculous can take scheduled backups of the installation and keep a set number of copies. Backups count towards your hosting plan's disk space, so keep the rotation modest.

### Email Installation Details
- **Email installation details to**: enter your email address here if you would like Softaculous to send you a summary of the installation, including the URLs and the admin username.
## Step 4: Run the Installation and Log In
1. Scroll to the bottom of the form and click **Install**.
2. A progress bar appears while Softaculous copies the WordPress files and creates the database. Installation time varies, so leave the browser window open until it finishes.
3. When the installation completes, Softaculous shows a success message with two links: one to your new website and one to the WordPress admin area.
4. Click the admin link, or browse to `https://yourdomain.com/wp-admin/` (using your own domain), and log in with the admin username and password you set in Step 3.

## Managing Your Installation Afterwards
Softaculous keeps track of every installation it creates. Open Softaculous and go to **All Installations** (the box icon in the top toolbar) to upgrade WordPress, take or restore backups, clone the site, create a staging copy, or remove the installation cleanly. The **WordPress Manager** section adds one-click admin login, password changes, and plugin and theme management without needing to log in to WordPress itself.
## Troubleshooting
- **You cannot find Softaculous in your control panel**: not every plan includes Softaculous. Open a support ticket with the Noiz support team to confirm whether your plan includes it.
- **The installer reports that files already exist in the target directory**: Softaculous will not overwrite an existing site. Either choose a different directory in the **In Directory** field, or remove the old files first if you are certain they are no longer needed. Take a backup before deleting anything.
- **The installation succeeds but the site shows an old or default page**: your browser may be showing a cached copy, or your domain's DNS may still be propagating. Clear your browser cache, try a private browsing window, and allow up to 24 hours if the domain was recently pointed at Noiz.
- **You forgot the admin password**: open the installation in Softaculous and use its password change option, or click **Lost your password?** on the WordPress login page to receive a reset link at the admin email address.
- **The installer reports a PHP or database version problem**: this usually means an outdated PHP version is selected for your domain. Open a support ticket with the Noiz support team and the team will check the configuration for you.
Installing WordPress with Softaculous normally takes less than five minutes. If you get stuck at any point, open a support ticket with the Noiz support team and include your domain name and the step you are on.
# What Is Softaculous?
Source: https://docs.noiz.ie/softaculous/what-is-softaculous/
Softaculous is the auto-installer built into your hosting control panel. It takes a web application such as WordPress, Joomla or Drupal and does the whole setup for you: downloading the files, creating the database and database user, writing the configuration file, and creating your administrator login. What would otherwise be a twenty-minute manual job becomes a short form and a single click.
Think of it as an app store for your website. You pick the software you want, tell Softaculous which domain and folder to install it into, and it hands you a working site with a login, usually in under a minute. You will also see it called the **Softaculous Apps Installer**, the **Softaculous Auto Installer**, or simply "the one-click installer". These are all the same tool. This article explains what it does, what it does not do, and where to find it on Noiz hosting.
**Last reviewed:** 27 July 2026, against the current stable release of Softaculous. This guide is written for Noiz hosting and is kept current against Softaculous. It complements, and does not replace, the official Softaculous documentation linked below.
### Official Documentation Reference
- [Softaculous documentation home](https://www.softaculous.com/docs/).
- [The full Softaculous application library](https://www.softaculous.com/apps/), which is the authoritative list of what can be installed.
## What Softaculous Actually Does
Installing is only the headline feature. Once an application is installed through Softaculous it appears in your **Installations** list, and the same tool manages it for the rest of its life:
- **Install** an application onto a domain, subdomain or subfolder, with the database and admin account created for you.
- **Upgrade** to a newer version of the application, either on demand or automatically as releases appear, so you stay on a secure and supported release.
- **Back up** an installation (files, database, or both) and **restore** from that backup if a change goes wrong.
- **Clone** a site to another domain or folder, which is the usual way to build a staging copy before you make a risky change.
- **Uninstall** cleanly, removing the files, the database and the database user together instead of leaving orphans behind.
Automatic backups and automatic upgrades are set per installation, so you can leave a hobby site to look after itself while keeping a hands-on approach to your main site.
The uninstall behaviour is worth noting. If you delete an application's folder by hand in File Manager, the database, the database user and the Softaculous record of the install all stay behind and quietly consume your plan's limits. Removing it from the Softaculous **Installations** list clears all of it in one go.
## Applications You Can Install
Softaculous carries over 400 web applications, grouped by what they are for. The ones customers reach for most often on Noiz hosting are:
- **Blogs and content management:** WordPress, Joomla, Drupal, Ghost, Grav, Concrete CMS.
- **Online shops:** WooCommerce (as a WordPress option), PrestaShop, OpenCart, Magento Open Source.
- **Forums and community:** phpBB, Discourse, Flarum.
- **Learning and documentation:** Moodle, MediaWiki, DokuWiki.
- **Business and productivity:** Nextcloud, Dolibarr, SuiteCRM, Matomo analytics, Mautic.
- **Developer frameworks:** Laravel, Symfony, CodeIgniter, and plain PHP or Node.js starting points.
The library changes as applications are added and as older ones are retired, so treat the list above as a guide rather than an inventory. The live list inside your own control panel is always the accurate one, because it reflects what the server's PHP and database versions can actually run.
## Where to Find Softaculous on Noiz Hosting
Softaculous sits inside your control panel, so how you reach it depends on which panel your plan uses:
- **cPanel:** log in, scroll to the **Software** section, and click **Softaculous Apps Installer**. Full walkthrough: [How to Access Softaculous in cPanel](/softaculous/how-to-access-softaculous-in-cpanel/).
- **Plesk:** log in to your subscription and open **Applications** from the left-hand menu, or use the **Websites & Domains** tab.
If you cannot see it at all, the quickest check is the control panel search box: type `Softaculous` on the home page. If nothing comes back, your plan may not include it, and Noiz support can confirm that for you.
## The Honest Limits
Softaculous is excellent at getting an application running. It is worth being clear about where its responsibility ends, because that is where most avoidable problems start.
- **It installs, it does not maintain your site.** Once WordPress is on your domain, the themes, plugins, content and security posture are yours to look after. Softaculous can automate the core application upgrade, but it has no opinion about the fifteen plugins you added afterwards.
- **Automatic upgrades cut both ways.** Leaving auto-upgrade on keeps you patched without thinking about it, which is usually the right call for security. It can also push a major version that one of your plugins is not ready for. If the site matters to your business, pair auto-upgrade with the automatic backup option so there is always something to roll back to.
- **Softaculous backups live on the same account.** They count against your disk quota and they sit on the same server as the site. They are ideal for undoing a bad upgrade, and they are not a disaster recovery plan. Keep an independent copy somewhere off the server as well.
- **The install target must be empty.** Softaculous refuses to write over existing files, which is a feature rather than an obstacle. To install at the top level of a domain, leave the **In Directory** field blank. To install into a subfolder, name a folder that does not exist yet.
- **Change the defaults on the install form.** The two fields worth ten seconds of your attention are the administrator username (do not leave it as `admin`) and the admin email address, which is where password resets and update notices will go.
## Related Guides
- [How to Access Softaculous in cPanel](/softaculous/how-to-access-softaculous-in-cpanel/)
- [How to Install WordPress with Softaculous](/softaculous/how-to-install-wordpress-with-softaculous/)
- [How to Install Joomla with Softaculous](/softaculous/how-to-install-joomla-with-softaculous/)
- [How to Install Drupal with Softaculous](/softaculous/how-to-install-drupal-with-softaculous/)
- [Where to Find the Softaculous Error Log in a Plesk Subscription](/softaculous/where-to-find-the-softaculous-error-log-in-a-plesk-subscription/)
If the application you want is not in the library, or an installation fails and the on-screen error does not tell you enough, open a ticket from your Noiz client area. Quote the application, the domain and the directory you were installing into, and Noiz support will take it from there.
# Where to Find the Softaculous Error Log in a Plesk Subscription
Source: https://docs.noiz.ie/softaculous/where-to-find-the-softaculous-error-log-in-a-plesk-subscription/
Softaculous is the one-click application installer built into Plesk that deploys WordPress, Joomla, Magento, Nextcloud and hundreds of other web applications for you. Every so often an install stops part-way and reports that it failed. When that happens, the error Softaculous recorded is what tells you why, and reading it turns a vague "it did not work" into a fixable, specific fault.
This guide shows you, as the owner of a Plesk subscription on Noiz hosting, where Softaculous records a failed installation, how to read that record, and a worked example of a common failure and its fix.
**Last reviewed:** 27 July 2026, against the current stable release of Softaculous. This guide is written for Noiz Plesk hosting and is kept current against Softaculous. It complements, and does not replace, the official Softaculous documentation linked below.
### Official Documentation Reference
- [Softaculous Logs in the Admin Panel](https://www.softaculous.com/docs/admin/softaculous-logs-admin-panel) (server-administrator reference for the on-disk log files).
- [Softaculous documentation home](https://www.softaculous.com/docs/).
## Prerequisites
- A Plesk hosting subscription on Noiz with Softaculous available (you reach it from the Plesk left-hand menu under **Applications**, or from the **Websites & Domains** tab).
- An installation that has failed, so there is an error to look at.
## Read the on-screen error first
When an installation fails, Softaculous does not hide the reason. The results page shows the failure with a red banner and a short message describing what went wrong, and the installation is usually rolled back so it does not leave a half-built site behind. This on-screen message is the single most useful thing you have as a subscription owner, because you can see it without any server-level access.
Before you do anything else, read that message in full and copy it somewhere. Nine times out of ten it names the exact problem: a directory that is not empty, a database limit reached, or a download that did not complete. If you closed the page too quickly, start the same install again and let it fail once more so you can capture the wording.
## Where Softaculous keeps its error logs
Behind the on-screen message, Softaculous writes a persistent record to two log files on the server:
- `/var/softaculous/error_log.log` captures critical failures inside Softaculous itself.
- `/var/softaculous/logs/softaculous.log` records general operational activity, at the logging level set in Softaculous.
A server administrator reads these from within the **Softaculous Admin Panel** under **Settings > Error Logs**, where a drop-down chooses which of the two files to display and the entries appear in a panel below.
**Scope, honestly:** those two files and the Softaculous Admin Panel live at the *server* level, not inside your subscription. On Noiz managed Plesk hosting you have your subscription in Plesk, not shell access or the server-wide Softaculous Admin Panel, so you cannot open `/var/softaculous/error_log.log` yourself. That is by design and it keeps the shared server secure. If the on-screen message is not enough to solve the problem, this is where Noiz support steps in: raise a ticket and Noiz will pull the matching lines from the server-level log for your subscription. If instead you run your own Plesk server and hold the administrator login, you can open the Admin Panel path above directly.
## A worked example: the target directory is not empty
One of the most common Softaculous failures on a Plesk subscription reads along these lines on the results page, and is mirrored in the log:
```
Installation Failed
The directory you have specified already exists and is not empty.
Please specify an empty directory or a directory that does not exist.
```
**Why it happens:** Softaculous refuses to install over the top of existing files so that it never overwrites content you meant to keep. This appears when you try to install into the domain root (`httpdocs`) of a subscription that already has a site in it, or into a subfolder you used for a previous install and did not clear.
**How to fix it:**
1. Decide where the new application should live. To put it at the top level of the domain (for example `yourdomain.com`), the **In Directory** field on the Softaculous install form must be left empty.
2. To install into a subfolder instead (for example `yourdomain.com/blog`), enter a folder name that does not yet exist in **In Directory**.
3. If you genuinely want to reuse a location that already has files, remove the old contents first using the Plesk **File Manager** (or delete the previous installation from the Softaculous **Installations** list so Softaculous cleans it up for you), then run the install again.
## Other common failures and their fixes
- **Database limit reached** (message mentions creating the database, or a MySQL error): your hosting plan has a fixed number of databases and you have used them all. Remove an unused database in Plesk under **Databases**, or move to a plan with a higher limit.
- **Disk quota exceeded**: the install runs out of space part-way. Free up space in **File Manager** or upgrade the plan, then retry.
- **Download or mirror failure** (message mentions failing to download the install package, or a cURL error): the server could not fetch the application package. This is transient more often than not, so retry after a few minutes. If it keeps failing it is a server-side matter, so contact Noiz.
- **Permission or write errors** (failed to create a directory or file): usually a leftover from a previous failed attempt. Clear the target directory as in the worked example above, then reinstall.
## Still stuck?
If the on-screen error does not point to something you can change yourself, the answer is almost always in the server-level Softaculous log, which Noiz can read for you. Open a ticket from your Noiz client area, quote the exact wording of the failure and the application, domain and directory you were installing into, and Noiz support will check `/var/softaculous/error_log.log` for your subscription and tell you exactly what to do next.
# How to Install and Configure Nextcloud AIO on Ubuntu 24.04 LTS
Source: https://docs.noiz.ie/nextcloud/how-to-install-and-configure-nextcloud-aio-on-ubuntu-2404-lts/
This guide walks you through installing and configuring Nextcloud All-in-One (AIO) on an Ubuntu 24.04 LTS (Noble) server, with software RAID, a custom data directory on dedicated storage, and full IPv6 support. It is written from a real Noiz production install (noiz.cloud) running on a dedicated cloud server, and it reflects the specific configuration changes needed to make AIO work reliably on a modern Ubuntu host. The same procedure also works on Ubuntu 22.04 LTS (Jammy), which shares the same networking stack.
**Last reviewed:** 27 July 2026, against Nextcloud All-in-One (latest stable) on Ubuntu **24.04 LTS**. This guide is written for Noiz hosting and documents a real Noiz production deployment. It complements, and does not replace, the official Nextcloud AIO and Docker documentation linked below.
### Official Documentation Reference
- Nextcloud AIO repository and documentation: [github.com/nextcloud/all-in-one](https://github.com/nextcloud/all-in-one)
- Docker Engine install on Ubuntu: [docs.docker.com/engine/install/ubuntu](https://docs.docker.com/engine/install/ubuntu/)
- Docker IPv6 networking: [docs.docker.com/engine/daemon/ipv6](https://docs.docker.com/engine/daemon/ipv6/)
- Nextcloud admin manual: [docs.nextcloud.com/server/latest/admin\_manual](https://docs.nextcloud.com/server/latest/admin_manual/)
## Hardware Setup Assumptions
The following hardware setup is assumed. Adjust to your own where the specifics differ.
- **NVMe Drives**: Two NVMe SSDs in a RAID 1 array, hosting the operating system, swap, and boot partition.
- **HDDs**: Four hard disk drives in a RAID 5 array for bulk data storage, providing redundancy with one drive of fault tolerance.
- **Network**: A network interface with a routed public IPv6 `/64` from your provider.
- **Resources**: At least 4 CPU cores and 8 GB RAM. A fully featured AIO install can run up to around 14 containers (a master, five core services, and several optional add-ons), so more resources help.
## Prerequisites
- **OS**: Ubuntu 24.04 LTS (Noble), 64-bit. The same steps also work on 22.04 LTS (Jammy).
- **Software**: Docker Engine from the official Docker APT repository (not the Snap package), `mdadm`, and basic system tools.
- **Network**: Public IPv4 and, ideally, a routed IPv6 `/64`.
- **Access**: Root or sudo on the host.
## Step 1: Set Up Software RAID
NVMe RAID 1 is typically pre-configured by the hosting provider. This step covers building the RAID 5 array on the HDDs for Nextcloud data.
### 1.1 Verify Current Block Devices
```
lsblk
```
Confirm the NVMe drives are already part of the existing arrays (`/dev/md0` for swap, `/dev/md1` for `/boot`, `/dev/md2` for `/`) and that the HDDs (`sda`, `sdb`, `sdc`, `sdd`) are unused.
### 1.2 Create the RAID 5 Array
```
mdadm --create --verbose /dev/md3 --level=5 --raid-devices=4 /dev/sda /dev/sdb /dev/sdc /dev/sdd
```
Monitor build progress:
```
cat /proc/mdstat
```
Format the array (this may take a long time on large arrays):
```
mkfs.ext4 /dev/md3
```
### 1.3 Mount the Array Persistently
```
mkdir /data
mount /dev/md3 /data
```
Get the array UUID:
```
blkid /dev/md3
```
Add to `/etc/fstab` using that UUID (replace with your own):
```
UUID=xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx /data ext4 defaults 0 0
```
Test the fstab entry:
```
mount -a
```
### 1.4 Persist the RAID Configuration
```
mdadm --detail --scan | grep md3 | tee -a /etc/mdadm/mdadm.conf
update-initramfs -u
```
This ensures the array is assembled correctly on every boot.
## Step 2: Install Docker Engine
Install Docker from the official Docker APT repository. **Do not use the Ubuntu Snap package.** Its sandboxing causes problems with bind mounts, networks, and AIO's container management.
### 2.1 Add the Docker APT Repository
```
apt-get update
apt-get install ca-certificates curl
install -m 0755 -d /etc/apt/keyrings
curl -fsSL https://download.docker.com/linux/ubuntu/gpg -o /etc/apt/keyrings/docker.asc
chmod a+r /etc/apt/keyrings/docker.asc
echo "deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.asc] https://download.docker.com/linux/ubuntu $(. /etc/os-release && echo "${UBUNTU_CODENAME:-$VERSION_CODENAME}") stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null
apt-get update
```
### 2.2 Install Docker
```
apt-get install docker-ce docker-ce-cli containerd.io docker-buildx-plugin docker-compose-plugin
```
### 2.3 Verify the Install
```
docker run hello-world
```
## Step 3: Configure Docker daemon.json (DNS + IPv6)
This is the most important step and the one most likely to be done incorrectly. There are two issues to solve at the Docker daemon level.
### 3.1 Why DNS Configuration Matters
Ubuntu 24.04 (and 22.04 before it) uses `systemd-resolved`, which puts `127.0.0.53` in the host's `/etc/resolv.conf` as a stub resolver. When Docker copies this resolv.conf into containers, the loopback address resolves to the container itself rather than the host's resolver, and DNS resolution silently fails inside every container. The AIO master container's first action on startup is a `curl` to `ghcr.io` to check for updates, so this DNS failure causes the master to crash-loop indefinitely.
The fix is to explicitly set DNS servers in `daemon.json` so every container gets working resolvers regardless of what is in the host's resolv.conf.
### 3.2 Why the Default IPv6 Example Is Wrong
Many guides (including older versions of this one) use `2001:db8:1::/64` as the `fixed-cidr-v6` value. This is the **RFC 3849 documentation prefix**, which is reserved for use in examples and must never appear on a production network. Containers assigned addresses in this range cannot route to the internet, because no router on the internet will accept traffic from or send traffic to this prefix.
The correct approach is to sub-allocate a slice from your provider's routed `/64`.
### 3.3 Determine Your IPv6 Sub-Prefix
Check what IPv6 prefix your host has:
```
ip -6 addr show scope global
```
Look for the public IPv6 on your main network interface. On a typical dedicated cloud server it often looks like `2a01:4f8:13b:3004::2/64`, meaning your provider has routed `2a01:4f8:13b:3004::/64` to the server. This value is an example only; substitute your provider's actual routed prefix.
Pick a `/80` sub-prefix from inside this `/64` that does not conflict with the host's own address. A safe pattern is to use a discriminator nibble like `:1::/80`, giving:
```
2a01:4f8:13b:3004:1::/80
```
Replace `2a01:4f8:13b:3004` with your own prefix.
### 3.4 Write the daemon.json
```
cat > /etc/docker/daemon.json <<'EOF'
{
"ipv6": true,
"fixed-cidr-v6": "2a01:4f8:13b:3004:1::/80",
"ip6tables": true,
"default-network-opts": {
"bridge": {
"com.docker.network.enable_ipv6": "true"
}
},
"dns": ["1.1.1.1", "8.8.8.8"]
}
EOF
```
### 3.5 Apply
```
systemctl restart docker
```
### 3.6 Verify IPv6 Works in a Container
```
docker run --rm alpine sh -c "ip -6 addr show eth0 && ping6 -c 2 ipv6.google.com"
```
You should see that the container has a public address in your sub-prefix (for example `2a01:4f8:13b:3004:1::3/80`) and that `ping6` succeeds with reasonable latency.
## Step 4: Install Nextcloud AIO
Deploy the AIO master container with the data directory pointed at the RAID 5 array.
### 4.1 Prepare the Data Directory
AIO expects the data directory to be owned by UID 33 (which is `www-data` inside the AIO Nextcloud container):
```
mkdir -p /data/ncdata
chown 33:0 /data/ncdata
chmod 750 /data/ncdata
```
### 4.2 Run the Master Container
```
docker run -d \
--init \
--sig-proxy=false \
--name nextcloud-aio-mastercontainer \
--restart always \
--publish 80:80 \
--publish 8080:8080 \
--publish 8443:8443 \
--volume nextcloud_aio_mastercontainer:/mnt/docker-aio-config \
--volume /var/run/docker.sock:/var/run/docker.sock:ro \
--env NEXTCLOUD_DATADIR="/data/ncdata" \
ghcr.io/nextcloud-releases/all-in-one:latest
```
The `--restart always` flag ensures the master comes back up automatically on reboot or after a Docker daemon restart.
**Note on DNS**: Because DNS servers were set in `daemon.json` in Step 3, the master container inherits working DNS automatically. If you did not complete Step 3, you would need to add `--dns 1.1.1.1 --dns 8.8.8.8` to this `docker run` command to avoid the crash-loop described earlier.
### 4.3 Confirm the Master Is Healthy
```
docker ps | grep nextcloud-aio-mastercontainer
```
Expected: `Up X seconds (healthy)`. If you see `Restarting`, check the logs with `docker logs nextcloud-aio-mastercontainer` to diagnose.
## Step 5: Configure the Firewall
Open the ports AIO needs, plus your chosen SSH port:
```
ufw allow 80,443,8080,8443,3478,2222/tcp
ufw allow 3478/udp
ufw reload
ufw enable
```
Adjust `2222` to whichever non-standard port your SSH service listens on. Ensure IPv6 is also enabled in UFW: check `/etc/default/ufw` for `IPV6=yes`.
Port summary:
- **80**: HTTP (used by the AIO Apache container for ACME/Let's Encrypt challenges and HTTP-to-HTTPS redirects).
- **443**: HTTPS (the main Nextcloud entry point, served by the AIO Apache container).
- **8080**: AIO management interface (self-signed cert; see the HSTS note below).
- **8443**: AIO management interface, alternate.
- **3478/tcp+udp**: Nextcloud Talk STUN/TURN.
## Step 6: First Access to the AIO Interface
### 6.1 Access Via Server IP, Not Domain
The AIO management interface uses a self-signed certificate by design. Once Nextcloud is set up and HSTS is enabled on the domain (which it will be), browsers refuse to accept the self-signed cert on port 8080 even though it is a different port. **Always access the AIO interface using the server IP, not the domain name**:
```
https://:8080
```
For example: `https://203.0.113.10:8080` (the address shown here is an example; use your own). Accept the self-signed certificate warning in your browser. Use HTTPS, not HTTP.
### 6.2 Retrieve the AIO Passphrase
The AIO interface displays a one-time generated passphrase on first run. If you missed it or need to retrieve it later, run the following on the host:
```
docker exec nextcloud-aio-mastercontainer grep password /mnt/docker-aio-config/data/configuration.json
```
Save this passphrase in your password manager. It is required for every login to the AIO management interface.
### 6.3 Complete the Setup Wizard
Log in, enter your Nextcloud domain name, select the optional containers you want (Office, Talk, Whiteboard, and so on), and confirm the data directory shows `/data/ncdata`.
### 6.4 Start the Containers
This step is missed easily. After completing the wizard, you must click **Start containers** in the AIO interface to begin pulling and launching the child containers (Apache, Nextcloud, PostgreSQL, Redis, and any optional add-ons). The initial pull takes 10 to 20 minutes depending on bandwidth, since AIO pulls a dozen or more container images.
Monitor progress in the AIO interface (the indicators turn green as each container becomes healthy) or from the host:
```
docker ps
```
## Step 7: Post-Installation
### 7.1 Verify Everything Is Up
```
docker ps
docker logs nextcloud-aio-mastercontainer
ls -l /data/ncdata
```
You should see the master container plus its child containers: the five core services (Apache, Nextcloud, PostgreSQL, Redis, and Notify Push) and any optional add-ons you enabled. All should be `Up` and, eventually, `(healthy)`. The data directory will contain Nextcloud's data files owned by UID 33.
### 7.2 Enable Backups
Configure the backup target in the AIO interface (a local `/mnt/backup` path or a remote borg repository). Daily backups are recommended.
### 7.3 Updates
Future updates of Nextcloud and all child containers are performed via the **Stop containers** then **Start and update containers** sequence in the AIO interface. Do not attempt to update child containers directly from the command line, because AIO is the authoritative manager.
### 7.4 Reboot Persistence
To confirm the install survives a reboot, run `reboot` on the host and verify that after the host comes back, `docker ps` shows all containers `Up` within 1 to 2 minutes. The master comes back via `--restart always` and starts the children automatically.
## Troubleshooting
### Master Container Crash-Looping
If `docker ps -a | grep mastercontainer` shows `Restarting`:
```
docker logs --tail 30 nextcloud-aio-mastercontainer
```
Look for `Could not resolve host: ghcr.io`, which indicates the DNS problem described in Step 3. Verify `/etc/docker/daemon.json` contains the `"dns"` entry and that `systemctl restart docker` was run after the change.
### AIO Interface Unreachable
If `https://:8080` times out:
- Confirm UFW allows port 8080 (`ufw status`).
- Confirm any provider-level firewall (for example a cloud firewall in your provider's control panel) also allows port 8080 inbound.
- Confirm the master container is up and bound to 8080 (`docker ps`).
### HSTS Blocks the AIO Interface
If your browser shows `SEC_ERROR_UNKNOWN_ISSUER` with no "Accept Risk and Continue" option when accessing `https://:8080`, this is HSTS blocking. Use the server's IP address instead of the domain name. HSTS is hostname-bound, so the IP is unaffected.
### IPv6 Not Working in Containers
Verify the container actually got an address in your sub-prefix:
```
docker run --rm alpine ip -6 addr
```
If the container's IPv6 is in a different range than expected, recheck `daemon.json` and confirm `systemctl restart docker` was run. If containers have addresses but cannot ping external IPv6 hosts, check that `ip6tables: true` is set in `daemon.json` and that the host itself has working outbound IPv6.
### Data Directory Permissions
If AIO complains it cannot write to the data directory:
```
chown 33:0 /data/ncdata
chmod 750 /data/ncdata
```
UID 33 corresponds to the `www-data` user inside the AIO Nextcloud container.
## Automation Script
The following script automates Steps 3 and 4 (daemon.json configuration and master container launch). It assumes Docker is already installed (Step 2) and the data partition is mounted at `/data` (Step 1). **Edit the `IPV6_PREFIX` variable to match your own routed IPv6 sub-prefix before running.**
```
#!/bin/bash
set -e
# === Edit this to match your environment ===
IPV6_PREFIX="2a01:4f8:13b:3004:1::/80"
DATA_DIR="/data/ncdata"
# ============================================
echo "Writing /etc/docker/daemon.json..."
cat > /etc/docker/daemon.json <
```
For example, to check the current Nextcloud status:
```
docker exec --user www-data nextcloud-aio-nextcloud php /var/www/html/occ status
```
If a command fails with permission errors (rare but possible for certain low-level operations), substitute `--user root`:
```
docker exec --user root nextcloud-aio-nextcloud php /var/www/html/occ
```
## Method 2: Enter the Container Interactively
Useful when exploring the container, running multiple commands in sequence, or troubleshooting paths.
1. SSH into your Docker host.
2. Enter the container as root: `docker exec -it --user root nextcloud-aio-nextcloud bash`
3. Navigate to the Nextcloud directory: `cd /var/www/html`
4. Run any `occ` command: `php occ `
5. Exit the container when finished: `exit`
## Common occ Commands
The following are the commands you will reach for most often. All can be run via Method 1 by replacing ``.
### Maintenance and Repair
- `maintenance:repair --include-expensive`: repair core data integrity issues (recommended after major upgrades).
- `maintenance:mode --on`: put Nextcloud into maintenance mode (users see a maintenance page).
- `maintenance:mode --off`: bring Nextcloud back online.
### Database Migrations
- `db:add-missing-indices`: add any indices required by recent Nextcloud or app updates.
- `db:add-missing-columns`: add missing columns introduced by updates.
- `db:add-missing-primary-keys`: add missing primary keys.
These three are idempotent and safe to run regularly; they output `Done.` when complete or nothing when there is no work to do.
### App Management
- `app:list`: list installed and disabled apps with versions.
- `app:enable `: enable an app.
- `app:disable `: disable an app.
### Configuration
- `config:system:get `: read a system configuration value (e.g. `version`, `trusted_domains`).
- `config:system:set --value=`: set a system configuration value.
### User Management
- `user:list`: list all Nextcloud users.
- `user:resetpassword `: reset a user's password (prompts interactively, so use Method 2 for this one).
### Encryption
- `encryption:status`: show current encryption status and active module.
- `encryption:recover-user `: recover encrypted files for a user using the recovery key.
### Storage Maintenance
- `files:scan --all`: rescan the file index for all users (use when files have been added or changed on disk outside Nextcloud).
- `versions:cleanup`: purge old file versions to reclaim storage.
- `trashbin:cleanup`: empty the trash bin for all users.
### Upgrades
- `upgrade`: run pending upgrade routines from the command line (useful when the web upgrader times out).
## Long-running Commands
Some `occ` commands can take a long time to complete on large installs, notably `encryption:encrypt-all`, `files:scan --all`, and `versions:cleanup` against many users. Put Nextcloud into maintenance mode before running these to prevent users from hitting the instance mid-operation:
```
docker exec --user www-data nextcloud-aio-nextcloud php /var/www/html/occ maintenance:mode --on
docker exec --user www-data nextcloud-aio-nextcloud php /var/www/html/occ files:scan --all
docker exec --user www-data nextcloud-aio-nextcloud php /var/www/html/occ maintenance:mode --off
```
## Troubleshooting
- **Permission Denied**: try `--user root` instead of `--user www-data`. Some low-level commands require root.
- **Command Not Found**: confirm the container name (`docker ps`) and the `occ` path (`/var/www/html/occ` in the official image). A wrong container name or a path from a non-Docker install is the usual cause.
# How to Upgrade PeerTube and Regenerate Thumbnails
Source: https://docs.noiz.ie/peertube/how-to-upgrade-peertube-and-regenerate-thumbnails/
**Last reviewed:** 27 July 2026, against PeerTube **8.1.5** (latest stable). This article reproduces the official PeerTube procedure for upgrading a classic (non-Docker) install on a Linux server and regenerating thumbnails afterwards. PeerTube releases frequently, so always cross-reference the current version of the official documentation before starting. Direct links to every section used in this guide are provided below.
### Official Documentation Reference
- Upgrade procedure (auto-upgrade script): [docs.joinpeertube.org/install/any-os#peertube-instance](https://docs.joinpeertube.org/install/any-os#peertube-instance)
- Reconciling production.yaml: [docs.joinpeertube.org/install/any-os#update-peertube-configuration](https://docs.joinpeertube.org/install/any-os#update-peertube-configuration)
- Updating nginx configuration: [docs.joinpeertube.org/install/any-os#update-nginx-configuration](https://docs.joinpeertube.org/install/any-os#update-nginx-configuration)
- Updating systemd service: [docs.joinpeertube.org/install/any-os#update-systemd-service](https://docs.joinpeertube.org/install/any-os#update-systemd-service)
- Restarting PeerTube: [docs.joinpeertube.org/install/any-os#restart-peertube](https://docs.joinpeertube.org/install/any-os#restart-peertube)
- Rollback procedure: [docs.joinpeertube.org/install/any-os#things-went-wrong](https://docs.joinpeertube.org/install/any-os#things-went-wrong)
- Regenerate thumbnails: [docs.joinpeertube.org/maintain/tools#regenerate-video-and-playlist-thumbnails](https://docs.joinpeertube.org/maintain/tools#regenerate-video-and-playlist-thumbnails)
- Prune storage: [docs.joinpeertube.org/maintain/tools#prune-filesystem-object-storage](https://docs.joinpeertube.org/maintain/tools#prune-filesystem-object-storage)
- Changelog (IMPORTANT NOTES per version): [github.com/Chocobozzz/PeerTube/blob/develop/CHANGELOG.md](https://github.com/Chocobozzz/PeerTube/blob/develop/CHANGELOG.md)
If you are running a Docker installation, the equivalent commands are documented at [docs.joinpeertube.org/install/docker](https://docs.joinpeertube.org/install/docker).
From PeerTube 8.1 onwards, image processing migrated to the `sharp` dependency, and regenerating thumbnails is explicitly recommended after upgrading.
## Before You Begin
You need:
- **Root SSH access** to the PeerTube server.
- **Your current PeerTube version**, which you can check with: `cat /var/www/peertube/peertube-latest/package.json | grep '"version"'`
- **The IMPORTANT NOTES section** of the official changelog reviewed for every version between your current one and the latest. This is non-negotiable. Major versions (6.3, 7.2, 8.0, 8.1) require manual migration scripts that must be run in sequence. See [the changelog](https://github.com/Chocobozzz/PeerTube/blob/develop/CHANGELOG.md).
- **The correct Node.js version** for the target PeerTube version. PeerTube 8.x requires Node `>= 20.19 < 21` or `>= 22.12 < 23`.
- **pnpm installed** if you are upgrading from a pre-8.0 version, since yarn was removed in 8.0. See the [dependencies guide](https://docs.joinpeertube.org/support/doc/dependencies).
## Back Up the Database
The upgrade script creates its own backup, but always take an independent SQL backup before any upgrade.
```
SQL_BACKUP_PATH="backup/sql-peertube_prod-$(date -Im).bak" && \
cd /var/www/peertube && sudo -u peertube mkdir -p backup && \
sudo -u postgres pg_dump -F c peertube_prod | sudo -u peertube tee "$SQL_BACKUP_PATH" >/dev/null
```
Note the timestamped filename, as you will need it if you have to roll back.
## Run the Upgrade Script
PeerTube ships an upgrade script that fetches the latest release, downloads it, installs node dependencies, and updates the `peertube-latest` symlink:
```
cd /var/www/peertube/peertube-latest/scripts && sudo -H -u peertube ./upgrade.sh
```
When prompted, enter the **PeerTube database user password** (not your system root password).
If `git` is installed on your system, the script also generates a `config/production.yaml.new` file that merges your existing configuration with any new keys introduced by the upgrade.
## Reconcile Configuration Files
Three configuration files need to be checked against the new release. None should be applied blindly, so review every change.
### 1. PeerTube Configuration
```
cd /var/www/peertube && sudo -u peertube diff config/production.yaml config/production.yaml.new
```
Review the output for conflict markers (`<<<<<<<`, `=======`, `>>>>>>>`) and resolve them by editing `production.yaml.new`. When the merged file is clean, replace your live config:
```
cd /var/www/peertube && sudo -u peertube cp config/production.yaml.new config/production.yaml
```
### 2. Nginx Configuration
Compare the nginx template between the two most recently installed versions:
```
cd /var/www/peertube/versions
diff -u "$(ls -t | head -2 | tail -1)/support/nginx/peertube" "$(ls -t | head -1)/support/nginx/peertube"
```
If the upstream template has changed, apply the equivalent edits to your live config at `/etc/nginx/sites-available/peertube`. Test and reload:
```
sudo nginx -t && sudo systemctl reload nginx
```
### 3. Systemd Service
```
cd /var/www/peertube/versions
diff -u "$(ls -t | head -2 | tail -1)/support/systemd/peertube.service" "$(ls -t | head -1)/support/systemd/peertube.service"
```
If the unit file has changed, apply the equivalent edits to `/etc/systemd/system/peertube.service` and reload systemd:
```
sudo systemctl daemon-reload
```
## Restart PeerTube and Watch the Logs
```
sudo systemctl restart peertube && sudo journalctl -fu peertube
```
Wait for the line:
```
Migrations finished. New migration version schema: NNNN
```
The schema number depends on which version you upgraded to. Do not proceed to migration scripts until this line appears.
## Run Migration Scripts
For every major version you skipped over, run the corresponding migration script. They are idempotent (safe to run multiple times), but they **must** be run in order.
| Upgrading From | Script to Run |
| --- | --- |
| Earlier than 6.3 | `peertube-6.3.js` |
| Earlier than 7.2 | `peertube-7.2.js` |
| Earlier than 8.0 | `peertube-8.0.js` |
| Earlier than 8.1 | `peertube-8.1.js` |
Each script is invoked like this (replace the filename):
```
cd /var/www/peertube/peertube-latest && \
sudo -u peertube NODE_CONFIG_DIR=/var/www/peertube/config NODE_ENV=production \
node dist/scripts/migrations/peertube-8.1.js
```
The 6.3 migration in particular may take a long time on instances with many federated videos.
## Regenerate Thumbnails
After every upgrade, and especially when moving to 8.1 or later, regenerate thumbnails to ensure they are processed at the correct sizes for the current release:
```
cd /var/www/peertube/peertube-latest; \
sudo -u peertube NODE_CONFIG_DIR=/var/www/peertube/config NODE_ENV=production npm run regenerate-thumbnails
```
The script reads each video's existing thumbnail file and reprocesses it. It does **not** generate thumbnails from scratch. If the source thumbnail file is missing from disk, the script logs an error for that video and continues with the rest.
If you see errors like `Thumbnail /path/to/file.jpg does not exist on disk`, those specific videos have lost their thumbnail files (commonly the result of an incomplete storage migration). The quickest fix is to open each affected video in the admin interface and upload a new thumbnail via **My Library โ Videos โ Update โ Thumbnail**.
## Prune Storage
Optionally clean up orphaned files left behind by interrupted transcodes, killed jobs, or deleted videos:
```
cd /var/www/peertube/peertube-latest; \
sudo -u peertube NODE_CONFIG_DIR=/var/www/peertube/config NODE_ENV=production npm run prune-storage
```
The script lists candidate files and asks for confirmation before deleting. Review the count first. If it reports thousands of files, stop and investigate before confirming.
## If Something Goes Wrong
To roll back to the previous version, replace `OLD_VERSION` and `SQL_BACKUP_PATH` with the actual values from your backup:
```
OLD_VERSION="vX.Y.Z" && SQL_BACKUP_PATH="backup/sql-peertube_prod-TIMESTAMP.bak" && \
cd /var/www/peertube && sudo -u peertube unlink ./peertube-latest && \
sudo -u peertube ln -s "versions/peertube-$OLD_VERSION" peertube-latest && \
sudo -u postgres pg_restore -c -C -d peertube_prod "$SQL_BACKUP_PATH" && \
sudo systemctl restart peertube
```
If you are on a Noiz managed PeerTube plan, you do not need to perform this procedure yourself. Contact Noiz support and the upgrade will be handled for you. If you self-manage your PeerTube install and run into trouble, Noiz support can also help on a billable basis.
# Best Practices for Mailing Lists to Avoid Spam Flagging
Source: https://docs.noiz.ie/email/best-practices-for-mailing-lists-to-avoid-spam-flagging/
If you send newsletters, announcements, or any bulk email to a mailing list, the biggest risk is not that your message looks bad, but that mailbox providers decide it is spam and route it to the junk folder, or block it outright. Once your domain or sending address earns a poor reputation it is slow to recover, so it is far easier to protect it from the start. This guide sets out the practices that keep list mail landing in the inbox and keep your domain off blocklists, whether you send from your own mail client, a script on your Noiz hosting, or a third-party newsletter service.
**Last reviewed:** 27 July 2026. Anti-spam standards and the bulk-sender rules enforced by the major mailbox providers change over time, so this guide is reviewed regularly. It complements, and does not replace, the sender guidelines published by the mailbox providers linked below.
### Official Documentation Reference
- [Google: Email sender guidelines (Gmail)](https://support.google.com/mail/answer/81126)
- [Microsoft: Outlook.com sending policies](https://sendersupport.olc.protection.outlook.com/pm/policies.aspx)
- [RFC 8058: One-Click List-Unsubscribe (List-Unsubscribe-Post header)](https://www.rfc-editor.org/rfc/rfc8058)
## Get permission before you send
The single most important rule is that everyone on your list has actively asked to be there. Sending to people who never opted in is the fastest way to generate spam complaints, and a rising complaint rate is exactly what mailbox providers watch for.
- **Use a double opt-in.** The subscriber first enters their address, then receives a confirmation email and must click the confirmation link before they are added to the list. This proves the address belongs to a real person who genuinely wants your mail, and it stops mistyped addresses, a colleague signing up someone else, or a bot from poisoning your list.
- **Do not buy, rent, or scrape lists.** Purchased and harvested addresses have not consented to hear from you, tend to contain spam traps, and will damage your sender reputation quickly. Grow your list from people who chose to join.
- **Keep proof of consent.** Record when and how each subscriber opted in. Under South Africa's Protection of Personal Information Act (POPIA), unsolicited direct marketing generally requires the recipient's consent, and being able to show that consent protects you if a recipient ever complains.
## Make it easy to unsubscribe
An easy, honest way out lowers complaints, because a reader who can leave in one click does not need to hit the spam button to make your mail stop.
- **Put a clear unsubscribe link in every message,** usually in the footer. It must be obvious and must work.
- **Add a one-click unsubscribe header.** Modern bulk mail should include the `List-Unsubscribe` and `List-Unsubscribe-Post` headers so mail clients can show a native one-click unsubscribe button. Most reputable newsletter platforms add these for you; if you send with your own script, set them yourself.
- **Honour removals immediately.** Stop sending to an address as soon as it unsubscribes. Continuing to mail someone who has opted out is both a reputation risk and, in many jurisdictions, unlawful.
## Authenticate your sending domain
Authentication tells receiving servers that mail claiming to be from your domain really is from you. Without it, list mail is very likely to be filtered or rejected, and the major providers now require it for bulk senders. Set up all three of the following open-standard DNS records for the domain you send from:
- **SPF** (Sender Policy Framework) lists which servers are allowed to send mail for your domain.
- **DKIM** (DomainKeys Identified Mail) adds a cryptographic signature so the receiver can confirm the message was not altered and really came from your domain.
- **DMARC** (Domain-based Message Authentication, Reporting and Conformance) tells receivers what to do when SPF or DKIM fails, and sends you reports so you can spot abuse of your domain.
If you send through a third-party newsletter service, follow their instructions to add the SPF and DKIM records for their sending infrastructure to your DNS. If you are unsure how these records should look for a domain hosted with Noiz, contact Noiz support and the team will help you set them up correctly.
## Keep your list clean
A stale list quietly wrecks your reputation, because dead addresses turn into bounces and spam traps while disengaged readers are more likely to complain.
- **Remove hard bounces promptly.** An address that returns a permanent failure no longer exists; repeatedly mailing it signals to providers that you do not maintain your list.
- **Watch your spam-complaint rate.** Gmail and other providers expect bulk senders to keep complaints well below **0.3%** of messages sent. Sustained complaints above that level lead to throttling or blocking.
- **Prune inactive subscribers.** Consider removing or re-confirming people who have not opened your mail in a long time. A smaller engaged list outperforms a large indifferent one.
- **Take abuse seriously.** If you run a list on behalf of others, make sure it cannot be used to send unsolicited mail, and act on any complaints you receive.
## Write mail that does not look like spam
Spam filters score the content of every message, and a few habits reliably push that score up. Small changes here keep legitimate mail out of the junk folder.
- **Keep formatting simple.** Multiple font sizes and clashing colours are common in spam, so filters treat them as a warning sign. Use consistent, restrained formatting.
- **Avoid large blocks of blank space.** Big empty gaps, often left behind when copying from a word processor, raise your spam score in most scoring systems.
- **Balance images and text.** An email that is one big image with almost no text is a classic spam pattern. Include real text, and always set meaningful `alt` text on images in case they do not load.
- **Write honest subject lines.** Avoid ALL CAPS, rows of exclamation marks, and misleading claims. The subject should match what is actually in the message.
- **Be careful with links and attachments.** Link only to reputable destinations, avoid URL shorteners that hide the real address, and do not attach executable files.
## Send at a steady, predictable rate
Reputation is built on consistency. Suddenly sending a large volume from a domain or address that normally sends very little looks like a compromised account, and providers may throttle or block the burst. If you are starting a new list or sending from a new domain, build up your volume gradually over days or weeks rather than blasting everyone at once, and try to send on a regular, predictable schedule.
## Need a hand?
If your list mail is landing in spam, or you want help configuring SPF, DKIM, and DMARC for a domain hosted with Noiz, open a support ticket from your Noiz client area and the team will help you diagnose the problem and get your mail delivered.
# How to Add an Email Account in Mozilla Thunderbird
Source: https://docs.noiz.ie/email/how-to-add-an-email-account-in-mozilla-thunderbird/
This guide shows you how to add a Noiz mailbox to Mozilla Thunderbird, the free desktop email client for Windows, macOS and Linux, so that you can send and receive mail for your own domain from your computer. You will see both ways to set an account up: the automatic path, where Thunderbird tries to work the settings out for you, and the manual path, where you type the exact Noiz server settings in yourself. The manual path matters here, because a mailbox on a custom domain such as `yourdomain.com` very often does not autoconfigure, so knowing the correct settings saves a lot of guesswork. This article is for Noiz email clients whose mailbox lives on the Noiz mail platform.
Along the way you will also decide between **IMAP** and **POP**, the two protocols Thunderbird can use to fetch your mail. For almost everyone on Noiz hosting the answer is IMAP, and the reasoning is explained below so the choice is yours to make with confidence.
**Last reviewed:** 27 July 2026, against Mozilla Thunderbird **140** (latest stable Release and ESR). This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below. Thunderbird updates frequently and the wording of buttons or the layout of the Account Setup screen can vary slightly between the monthly Release and the ESR (Extended Support Release), so if a screen differs from what you see here, the field names and values remain the same even when their arrangement moves.
### Official Documentation Reference
- [Thunderbird Support (Mozilla)](https://support.mozilla.org/en-US/products/thunderbird): the official support hub for Thunderbird, kept current with the latest release.
- [Automatic Account Configuration](https://support.mozilla.org/en-US/kb/automatic-account-configuration): how Thunderbird tries to discover mail settings for you, and why it sometimes cannot.
- [Manual Account Configuration](https://support.mozilla.org/en-US/kb/manual-account-configuration): the reference for every field in the manual setup form, including protocol, ports and connection security.
## Prerequisites
- The mailbox already exists on the Noiz mail server. If you have not created it yet, do that first: see [How to Create a Mailbox in Plesk](/plesk/how-to-create-an-email-address-in-plesk/). Thunderbird can only connect to a mailbox that has already been provisioned.
- You know the full email address, for example `you@yourdomain.com`, and the password that was set when the mailbox was created. The username for Noiz mail is always the full email address, not just the part before the `@`.
- Thunderbird is installed on your computer. Download it from the [official Thunderbird website](https://www.thunderbird.net/) and keep it up to date, so you get current security fixes and the modern setup screen described here.
- A working internet connection, and a domain whose mail is hosted at Noiz. If your domain was only recently pointed to Noiz, allow DNS changes time to take effect before the mail hostname will resolve.
## IMAP or POP: Choose the Right Protocol
Before you add the account, decide how Thunderbird should collect your mail. The two options are not interchangeable, and switching later means removing and re-adding the account, so it is worth a moment now.
- **IMAP** keeps your mail on the Noiz server and mirrors it to Thunderbird. Folders, read and unread status, and every message stay in sync across all your devices. Read a message on your phone and it shows as read in Thunderbird; file it into a folder on your laptop and that folder appears everywhere. This is the right choice for almost everyone, and it is what Noiz recommends.
- **POP** (POP3) downloads your mail to one computer and, by default, removes it from the server. It suits a single device with no need for webmail or a second device, and it can help if you deliberately want mail stored only on your own machine. Its weakness is that your other devices and Noiz webmail will not see mail that a POP client has already pulled down.
The practical rule: if you check mail on more than one device, or ever use webmail, choose **IMAP**. Only choose POP if you have a specific reason to keep mail on a single computer. The rest of this guide uses IMAP as the example; the manual settings table also lists the POP values in case you need them.
## The Noiz Mail Settings
These are the settings a Noiz mailbox uses. Wherever you see `yourdomain.com`, replace it with your own domain. Keep this table to hand: the manual setup in the next section is simply a matter of typing these values into the matching fields.
| Setting | Incoming (IMAP, recommended) | Outgoing (SMTP) |
| --- | --- | --- |
| Server hostname | `mail.yourdomain.com` | `mail.yourdomain.com` |
| Port | `993` | `465` |
| Connection security | SSL/TLS | SSL/TLS |
| Authentication method | Normal password | Normal password |
| Username | Your full email address, e.g. `you@yourdomain.com` | Your full email address, e.g. `you@yourdomain.com` |
| Password | The mailbox password | The same mailbox password |
If you decide on POP instead of IMAP, the only change is the incoming server: use the same hostname `mail.yourdomain.com` with port `995` and SSL/TLS. The outgoing SMTP settings are identical either way.
Two points that trip people up on custom domains:
- The username is the **whole address**, including `@yourdomain.com`. A username of just `you` will fail authentication.
- Both incoming and outgoing use **SSL/TLS** on the encrypted ports (993, 465 and 995). Do not use the older unencrypted ports (143 for IMAP, 110 for POP, 25 or 587 without encryption); Noiz mail is secured throughout.
## Open the Account Setup Screen
If this is the very first time you have opened Thunderbird, the Account Setup screen appears on its own and you can skip straight to the next section. Otherwise, open it manually:
1. Click the **โฐ** menu button (three horizontal lines) at the top right of the Thunderbird window.
2. Choose **New**, then **Existing Mail Accountโฆ**
The same screen is reachable from **Account Settings**: open the **โฐ** menu, choose **Account Settings**, then at the bottom of the left panel click **Account Actions** and **Add Mail Account**. Either route opens the Account Setup tab.
## Enter Your Details
On the Account Setup tab, fill in the three fields at the top:
1. **Your full name**: the name you want recipients to see, for example `Jane Smith`.
2. **Email address**: your full Noiz email address, for example `you@yourdomain.com`.
3. **Password**: the mailbox password. Leave **Remember password** ticked if you want Thunderbird to store it, so you are not prompted each time.
## Path A: Try Automatic Setup First
Click **Continue**. Thunderbird now tries to discover the settings by checking its own provider database and by looking for a configuration file published at your domain. If it succeeds, it shows one or more **Available configurations**, usually offering both an **IMAP** and a **POP3** option.
1. Select **IMAP** (already selected by default when offered).
2. Click **Done**.
3. Confirm the discovered values against the Noiz settings table above. In particular check that the hostname is `mail.yourdomain.com` and that the ports are 993 (incoming) and 465 (outgoing) on SSL/TLS.
**Why automatic setup often does not work on a custom domain.** Thunderbird's automatic discovery relies on either a known large provider or a small configuration file that the domain publishes for the purpose. Most custom domains hosted on a standard mail platform do not publish that file, so Thunderbird either finds nothing or guesses settings that then fail to connect. This is expected and is not a fault with your mailbox. When automatic setup fails, or offers settings that do not match the table above, switch to the manual path below. It is completely reliable because you supply the exact values yourself.
## Path B: Configure Manually (Recommended for Custom Domains)
From the Account Setup tab, after entering your name, address and password, click **Configure manually**. This expands the full set of server fields. Enter the values exactly as follows.
### Incoming Server
1. **Protocol**: choose **IMAP** (or **POP3** if you deliberately chose POP earlier).
2. **Hostname**: `mail.yourdomain.com`
3. **Port**: `993` for IMAP (or `995` for POP3).
4. **Connection security**: **SSL/TLS**.
5. **Authentication method**: **Normal password**.
6. **Username**: your full email address, for example `you@yourdomain.com`.
### Outgoing Server (SMTP)
1. **Hostname**: `mail.yourdomain.com`
2. **Port**: `465`
3. **Connection security**: **SSL/TLS**.
4. **Authentication method**: **Normal password**.
5. **Username**: your full email address, the same as the incoming username.
### Test and Finish
1. Click **Re-test**. Thunderbird connects to the incoming and outgoing servers with the values you entered and confirms they work. A green message reports that the settings were verified.
2. Click **Done**. Thunderbird creates the account and begins downloading your folders and messages.
3. If a confirmation screen offers to link other services or set up encryption, you can safely click **Finish** now and revisit those later.
Your Noiz mailbox now appears in the folder list on the left. Send yourself a short test message and reply to it to confirm that both sending and receiving work end to end.
## Troubleshooting
- **Symptom: "Unable to log in at server" or repeated password prompts.** The most common cause is a username that is not the full address. Open the **โฐ** menu > **Account Settings**, check **Server Settings** (incoming) and **Outgoing Server (SMTP)**, and make sure both usernames are the complete `you@yourdomain.com`. Then confirm the password by signing in to Noiz webmail with the same details; if webmail also rejects the password, reset it where the mailbox was created.
- **Symptom: Thunderbird cannot find the settings automatically.** This is normal for a custom domain. Use **Path B: Configure Manually** above and type the Noiz settings in yourself.
- **Symptom: a security or certificate warning about the mail host.** Make sure **Connection security** is **SSL/TLS** on ports 993, 465 or 995, and that the hostname is spelled exactly `mail.yourdomain.com`. A warning that the certificate name does not match usually means the domain's mail is not yet fully live on Noiz, or DNS has not finished pointing to the mail server. If your domain has only recently moved to Noiz, wait for DNS to take effect and try again, or contact Noiz support for the correct hostname to use in the interim.
- **Symptom: mail is received but will not send.** This is an outgoing (SMTP) problem. Check that the SMTP server uses port `465`, **SSL/TLS**, **Normal password**, and your full email address as the username. Some networks block outgoing mail ports; if sending fails only on a particular network, try another connection to confirm.
- **Symptom: the incoming server host does not resolve.** Confirm the domain's mail is hosted at Noiz and that DNS has propagated. Until then, `mail.yourdomain.com` may not point anywhere. Noiz support can confirm the status of your mail DNS.
If you work through the settings above and the account still will not connect, open a support ticket with the Noiz support team. Include the email address, whether the problem is with sending, receiving or both, and a screenshot of any error message Thunderbird shows. On Noiz managed plans the support team can verify the mailbox and its settings from the server side and point you to the exact value to correct.
# How to Check for New Email in Mozilla Thunderbird
Source: https://docs.noiz.ie/email/how-to-check-for-new-email-in-mozilla-thunderbird/
Mozilla Thunderbird is a free, open-source email client for Windows, macOS, and Linux. This guide shows you how to force Thunderbird to check your Noiz mailbox for new mail on demand, how to control how often it checks on its own, and what to do when a message you know was sent still refuses to appear. Thunderbird calls a manual check **Get Messages**; you may also see it described as polling, fetching, or receiving mail.
**Last reviewed:** 27 July 2026, against Thunderbird **153 ESR** (the current Extended Support Release; the 140 ESR series remains supported during the changeover and behaves identically for everything described here). This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below.
### Official Documentation Reference
- [Thunderbird Help (support.mozilla.org)](https://support.mozilla.org/en-US/products/thunderbird): the authoritative support knowledge base.
- [Thunderbird ESR](https://support.mozilla.org/en-US/kb/thunderbird-esr): what the Extended Support Release channel is and which version you should be running.
- [Manual account configuration](https://support.mozilla.org/en-US/kb/manual-account-configuration): server settings reference, useful if a failed check turns out to be a connection problem.
## Prerequisites
- Thunderbird installed and your mailbox already added. If it is not, follow [How to set up your existing email address in Thunderbird](/email/how-to-set-up-email-in-thunderbird/) first.
- Your full email address and mailbox password, in case Thunderbird asks you to re-authenticate.
- A working internet connection. Thunderbird shows cached mail happily while offline, which is exactly why an offline session can look like a mail delivery failure.
## Check for New Mail Right Now
1. Open Mozilla Thunderbird. 
2. Look at the **Folders** pane on the left. Each account you have added is listed by its email address. Click the arrow beside an account, or double-click the account name, to expand it and reveal **Inbox**, **Drafts**, **Sent**, **Spam**, and **Trash**. 
3. Click the account or its **Inbox** so it is selected. Thunderbird checks the account you have selected, not every account at once, so this step matters when you have more than one mailbox set up.
4. Click **Get Messages** in the toolbar above the message list. To check a different account without selecting it first, click the small arrow beside the button and pick either a specific account or **Get All New Messages**.
5. Alternatively, right-click the account name in the **Folders** pane and choose **Get Messages**. The same command also lives under **File โ Get New Messages For**.
**Keyboard shortcuts:** press `F5` to check the currently selected account, or `Shift` + `F5` to check every account. On a Mac you may need to hold `fn` as well, depending on your keyboard settings.
**If the Get Messages button is missing:** it lives in the unified toolbar, which is customisable and can be emptied by accident. Right-click an empty part of the toolbar, choose **Customise**, and drag **Get Messages** back into place.
## How Often Thunderbird Checks on Its Own
You rarely need to click **Get Messages** at all. Out of the box Thunderbird checks when you open the program and then roughly every 10 minutes after that. Both behaviours are per account and both can be changed.
1. Click the menu button (**โก**) at the top right and choose **Account Settings**, or right-click the account in the **Folders** pane and choose **Settings**.
2. Select **Server Settings** beneath the account you want to change.
3. Under **Server Settings**, tick **Check for new messages at startup** and **Check for new messages every [ ] minutes**, and set the interval you want.
4. For an IMAP account, also tick **Allow immediate server notifications when new messages arrive**. This turns on IMAP IDLE, an open standard where the Noiz mail server pushes a notification the moment a message lands, so new mail usually appears within a second or two no matter what polling interval you set.
**Why the polling interval is not the answer:** people who feel their mail is slow often drop the interval to 1 minute. With IMAP IDLE enabled that gains you nothing, because push already beats any poll, and a very short interval across several accounts means constant reconnections that can trip server-side connection limits and slow everything down. Leave the interval at 5 to 10 minutes and rely on IDLE for immediacy.
**POP3 accounts behave differently:** POP3 has no push mechanism, so the polling interval genuinely is your check frequency. POP3 also downloads mail to one machine, which means a message already collected on your phone or another computer may no longer be on the server for Thunderbird to fetch. If you read mail on more than one device, use IMAP.
## Troubleshooting: Mail That Will Not Appear
Before you change anything in Thunderbird, log in to your Noiz webmail and look for the message there. Webmail reads the mailbox directly on the server, so it settles the question of whether the message has been delivered at all. If webmail has it and Thunderbird does not, the fault is on your desktop. If webmail does not have it either, the message has not reached the server yet and nothing in Thunderbird will change that.
- **Symptom: Get Messages does nothing and no error appears.** Thunderbird is in offline mode. Go to **File โ Offline** and untick **Work Offline**, then try again.
- **Symptom: one account updates and the others do not.** You checked only the selected account. Use the arrow beside **Get Messages** and choose **Get All New Messages**, or press `Shift` + `F5`.
- **Symptom: the Inbox updates but a subfolder never does.** By default Thunderbird only polls the Inbox. Right-click the folder, choose **Properties**, and tick **When getting new messages for this account, always check this folder**.
- **Symptom: mail stopped arriving after a password change.** Thunderbird prompts once for the new password, and if that prompt is dismissed it can stop checking quietly. Click **Get Messages** to trigger the prompt again and enter the current mailbox password.
- **Symptom: the expected message is nowhere in the Inbox.** Check the **Spam** or **Junk** folder, and check whether a message filter (in Thunderbird, or a server-side rule) has moved it into another folder.
- **Symptom: an error about connecting to the server.** Confirm the incoming server settings match your Noiz mailbox: IMAP on port `993` with SSL/TLS, with your username set to your full email address, using the mail hostname from your welcome email (commonly `mail.yourdomain.com`, which you replace with your own domain). A firewall, VPN, or mobile hotspot blocking port 993 produces the same symptom, so test on another network before assuming the mailbox is at fault.
- **Symptom: the folder list looks wrong or folders are missing.** Right-click the account, choose **Subscribe**, and confirm the folders you expect are ticked. Thunderbird only synchronises folders you are subscribed to.
## Summary
Click **Get Messages** (or press `F5`) for an immediate check of the selected account, and `Shift` + `F5` for every account. For day-to-day use, enable immediate server notifications on your IMAP accounts and leave the polling interval alone, so new mail lands in Thunderbird as soon as it reaches the Noiz mail server.
If mail is missing from webmail as well as from Thunderbird, the problem is on the delivery side rather than in your email client. Open a ticket from your Noiz client area with the sender's address and the approximate time the message was sent, and Noiz support can trace the delivery for you.
# How to Check for New Email on iPhone or iPad
Source: https://docs.noiz.ie/email/how-to-check-for-new-email-on-iphone-or-ipad/
This guide shows you how to check for new email in the Mail app on an iPhone or iPad, and how to control how often your device looks for new messages. Checking for mail is sometimes called refreshing, syncing or fetching your inbox: they all mean the same thing, asking the mail server whether anything new has arrived. You will learn the pull-down gesture for an instant manual check, the difference between push and fetch delivery, and where to set the fetch schedule so new mail arrives as quickly as you need it to.
**Last reviewed:** 27 July 2026, against iOS and iPadOS **26** (latest stable). This article reproduces the official Apple procedures for checking email in the Mail app and adjusting the Fetch New Data settings. Apple releases updates frequently, so always cross-reference the current version of the official documentation before starting: direct links to every section used in this guide are provided below.
### Official Documentation Reference
- [Check your email in Mail on iPhone (iPhone User Guide, iOS 26)](https://support.apple.com/en-gb/guide/iphone/iph461684497/ios)
- [Check your email in Mail on iPad (iPad User Guide, iPadOS 26)](https://support.apple.com/en-gb/guide/ipad/ipad99a3ef9e/ipados)
- [Change your Mail settings on iPhone (iPhone User Guide, iOS 26)](https://support.apple.com/en-gb/guide/iphone/iph80dabb18b/ios)
- [If you can't receive email on your iPhone or iPad (Apple Support)](https://support.apple.com/en-gb/102578)
## Prerequisites
- An email account already added to the Mail app on your iPhone or iPad. Mail cannot check a mailbox that has not been set up on the device.
- A working mailbox on your hosting plan, for example `you@yourdomain.com` (replace with your own address). If you host with Noiz and have not created one yet, see [How to Create an Email Address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/).
- An active internet connection on the device, over Wi-Fi or mobile data.
- Your mailbox password to hand, in case Mail prompts you to re-enter it.
## Check for New Email Manually
The quickest way to check for new mail at any moment is to refresh the message list by hand. This works regardless of your fetch or push settings.
### Open the Inbox You Want to Check
1. Open the **Mail** app on your iPhone or iPad.
2. If you are viewing an individual message, tap the back arrow in the top-left corner until you see the **Mailboxes** list.
3. Tap **All Inboxes** to check every account at once, or tap the inbox for a single account, for example the one holding `you@yourdomain.com`.
### Refresh the Message List
1. Touch the message list, drag it downwards until a spinning refresh indicator appears at the top, then release.
2. Mail contacts the server and downloads anything new. New messages appear at the top of the list, and the status text at the bottom of the screen updates to show when the mailbox was last checked.
3. If nothing appears, there is simply no new mail waiting on the server. You can confirm this by logging in to webmail from another device and comparing the two.
Mail also checks for new messages automatically every time you open the app, even when the fetch schedule is set to **Manually**.
## Understand Push and Fetch
Between manual checks, your device receives mail in one of two ways:
- **Push**: the mail server sends new messages to your device the moment they arrive. Push is only available if your email service supports it. Most standard hosting mailboxes use the IMAP protocol, which does not offer push to iOS devices, so those accounts fall back to fetch. This is normal behaviour, not a fault.
- **Fetch**: your device contacts the server on a schedule and asks whether anything new has arrived. You choose the schedule: every 15 minutes, every 30 minutes, hourly, automatically or manually.
By default, Apple sets fetch to **Automatically**, which only checks in the background while the device is charging and connected to Wi-Fi. If your mail seems to arrive only when you open the Mail app, this default is almost always the reason, and switching to a timed schedule fixes it. A shorter fetch interval uses slightly more battery, but for most people **Every 15 Minutes** is the best balance between speed and battery life.
## Change How Often Your Device Checks for Mail
### Open the Fetch New Data Settings
1. Open the **Settings** app.
2. Tap **Apps**, then tap **Mail**. On iOS 17 and earlier, Mail appears directly in the main Settings list instead of under Apps.
3. Tap **Mail Accounts**, then tap **Fetch New Data**.
### Choose a Delivery Method and Schedule
1. At the top of the screen, turn on **Push** if you want push delivery for accounts that support it. If your account only supports fetch, this toggle makes no difference to it.
2. Under the list of accounts, choose a fetch schedule: **Automatically**, **Manually**, **Hourly**, **Every 30 Minutes** or **Every 15 Minutes**. For prompt delivery to a standard hosting mailbox, choose **Every 15 Minutes**.
3. Optionally, tap an individual account in the list to set a different method for that account alone, for example push for one account and fetch for another.
Remember that **Automatically** only fetches in the background while the device is charging and on Wi-Fi, and **Manually** only checks when you open the Mail app or pull down to refresh.
## Check Your Notification Settings
If new mail arrives but you are never alerted, the fetch schedule may be fine and the notifications switched off instead.
1. Open the **Settings** app and tap **Notifications**.
2. Tap **Mail**.
3. Adjust the **Alerts**, **Sounds** and **Badges** options to suit you.
By default, the unread count badge on the Mail icon only reflects messages in the Primary category. To count every unread message, tap **Customise Notifications** on the same screen, then turn on **All Unread Messages**.
## Troubleshooting
**Mail only arrives when you open the Mail app**: the fetch schedule is set to Automatically or Manually. Go to **Settings** > **Apps** > **Mail** > **Mail Accounts** > **Fetch New Data** and choose a timed schedule such as **Every 15 Minutes**.
**New mail is delayed by up to an hour**: the fetch schedule is set to Hourly. Choose a shorter interval on the same Fetch New Data screen.
**There is no Push option for your account**: your email service delivers mail over IMAP, which does not support push on iOS. The account uses fetch instead, so set a 15-minute schedule for near-immediate delivery.
**A message arrived but you cannot see it in the inbox**: Mail in iOS 26 can sort incoming messages into categories such as Primary, Transactions, Updates and Promotions. Check the other category tabs at the top of the inbox, or tap the more button in the top-right corner of the inbox and switch to **List View** to see everything in one list.
**Mail shows on webmail but not on the device**: confirm the device has an internet connection, pull down to refresh, and re-enter your password if Mail prompts for it. If it still fails, follow Apple's steps in [If you can't receive email on your iPhone or iPad](https://support.apple.com/en-gb/102578) to remove the account and add it again, after confirming your messages are safe on the server.
**Mail keeps asking for your password**: the stored password no longer matches the mailbox password on the server. Check the password by logging in to webmail, then enter the working password on the device.
Everything in this guide happens on your own device, so it is quick to work through yourself. If your mailbox still does not receive new email after following these steps, the problem may be on the server side: open a support ticket with the Noiz support team, include your email address and a description of what you have tried, and the team will investigate the mailbox for you.
# How to Create a Global Email Filter in cPanel
Source: https://docs.noiz.ie/email/how-to-create-a-global-email-filter-in-cpanel/
You cannot stop spam reaching the mail server entirely, but you can decide what happens to it once it arrives. A **global email filter** in cPanel lets you match messages on their content and then discard, redirect, or file them automatically. Because it is created at account level, one global filter applies to *every* mailbox on the cPanel account at once, so you do not have to repeat the same rule for each address.
Global email filters are sometimes called *account-level filters*. They are different from the per-mailbox **Email Filters** tool, which affects only a single email account. Use a global filter when you want the same rule to protect the whole account; use a per-mailbox filter when only one address needs it.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM interface (Jupiter theme). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [Global Email Filters](https://docs.cpanel.net/cpanel/email/global-email-filters/): the account-level interface used in this guide.
- [Email Filters](https://docs.cpanel.net/cpanel/email/email-filters/): filters for a single mailbox only.
- [How to Configure Email Filters](https://docs.cpanel.net/knowledge-base/email/how-to-configure-email-filters): the full list of rule fields, comparison operators and actions.
## Prerequisites
- A hosting account with cPanel access (included with all Noiz cPanel plans).
- Your cPanel sign-in details.
## Open Global Email Filters
1. Log in to your cPanel account.
2. In the **Email** section, click **Global Email Filters**.

## Create a New Filter
1. Click **Create a New Filter**.
2. Enter a name for the filter in the **Filter Name** box. Choose something you will recognise later, for example `Discard Lottery Scams`.
## Define the Rule
A rule has three parts: the part of the message to inspect, how to compare it, and the value to match. To act on any message whose body contains a word such as **Lottery**, select **Body** in the first list, select **contains** in the second list, and type the word in the value box.

You can inspect other parts of the message instead of the body, such as **From**, **Subject** or **To**, and you can use operators such as **equals**, **begins with**, **ends with** or **matches regex** for more precise matches. Click **+** to add further conditions when you need to match on more than one criterion.
## Choose the Action
From the **Actions** drop-down, choose what happens to a matching message. To silently delete it, select **Discard Message**, then click **Create**.
**Before you discard:** **Discard Message** deletes the email with no bounce and no notice to the sender, so a legitimate message caught by an over-broad rule is gone without trace. For spam handling it is often safer to choose **Deliver to Folder** and send matches to a dedicated folder you can review, or **Redirect to Email** to route them elsewhere. Use **Discard Message** only once you are confident the rule matches spam and nothing else.
## How Global Filters Are Applied
- A global filter runs against mail for every mailbox on the account, so a single rule covers all current and future addresses.
- Rules are processed from the top of the list downward. Order matters: a message that has already been discarded by an earlier rule is not seen by later ones.
- Global filters run before any per-mailbox **Email Filters**, which are evaluated afterwards for the specific address.
## Test the Filter
The Global Email Filters page includes a **Filter Test** box. Paste a sample message into it and run the test to confirm the rule behaves as expected before you rely on it. This is the safest way to check a discard rule, because you can prove what it catches without losing real mail.
## Troubleshooting
**Symptom**: legitimate mail has stopped arriving. Review your global filters for an over-broad rule (for example **Body** **contains** a very common word) and either narrow the condition or change the action from **Discard Message** to **Deliver to Folder** so you can inspect what is being caught.
**Symptom**: the filter only affects one mailbox. You may have created it under the per-mailbox **Email Filters** tool instead of **Global Email Filters**. Recreate it under **Global Email Filters** to apply it account-wide.
If you are on a Noiz managed plan and want help building or tuning spam filters for your account, contact Noiz support and the team will assist.
# How to Create a Professional HTML Email Signature in Thunderbird
Source: https://docs.noiz.ie/email/how-to-create-a-professional-html-email-signature-in-thunderbird/
This guide shows you how to design and install a professional HTML email signature in Mozilla Thunderbird: a tidy footer carrying your name, job title, company, phone number, website and a small logo. You will get a clean, copy-paste-ready signature template built the way email signatures actually need to be built (a table layout with inline styles), two reliable ways to install it in Thunderbird, and clear advice on how to handle the logo image so your signature looks right for the people who receive it. It is written for Noiz clients whose mailbox is already set up in Thunderbird.
One quick point of terminology first, because the word "signature" means two different things in email. This article is about the **visual footer** appended to the bottom of your messages. It is not about a **digital signature**, the cryptographic OpenPGP/S-MIME feature (built into Thunderbird since version 78) that proves a message genuinely came from you. Those are separate features and this guide covers only the visual footer.
**Last reviewed:** 27 July 2026, against Thunderbird **140** (latest stable). This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below. Menu labels shift slightly between the monthly Release channel and the Extended Support Release (ESR), and between operating systems, so if a control is named a little differently on your machine, look for the closest match.
### Official Documentation Reference
- [Signatures (Mozilla Support)](https://support.mozilla.org/en-US/kb/signatures): the official article on adding a plain-text or HTML signature and on attaching a signature from a file.
- [Thunderbird Support home (Mozilla Support)](https://support.mozilla.org/en-US/products/thunderbird): the official hub for account, composition and interface topics, and the place to confirm the wording in your exact version.
- [Signatures (MozillaZine Knowledge Base)](https://kb.mozillazine.org/Signatures): a long-standing community reference that goes deep on file-based HTML signatures and how referenced images are embedded.
## Prerequisites
- Your mailbox is already added in Thunderbird. If it is not, follow [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/) first. On the Noiz platform the account uses IMAP `mail.yourdomain.com` on port `993` (SSL/TLS) and SMTP `mail.yourdomain.com` on port `465` (SSL/TLS), with your full email address as the username. HTML signatures work the same regardless of those settings.
- The details you want in the signature: name, job title, company name, phone number, website address and email address.
- A logo file, ideally a small PNG (transparent background) or JPG. See [Handling the logo image](#logo) for sizing.
- Basic comfort with copying and pasting a block of text. You do not need to understand HTML to use the template below; you only replace the words between the tags.
## Two Ways to Install an HTML Signature
Thunderbird gives you two routes to an HTML signature, and the difference matters mainly for how your logo travels to recipients:
- **Method 1: Paste HTML into the signature box.** You tick a **Use HTML** box in Account Settings and paste the signature markup straight into the text field. This is the quickest route. A logo is referenced by its web address, so the image lives on a server and each recipient's mail app fetches it when they open your message.
- **Method 2: Attach the signature from a file.** You save the signature as an `.html` file on your computer and point Thunderbird at it. This route lets you **embed** the logo, so a copy of the image is sent inside every message and always displays, even when the recipient blocks remote images.
Both use the same template. Pick the method after you have read [Handling the logo image](#logo), because that decision (host the logo versus embed it) is the one that actually shapes how your signature looks in the wild.
## The Professional Signature Template
Here is the template. It uses a `
` for layout and **inline styles** on every element, which is deliberate: mail apps such as Outlook, Gmail and Apple Mail strip out stylesheets and are unreliable with modern CSS layout, but they render simple tables and inline styles consistently. This is the single most important reason home-made signatures look perfect in Thunderbird yet fall apart in a recipient's inbox, and this template avoids it.
Copy everything between the first `
```
### What to Replace
Change only these values and leave every tag and style alone:
- `Your Full Name`, `Your Job Title`, `Your Company Name`: the three text lines.
- The logo `src`: for Method 1 use the full web address of your hosted logo, for example `https://www.yourdomain.com/img/logo.png`; for Method 2 use a plain filename such as `logo.png` (explained below). Keep the `alt` text as your company name so the logo still makes sense when the image cannot load.
- The phone number: appears twice, once as the dialable link `tel:+27210000000` (digits and a leading `+` only, no spaces) and once as the readable `+27 21 000 0000`.
- The website: appears in `href="https://www.yourdomain.com"` and as the visible `www.yourdomain.com`.
- The email: appears in `href="mailto:you@yourdomain.com"` and as the visible `you@yourdomain.com`.
- **Optional, the accent colour.** The hex value `#1a7f5a` appears three times (the vertical bar, the job title and the website link). Replace all three with your brand colour to match your identity. Keep the other colours (`#1a1a1a` for headings, `#2b2b2b` for body text) for readability.
`yourdomain.com`, the sample phone number and the colours are all placeholders shown as examples; swap in your own. Resist the temptation to add more: two or three tidy lines and a small logo read as far more professional than a wall of icons, quotes and disclaimers.
## Method 1: Paste the HTML into the Signature Box
This is the fastest way to get a working signature and is the right choice when your logo is hosted at a web address (see [Handling the logo image](#logo)).
1. Open **Account Settings**. Click the menu button (the three horizontal lines, near the top right) and choose **Account Settings**. If you use the classic menu bar, it is under **Tools > Account Settings** instead.
2. In the left-hand list, click the **name of the account** you are signing from (the top entry for that account, not a folder or a sub-page beneath it). The main settings for that identity appear on the right.
3. Tick the box labelled **Use HTML** (its full label is along the lines of "Use HTML (e.g. bold)"). This tells Thunderbird to treat the signature field as markup rather than as literal text.
4. Click into the **Signature text** box and paste the edited template. Because **Use HTML** is ticked, Thunderbird interprets the tags; you will not see the code, and the signature does not preview here.
5. Close the Account Settings tab. There is no Save button; changes are kept automatically.
Open a new message with **Write** to see the result rendered at the bottom of the compose window.
## Method 2: Attach the Signature from a File
Use this method when you want the logo to **always** display, even for recipients who block remote images. Here the whole signature lives in an `.html` file and Thunderbird embeds any image the file references.
### Save the Signature as a File
1. Open a plain-text editor (Notepad on Windows, TextEdit in plain-text mode on macOS, or gedit on Linux). Do **not** use a word processor such as Word, as it inserts formatting that breaks the file.
2. Paste the edited template. For an embedded logo, change the image `src` to a plain relative filename with no folder and no `https://`, for example `src="logo.png"`.
3. Save the file as `signature.html` in a folder you will not delete, and save your logo image into the **same folder** under the exact filename you referenced (`logo.png`). The relative reference only works when the image sits beside the HTML file.
### Point Thunderbird at the File
1. Open **Account Settings** (menu button, then **Account Settings**) and select the account name on the left.
2. Tick **Attach the signature from a file instead (text, HTML or image)**.
3. Click **Choose** and browse to your `signature.html` file.
4. Close the Account Settings tab. When you compose a message, Thunderbird reads the file, and because the logo is referenced relatively it embeds a copy of the image inside the outgoing message.
When you later change the signature, edit the `.html` file and the update is picked up automatically; there is nothing to re-import. If you replace the logo, keep the same filename or update the `src` to match.
## Handling the Logo Image: Host It or Embed It
This is the decision that determines whether recipients actually see your logo, so it is worth understanding both options.
### Host the Logo at a Web Address (Method 1)
The image sits on a server and the signature references it by URL. Each recipient's mail app downloads it when they open your message.
- **Upside:** your emails stay tiny, and you can swap the logo everywhere at once by replacing the file on the server.
- **Downside:** many mail apps block remote images by default until the reader clicks "show images", so your logo may appear as an empty box on first view. A remote image is also an external fetch, which privacy-minded recipients may distrust.
- **Where to host it on Noiz:** upload the logo into your website's files (for example a `/img/` folder) and use its public address, such as `https://www.yourdomain.com/img/logo.png`. Confirm the address opens in a browser on its own before relying on it, and never link to a logo on someone else's site.
### Embed the Logo in the Message (Method 2)
A copy of the image is carried inside every message you send.
- **Upside:** the logo always displays, with no "show images" prompt and no external fetch.
- **Downside:** every single email is a little larger, and a copy is embedded even in short replies, so keep the file small.
For most business users the embedded route (Method 2) gives the most reliable, professional result, provided the logo is genuinely lightweight.
### Keep the Logo Lightweight
- **Dimensions:** display the logo at roughly `64` to `90` pixels tall. The template sets `72` by `72`; adjust the `width`, `height` and the matching `style` values together.
- **Crispness on sharp screens:** export the file at twice the display size (for example a 144-pixel image shown at 72) so it stays clean on high-resolution displays, while keeping the `width` and `height` attributes at the display size.
- **File size:** aim to keep the logo under about 30 to 50 KB. Use PNG for logos with flat colour or transparency, and JPG for photographic content.
- **Always set `width` and `height`:** without them, some mail apps blow the image up to its full pixel size and wreck the layout.
## Test Your Signature Before You Rely On It
A signature that looks perfect in Thunderbird can still misbehave elsewhere, so send a few test messages and check them where your recipients actually read mail:
1. **Send one to yourself** and open it in Thunderbird to confirm the layout, links and logo.
2. **Send one to a different provider** such as a Gmail or Outlook.com address, and open it in that provider's web mail. This is where table-and-inline-style signatures earn their keep.
3. **Check with images blocked.** In the test message, do not click "show images" straight away. If you hosted the logo (Method 1) it will be hidden until you allow it; if you embedded it (Method 2) it should appear immediately. The `alt` text is your safety net either way.
4. **Check on a phone.** Open a test on a mobile mail app to confirm the signature does not overflow the screen.
5. **Click every link.** Confirm the phone number dials, the website opens and the email address composes a new message.
## Troubleshooting
- **Symptom**: the signature shows raw code like `
` instead of a formatted footer. The **Use HTML** box was not ticked before pasting (Method 1). Tick it, clear the box and paste the template again.
- **Symptom**: the logo is a broken-image icon or empty box. For a hosted logo (Method 1), open the `src` address in a browser; if it does not load, the file is not public or the address is wrong. For an embedded logo (Method 2), confirm the image sits in the same folder as the `.html` file and that the filename in `src` matches exactly, including capitalisation.
- **Symptom**: recipients see a plain-text version with no formatting. Their mail app, or your own, may be composing in plain text. Ensure you are writing HTML mail (hold **Shift** while clicking **Write** toggles the compose format), and remember some recipients deliberately view mail as plain text, where only the words survive by design.
- **Symptom**: the signature looks fine in Thunderbird but cramped or misaligned in Outlook or Gmail. Almost always caused by CSS that those apps ignore. Stick to the table-plus-inline-styles pattern in this template and avoid adding modern layout such as flexbox or background images.
- **Symptom**: the embedded logo appears twice, once inline and once as a loose attachment. This is normal in a few mail apps that list every embedded image in the attachment area as well as inline; it does not indicate a fault.
- **Symptom**: the signature does not appear on replies. Check **Account Settings > Composition & Addressing** for the option that includes the signature on replies and forwards, and confirm you are replying from the same account the signature belongs to.
If your signature still will not behave across mail apps, open a support ticket with the Noiz support team. Include the account it applies to, whether you used Method 1 or Method 2, the logo address if you hosted it, and a screenshot of how the signature looks in the inbox where it is going wrong.
# How to Create a User-Level Email Filter in cPanel
Source: https://docs.noiz.ie/email/how-to-create-a-user-level-email-filter-in-cpanel/
You cannot stop spam reaching your mailbox entirely, but you can decide what happens to it once it arrives. A user-level email filter in cPanel inspects each incoming message for a single mailbox and then acts on it automatically: sort it into a folder, redirect it, or discard it. This guide shows you how to create one.
A **user-level** filter applies to one email account only (for example `sales@yourdomain.com`). If you want a rule that applies to every mailbox on the cPanel account at once, you want a **global** (account-level) filter instead, which lives under **Global Email Filters**.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM stable release. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel & WHM Documentation: Email Filters (per mailbox)](https://docs.cpanel.net/cpanel/email/email-filters/)
- [cPanel & WHM Documentation: Global Email Filters (whole account)](https://docs.cpanel.net/cpanel/email/global-email-filters/)
## Prerequisites
- Access to your cPanel account. Your Noiz welcome email contains your cPanel sign-in URL and credentials.
- At least one email account already created in cPanel, since a user-level filter is attached to a specific mailbox.
## Create the Filter
1. Log in to your cPanel account.
2. In the **Email** section, click **Email Filters**. 
3. Under **Filters by Users**, you will see every email account on the cPanel account. Click **Manage Filters** next to the mailbox you want the filter to apply to. 
4. Click **Create a New Filter**.
5. Enter a descriptive name in the **Filter Name** box. The name must be unique for that mailbox, and a clear name (for example `Discard lottery spam`) makes the filter easy to find and edit later.
6. Build the rule. In the first list box, choose the part of the message to test, and in the second list box choose how to test it. To catch a message that contains a word such as **Lottery** anywhere in its text, select **Body** in the first list box and **contains** in the second, then type `Lottery` in the value box.
7. From the **Actions** menu, choose what should happen to a matching message. For example, select **Discard Message** to delete it silently. 
8. Click **Create**.
## Choosing the Right Action
The action decides the message's fate, so choose it deliberately:
- **Discard Message** deletes the message permanently and silently. There is no copy kept and no bounce sent to the sender, so a genuine message caught by a slightly too broad rule is gone for good. Use it only when you are confident the rule is precise.
- **Deliver to folder** is the safer choice for suspected spam. The message is filed into a folder (for example a `Junk` or `Filtered` folder) where you can review it before deleting, rather than losing it outright.
- **Redirect to email** forwards a matching message to another address.
- **Fail with message** rejects the message at delivery and returns your text to the sender.
- **Stop Processing Rules** halts any further filters for that message, which is useful when you want one rule to take precedence over the rest.
You can add more than one rule to a single filter with the **+** button and join them with **and** or **or**, so a filter can require several conditions to match before it acts.
## Test the Filter Before You Rely on It
The **Email Filters** page includes a **Filter Test** box. Paste a sample message (headers and body) into it and click **Test Filter** to see exactly which rules match and what action would run, without waiting for real mail to arrive. Testing first is the quickest way to confirm a **Discard Message** rule is not wider than you intended.
## Manage Existing Filters
Every filter you create for a mailbox is listed on the same **Manage Filters** screen for that account. From there you can drag filters to reorder them (they run top to bottom), click **Edit** to change a rule or action, or click **Delete** to remove a filter you no longer need. Because filters run in order, placing a **Stop Processing Rules** action correctly lets you control which rule wins when two could match the same message.
## Troubleshooting
- **The filter is not catching messages you expected**: check that you selected the correct message part (a keyword in the visible text is in the **Body**, while a sender address is in **From**), and that the value has no stray spaces. Use the **Filter Test** box to confirm.
- **Wanted mail is disappearing**: a **Discard Message** rule is almost certainly too broad. Edit the filter, switch the action to **Deliver to folder**, and narrow the condition until only unwanted mail matches.
- **The filter does not appear for other mailboxes**: this is expected. A user-level filter only applies to the single account you created it under. Create a **Global Email Filter** if you need the same rule across every mailbox on the account.
If you are on a Noiz managed plan and would like help designing a filter, or you are unsure whether a user-level or global filter is the right fit, open a support ticket and the Noiz team will assist.
# How to Delete Email Messages in Mozilla Thunderbird
Source: https://docs.noiz.ie/email/how-to-delete-email-messages-in-mozilla-thunderbird/
This guide shows you how to delete email messages in Mozilla Thunderbird, how to get a message back when you delete it by accident, and how to make sure the space really is freed on your Noiz mailbox. It is written for Noiz email clients using Thunderbird on a desktop or laptop. People describe this task in several ways: deleting a message, removing an email, throwing mail in the bin, or clearing out an inbox. They all mean the same thing here. Deleting looks like a single click, and most of the time it is, but what happens behind that click depends entirely on whether your account is set up as IMAP or POP. That one distinction decides whether the message disappears from your phone and webmail too, and whether your mailbox quota actually goes down. The sections below cover the click, and then the part nobody explains.
**Last reviewed:** 27 July 2026, against Thunderbird **140 ESR and the current monthly Release (version numbers in the 140s)**. This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below. Thunderbird's menu wording and toolbar layout shift a little between versions, so a label may sit slightly differently in your copy; the sequence and the behaviour described here hold across recent versions.
### Official Documentation Reference
- [Mozilla Thunderbird Support (home)](https://support.mozilla.org/en-US/products/thunderbird): the official help hub. If a menu label in your version differs from the wording used here, search this site for the current term.
- [IMAP Synchronization (Mozilla Support)](https://support.mozilla.org/en-US/kb/imap-synchronization): explains how Thunderbird keeps its local copy in step with the server, which is the mechanism behind everything in the "What Deleting Actually Does" section below.
- [Compacting Folders (Mozilla Support)](https://support.mozilla.org/en-US/kb/compacting-folders): the reference for why deleted mail can still occupy disk space, and how compacting clears it.
- [Archived Messages (Mozilla Support)](https://support.mozilla.org/en-US/kb/archived-messages): covers the Archive function, which is often what you actually want when you are only trying to tidy an inbox.
- [Thunderbird and Junk / Spam Messages (Mozilla Support)](https://support.mozilla.org/en-US/kb/thunderbird-and-junk-spam-messages): the difference between marking mail as junk and deleting it, and why the distinction matters for future filtering.
## Prerequisites
- Thunderbird is installed and your Noiz mailbox is already set up in it. If it is not, start with [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/).
- You know whether the account is **IMAP** or **POP**. This single fact decides what deleting does to your mail. To check, open **Account Settings**, click **Server Settings** beneath the account name, and read the **Server Type** line.
- You are online if the account is IMAP, so that the deletion is passed to the server rather than queued.
## What Deleting Actually Does
Deleting a message in Thunderbird is not one behaviour, it is two, and which one you get depends on the account type. This is the part worth reading before you start clearing anything out in bulk.
### IMAP: the deletion travels to the server
Noiz client mailboxes are normally set up as **IMAP**, which means the master copy of every message lives on the Noiz mail server and Thunderbird shows you a synchronised local view of it. When you delete a message in an IMAP account, Thunderbird tells the server to move it to the **Trash** folder on the server. The change then appears everywhere else the mailbox is open: webmail, your phone, a tablet, a second computer. That is normally exactly what people want, but it does mean a bulk clear-out on your laptop empties your phone as well, so be deliberate about it.
### POP: the message is only removed from this computer
A **POP** account works the other way round. POP downloads messages onto your computer, and deleting one afterwards removes it from Thunderbird on that machine only. The copy on the server is untouched by the delete, so if the account is configured to leave mail on the server, the message is still sitting in your Noiz mailbox and still counting against your quota. This surprises people who spend an afternoon deleting thousands of messages in Thunderbird and then find their mailbox is just as full as before. If that is your situation, log in to webmail and delete there as well, or move the account to IMAP so the two stay in step.
### Deleting is not the same as unsubscribing or blocking
Deleting removes one message. It does not stop the sender writing to you again, and it does not teach any filter anything. If you want the sender to stop, unsubscribe or block; if you want future messages of that kind sorted away automatically, use a filter rather than a daily delete. [How to Organise Your Email with Folders and Filters in Thunderbird](/email/how-to-organise-your-email-with-folders-and-filters-in-thunderbird/) covers that side of it.
## Step 1: Open Thunderbird and Select the Folder
Open Mozilla Thunderbird from your desktop, taskbar, Start menu, or Applications folder. In the folder list on the left, click the folder holding the message you want to remove, usually **Inbox** under the relevant account. The message list fills the middle pane.

If you have several accounts set up, check the account heading above the folder before you delete anything. The folder list stacks accounts one under another, and inboxes look identical at a glance, so it is easy to be looking at the wrong one.
## Step 2: Right-Click the Message and Choose Delete
In the message list, **right-click** the message you want to remove, then click **Delete Message** on the context menu. The message disappears from the list immediately and moves to **Trash**.

Thunderbird does not ask you to confirm an ordinary delete. That is by design, because the message goes to Trash rather than vanishing, and Trash is recoverable. The section on undoing a delete below covers how to get it back.
## Other Ways to Delete
The right-click route is the clearest one to learn first, but there are quicker options once you are comfortable:
- **The Delete key.** Select a message in the list and press **Delete**. This is the fastest way to work through a batch one at a time.
- **The toolbar button.** With a message selected or open, click the **Delete** button (the bin icon) on the message toolbar.
- **Several messages at once.** Click the first message, then hold **Ctrl** (**Cmd** on macOS) and click each additional message to pick out a scattered selection. To take a continuous run, click the first message, hold **Shift**, and click the last. Then press **Delete** once and the whole selection goes.
- **Everything in a folder.** Click any message in the list, press **Ctrl** + **A** (**Cmd** + **A**) to select all, then press **Delete**. Treat this one with respect, especially on IMAP, because it clears the folder on the server too.
One caution on bulk deletion over IMAP: a very large selection can take a while to process, because every deletion has to be sent to the server. Let Thunderbird finish rather than closing it partway through, or the folder can be left looking inconsistent until the next synchronisation catches up.
## Undoing a Delete
If you delete the wrong message, press **Ctrl** + **Z** (**Cmd** + **Z** on macOS) straight away, or use **Edit > Undo**. The message returns to the folder it came from.
If you have already carried on doing other things and undo no longer helps, open the **Trash** folder in the left-hand list. Deleted messages sit there until the Trash is emptied. Find the message, then drag it back to **Inbox** or whichever folder it belongs in, or right-click it and use **Move To**. On an IMAP account this works from any device, so a message deleted on your laptop can be rescued out of Trash in webmail.
The one case where this does not apply is a permanent delete, described below.
## Emptying the Trash and Freeing Mailbox Space
Deleting a message moves it to Trash. It does not remove it from your account. On an IMAP mailbox, everything in Trash still lives on the Noiz mail server and still counts towards your mailbox quota. This is the most common reason a mailbox stays full after a long clear-out.
To empty it, right-click the **Trash** folder in the folder list and choose **Empty Trash**. Thunderbird asks you to confirm, because this step genuinely is permanent: messages removed this way are not recoverable from Thunderbird, and Noiz cannot restore individual messages you have purged from your own mailbox. Check the contents of Trash before you confirm.
You can also have Thunderbird do this for you. In **Account Settings > Server Settings** for the account, tick **Empty Trash on Exit** so the folder is cleared every time you close the program. It keeps the mailbox tidy without any thought, though it also removes your safety net, so only enable it if you are confident you will not need to fish anything back out.
## Compacting: Why Deleted Mail Can Still Take Up Disk Space
There is a second, quieter reason space does not come back. Thunderbird stores messages in large container files, and when you delete a message it is marked as removed inside that file rather than being cut out of it. The space is only genuinely reclaimed when the folder is **compacted**. Until then, a folder you have emptied can still be occupying the same amount of disk as before.
To do it manually, right-click a folder and choose **Compact**, or use **File > Compact Folders** to process everything at once. Thunderbird also prompts you automatically once enough recoverable space builds up. Say yes when it asks. Compacting affects local storage on your computer; it is not the same thing as freeing server quota, which is what emptying Trash does. On a busy mailbox you generally want both.
## Deleting Permanently in One Step
To bypass Trash entirely, hold **Shift** while pressing **Delete**. The message is removed immediately with no copy kept in Trash and nothing to recover. Thunderbird may warn you the first time, but it will not keep asking.
This is useful for obvious rubbish you never want to see again, and it is worth knowing about mainly so you understand why a message you deleted is sometimes not in Trash. Avoid it as a habit. The few seconds saved are not worth losing a message you turn out to need, and it is easy to press Shift by accident when you are selecting a run of messages.
## When Deleted Messages Stay in the Folder with a Line Through Them
Some IMAP setups do not move deleted mail to Trash at all. Instead they flag the message as deleted and leave it in place, shown greyed out or struck through, until the folder is purged. If that is what you are seeing, the account is set to mark messages rather than move them.
You can change it. Open **Account Settings**, click **Server Settings** under the account, and look at **When I delete a message**. The options are:
- **Move it to this folder** (normally Trash): the standard behaviour described throughout this guide, and the one to choose if you want deleting to feel like every other mail program.
- **Just mark it as deleted**: the message stays in the folder, flagged, until you purge. Use **File > Compact** on the folder to clear the flagged messages out.
- **Remove it immediately**: no Trash and no flag, gone at once. This carries the same risk as a Shift-delete, applied to every deletion you make.
Noiz mailboxes work correctly with all three, so this is purely a matter of how you prefer Thunderbird to behave. [The Best Thunderbird Settings to Configure First](/email/the-best-thunderbird-settings-to-configure-first/) covers this setting alongside the other choices worth making early.
## Delete, Archive or Junk: Choosing the Right One
Deleting is not always the right tool, and picking the correct one saves a lot of regret later.
- **Delete** when the message has no future value: notifications you have read, duplicates, obvious rubbish. It frees quota once Trash is emptied.
- **Archive** when you only want the message out of your inbox but might need it again. Select it and press **A**, or click **Archive**. It moves to a dated archive folder, stays searchable, and is still there in a year. Archiving does not free any space, since the mail is only moved, but that is usually the point.
- **Junk** when the message is spam. Marking it as junk teaches the filter and helps similar mail get caught in future; simply deleting spam teaches it nothing. Mark first, then delete or let the junk folder handle it.
## Troubleshooting
**Symptom**: deleted messages come back after a few minutes. The deletion did not reach the server. Check you are online, then use **File > Get New Messages** to force a synchronisation. If the account is showing an authentication error, the password will need re-entering before any change can be pushed up.
**Symptom**: the mailbox is still full after deleting a lot of mail. The Trash folder is almost certainly still holding it, and on IMAP that counts against your quota. Right-click **Trash** and choose **Empty Trash**. Check any Junk, Sent and Archive folders as well, since those fill up quietly and are easy to forget.
**Symptom**: deleting in Thunderbird makes no difference to the mailbox at all. The account is POP, so deletions are local only. Delete in webmail as well, or reconfigure the account as IMAP.
**Symptom**: the disk on the computer has not freed up. Run **File > Compact Folders**. Deleted mail keeps occupying disk space until the folder is compacted.
**Symptom**: messages are struck through instead of disappearing. The account is set to **Just mark it as deleted**. See the section above to change the setting or to purge the flagged messages.
**Symptom**: a message vanished and is not in Trash. Either it was deleted with **Shift** held down, or the account is set to remove messages immediately. Check **Server Settings** to confirm which, and adjust the setting if the behaviour was not what you intended.
**Symptom**: the deletion happened on your phone as well, and you did not expect it. That is normal IMAP behaviour. Every device sees the same mailbox, so a deletion anywhere applies everywhere. Restore from Trash if the Trash has not been emptied.
## Getting Help from Noiz
Noiz can help with anything on the server side of this: checking your mailbox quota, confirming whether the account is set up as IMAP or POP, and investigating mail that is not synchronising correctly. Open a ticket from the client area and include the email address concerned and a short description of what you deleted and what you expected to happen. Be aware that once messages are purged from your mailbox they are gone from the server, so raise any suspected deletion problem promptly rather than after emptying the Trash. If you are on a managed plan, Noiz can review the account configuration with you and set the delete behaviour to suit how you work.
# How to Delete a Global Email Filter in cPanel
Source: https://docs.noiz.ie/email/how-to-delete-a-global-email-filter-in-cpanel/
This guide shows you how to remove a **Global Email Filter** (also called an account-level filter) from your cPanel account. Global filters run against mail for *every* mailbox on the account, so removing one changes how incoming mail is sorted, forwarded, or discarded for all addresses on the domain, not just a single inbox.
**Last reviewed:** 27 July 2026, against the current cPanel & WHM interface (Jupiter theme). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: Global Email Filters](https://docs.cpanel.net/cpanel/email/global-email-filters/)
## Prerequisites
- Access to your cPanel account.
- At least one existing global filter under **Current Filters**.
## Before You Delete
Deleting a filter is immediate and cannot be undone. If the filter routes, forwards, or discards mail, removing it can cause messages that were previously caught to start landing in inboxes again, or the other way round. If you only want to pause a filter temporarily, edit it and note the rule elsewhere first, because cPanel does not keep a copy of a deleted filter.
Global filters differ from per-mailbox filters, which you manage under **Email Filters** and which affect only one address. Make sure you are deleting from **Global Email Filters** if you intend the change to apply account-wide.
## Delete a Global Email Filter
### Step 1: Open Global Email Filters
Log in to your cPanel account. In the **Email** section, click **Global Email Filters**.

### Step 2: Find the filter to remove
The **Current Filters** list shows every global filter on the account. Locate the filter you want to remove, then click **Delete** next to it.

### Step 3: Confirm
Click **Delete Filter** to confirm. The filter is removed straight away and no longer applies to mail arriving at the account.
## Need a Hand?
On a Noiz managed plan, you do not have to touch filters yourself. If you are unsure which filter to remove, or a deletion has changed how your mail is delivered, contact Noiz support and the team will sort it out with you.
# How to Delete a User-Level Email Filter in cPanel
Source: https://docs.noiz.ie/email/how-to-delete-a-user-level-email-filter-in-cpanel/
This guide shows you how to remove a **user-level email filter** in cPanel. A user-level filter belongs to a single mailbox and only acts on mail delivered to that address, so deleting one affects that mailbox alone. It does not touch the account-level (global) filters that apply to every mailbox on the account, nor the filters set on any other email address.
Deleting a filter is permanent and takes effect immediately. cPanel does not keep a copy of the rule, so if you might need the filter again, note its conditions and actions before you remove it.
**Last reviewed:** 27 July 2026, against cPanel & WHM (Jupiter theme, current stable). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel: Email Filters](https://docs.cpanel.net/cpanel/email/email-filters/) (the interface used to create, edit and delete per-mailbox filters).
## Prerequisites
- Access to your cPanel account.
- At least one existing email filter on the mailbox you want to change.
## Deleting a User-Level Email Filter
1. Log in to your cPanel account.
2. In the **Email** section, click **Email Filters**. 
3. Under **Filters by Users**, cPanel lists every email account on the domain. Click **Manage Filters** next to the mailbox whose filter you want to remove. 
4. Under **Current Filters**, find the filter you want to remove and click **Delete** next to it. 
5. Click **Delete Filter** to confirm. The filter is removed from that mailbox straight away.
## Good to Know
- **Only this mailbox is affected.** User-level filters are separate from account-level (global) filters. Removing one here leaves the global filters and every other mailbox untouched.
- **There is no undo.** A deleted filter cannot be restored. To reinstate it later you have to recreate it by hand, so record the rule first if you are unsure.
- **Mail already handled stays put.** Deleting a filter only changes how future mail is treated. Messages the filter has already moved, redirected or discarded are not brought back.
## Need a Hand?
If you are on a Noiz managed plan and would rather Noiz take care of it, open a support ticket from your client area and the team will remove the filter for you.
# How to Determine the Source of Spam and Reduce It
Source: https://docs.noiz.ie/email/how-to-determine-the-source-of-spam-and-reduce-it/
This guide helps you work out where unwanted spam reaching your mailbox is actually coming from, and how to cut it down on Noiz hosting. It is written for mailbox users whose accounts run on Plesk with its built-in SpamAssassin spam filter. If your goal is specifically to tune the spam score or train the filter to recognise your spam more accurately, start with the companion article, [How to train your spam filter when using Plesk](/plesk/how-to-train-your-spam-filter-in-plesk/), then return here.
**Last reviewed:** 27 July 2026, against Plesk and its built-in SpamAssassin spam filter on Noiz hosting. This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk and SpamAssassin documentation linked below.
### Official Documentation Reference
- [Plesk Customer Guide: Protection from Spam](https://docs.plesk.com/en-US/obsidian/customer-guide/mail/protection-from-spam.65210/) (enabling and configuring the spam filter for a mailbox)
- [Apache SpamAssassin](https://spamassassin.apache.org/) (the open-source engine behind Plesk spam scoring, including how tests and scores work)
## Before you start
Spam filtering only works well once it has been switched on and given time to learn what your spam looks like. Before treating persistent spam as a fault, confirm that all of the following are true:
1. You have enabled spam filtering for your mailbox.
2. You have set your spam score to a suitable threshold. A lower threshold makes the filter more aggressive and catches more spam, at the cost of occasionally catching legitimate mail.
3. You have set up the correct Spam folder in your mail app so filtered messages have somewhere to go.
4. You have been manually moving spam messages into that Spam folder, and moving any wrongly filtered messages back to the Inbox, for at least a week. The filter needs this training time to become accurate.
If any of these are still outstanding, complete them first and give the filter a few days. Many spam complaints resolve on their own once the filter has been trained. The [spam filter training guide](/plesk/how-to-train-your-spam-filter-in-plesk/) walks through each of these steps in detail.
## Find out where the spam is coming from
Before you can reduce spam, it helps to know its real source. The most reliable way to do this is to read the message headers, also called the raw source. The headers record the servers a message passed through and the results of the sender authentication checks, and they are far harder to fake than the visible From name.
### View the raw source of a message
In Plesk webmail, open the offending message, open the message actions menu (the **More** or ellipsis option), and choose **Show source** or **View source**. Most desktop and mobile mail apps offer the same thing under a label such as **Show original**, **View source**, or **View message details**. This opens the full message, including every header line, which you can then read or copy.
### What to look for in the headers
- **Return-Path** and the topmost `Received:` lines show the server that actually delivered the message to you. This is the true origin, regardless of what the From line claims.
- **Authentication-Results** shows the outcome of the SPF, DKIM and DMARC checks. A message that fails all three is almost certainly forged or spam.
- **X-Spam-Status** or **X-Spam-Score** (added by the spam filter) shows the score the message received and which rules fired. If the score sits just below your threshold, tightening the threshold slightly may be all that is needed.
### Which situation are you in?
Reading the headers usually reveals one of three situations, and each is handled differently:
- **Genuine inbound spam.** The message really was sent to you from an outside server. Reducing it is a matter of filter training and threshold tuning (below).
- **Your address is being spoofed.** You receive bounce messages or replies for mail you never sent, because a spammer put your address in the From line. Publishing SPF, DKIM and DMARC records for your own domain makes this forgery far easier for other mail servers to reject.
- **Your account is sending the spam.** If the headers show the spam originating from your own mailbox or the mail server sending on your behalf, your account credentials have likely been compromised. Change the mailbox password immediately, then contact Noiz support.
## Reduce the spam you receive
For genuine inbound spam that keeps reaching your Inbox, the two most effective levers are:
1. **Keep training the filter.** Every message you move into the Spam folder, and every false positive you move back out, improves accuracy over time. Consistency matters more than volume.
2. **Lower the spam score threshold in small steps.** Nudge it down, watch for a few days, and check that legitimate mail is not being caught. The [training guide](/plesk/how-to-train-your-spam-filter-in-plesk/) covers safe threshold values.
## Still getting spam that is not being filtered?
If, after completing all the steps above and giving the filter time to learn, large amounts of spam still arrive in your Inbox without being marked or moved, Noiz support can help. Some diagnostic data is needed first so the problem can be reproduced and investigated.
Please include the following in your support ticket:
1. The **raw source** of one spam message that was not moved to the Spam folder or marked as spam, captured using the steps above. This is the single most useful item, because it contains the headers and the spam score.
2. The **email address** at which you are receiving the spam.
3. The **spam score threshold** you have set in Plesk.
4. Roughly **how many messages** you have trained as spam, and for **how long** you have been training the filter.
With the raw source in hand, the support team can examine the headers, the spam score and the server-side mail logs for your mailbox, and investigate without ever needing to sign in to your account.
## A note on your password
Never share your mailbox password with anyone, including support staff. Noiz support will never ask for it, and it is never required to diagnose a spam problem. The raw source of a message and, where relevant, the server-side mail logs provide everything needed. If anyone asks you to hand over your password to investigate spam, treat it as a phishing attempt. If you suspect your mailbox itself has been compromised, change the password straight away and mention this in your ticket.
Once you have gathered the diagnostic data above, [open a support ticket here](https://www.noiz.co.za/submitticket.php?step=2&deptid=1) so the Noiz team can investigate.
# How to Edit a Global Email Filter in cPanel
Source: https://docs.noiz.ie/email/how-to-edit-a-global-email-filter-in-cpanel/
Global Email Filters in cPanel apply mail-handling rules to **every** email account on your cPanel account at once, rather than to a single mailbox. Editing a global filter lets you change the conditions it matches, or the action it takes, without deleting and rebuilding it from scratch. This guide shows you how to open an existing global filter and save your changes.
**Global Email Filters** (account-wide) are separate from **Email Filters** (which apply to one mailbox only). If you cannot find the filter you are looking for, check whether it was created as a per-mailbox filter instead.
**Last reviewed:** 27 July 2026, against the current stable release of cPanel & WHM. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel & WHM Documentation: Global Email Filters](https://docs.cpanel.net/cpanel/email/global-email-filters/)
## Prerequisites
- Access to your cPanel account.
- At least one existing global filter listed under **Current Filters**. If none exists yet, create one first, then return here to edit it.
## Edit a Global Email Filter
1. Log in to your cPanel account.
2. In the **Email** section, click **Global Email Filters**. 
3. Under **Current Filters**, cPanel lists every existing global filter. Click **Edit** next to the one you want to change. 
4. Make your changes. You can rename the filter, adjust the **Rules** (the conditions a message must match), and change the **Actions** cPanel takes when a message matches.
5. Click **Save**.
## Good to Know
- **Changes apply to new mail only.** Editing a filter affects messages that arrive after you save. Mail already delivered to a mailbox is not re-filtered.
- **Rule order matters.** Within a filter, cPanel evaluates the rules from top to bottom, and the **and** / **or** logic between them decides whether they must all match or any one. If a filter is not behaving as expected, check the order and that logic first.
- **Global versus per-mailbox.** A global filter runs for every address on the cPanel account. If you only want the rule to affect one address, edit that mailbox's **Email Filters** instead.
- **Test before you rely on it.** Use the **Filter Test** box on the Global Email Filters page to paste a sample message and confirm the edited filter matches, or ignores, it as intended.
## Need a Hand?
If a global filter is discarding mail you expected to receive, or you are not sure whether a rule should be global or per-mailbox, the Noiz support team can review your filter setup. Open a support ticket from your [Noiz client area](https://www.noiz.co.za) and include the filter name and an example message.
# How to Edit a User-Level Email Filter in cPanel
Source: https://docs.noiz.ie/email/how-to-edit-a-user-level-email-filter-in-cpanel/
A user-level email filter in cPanel sorts, redirects, or discards messages for a single email address on your account, without touching the other mailboxes. This guide shows you how to change a filter that already exists: adjust the rules it matches on, change what it does with a matching message, or rename it.
A **user-level filter** applies to one specific email account only. If you need a rule that applies to every address on the account, edit an account-level (global) filter instead.
**Last reviewed:** 27 July 2026, against cPanel & WHM (current stable release). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel: Email Filters](https://docs.cpanel.net/cpanel/email/email-filters/)
## Prerequisites
- A hosting plan that uses the cPanel control panel, and your cPanel sign-in details.
- An email account that already has at least one filter to edit.
## Edit a User-Level Email Filter
1. Log in to your cPanel account.
2. In the **Email** section, click **Email Filters**. 
3. Under **Filters by Users**, you see every email account on your hosting. Click **Manage Filters** next to the address whose filter you want to change. 
4. Under **Current Filters**, click **Edit** next to the filter you want to change. 
5. Make your changes. You can rename the filter, adjust the matching rules (for example the field to check, such as **Body** or **From**, and the condition to match, such as **contains**), and change the action cPanel takes when a message matches, such as **Discard Message** or **Deliver to Folder**.
6. Click **Save**.
## Good to Know
- Filters run in order, from the top of the list downwards. Editing a filter does not move it. If your edited rule needs to run before another one, reorder the filters on the same Manage Filters page.
- Your changes apply to mail that arrives after you save. Messages already delivered to the mailbox are not re-filtered.
- Use the **Filter Test** box at the bottom of the Manage Filters page to paste a sample message and confirm the edited filter behaves the way you expect before you rely on it.
If you are on a managed Noiz plan and would like Noiz to review or fine-tune your email filtering, open a support ticket from your client area and the team will take care of it for you.
# How to Enable Apache SpamAssassin and Spam Box in cPanel
Source: https://docs.noiz.ie/email/how-to-enable-apache-spamassassin-and-spam-box-in-cpanel/
Apache SpamAssassin is an automated mail filter that scores each incoming message and flags the ones that look like spam. It examines the headers and body of every email and applies a large set of statistical tests, so unsolicited bulk mail is caught before it clutters your inbox. This guide shows you how to switch it on in cPanel and how to send flagged mail to a separate **Spam Box** folder so you can review it rather than lose it.
In current cPanel versions this feature is listed as **Spam Filters** (older versions labelled it **Apache SpamAssassin**). **Spam Box** is the option that quarantines flagged mail in a dedicated `Spam` folder instead of leaving it in your inbox.
**Last reviewed:** 27 July 2026, against current cPanel & WHM, where Apache SpamAssassin appears as the **Spam Filters** feature. This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Spam Filters (Apache SpamAssassin)](https://docs.cpanel.net/cpanel/email/spam-filters/)
- [Calculated Spam Score and Threshold Settings](https://docs.cpanel.net/cpanel/email/spam-filters/#calculated-spam-score-settings)
## Prerequisites
- Access to your cPanel account.
- The Spam Filters feature available on your plan. If the toggles described below are greyed out, Apache SpamAssassin has been disabled at the server level; contact Noiz support and it can be enabled for your account.
## Turn On Spam Filtering
1. Log in to your cPanel account.
2. In the **Email** section, click **Spam Filters**. 
3. Turn on the **Process New Emails and Mark them as Spam** toggle. When the toggle is on, Apache SpamAssassin scans every new message and marks anything that scores at or above the spam threshold. If the toggle is greyed out and cannot be moved, the filter is disabled at the server level. 
On its own, this setting only *marks* spam. Marked messages still arrive in your inbox with spam headers added, so most people also switch on Spam Box below to keep flagged mail out of the way.
## Move Flagged Mail to Spam Box
Spam Box collects messages that Apache SpamAssassin marks as spam into a separate `Spam` folder, keeping your inbox clean while letting you review anything that was caught by mistake.
1. In the same Spam Filters interface, turn on **Move New Spam to a Separate Folder (Spam Box)**. 
2. From now on, flagged messages are delivered to the `Spam` folder rather than your inbox. You can open that folder in Webmail, or in any mail app connected over IMAP, to check for legitimate mail that was mistakenly flagged.
Spam Box keeps flagged mail, it does not delete it. The `Spam` folder counts towards your mailbox quota, so empty it from time to time to avoid filling your storage.
## Adjust the Spam Threshold Score
Every message is given a spam score. The higher the score, the more spam-like the message. By default cPanel marks anything scoring **5** or above as spam.
- **Lower the threshold** (for example to 3 or 4) to catch more spam, at the risk of flagging some legitimate mail.
- **Raise the threshold** (for example to 7 or 8) to be less aggressive if genuine mail is being caught.
To change it, open **Spam Threshold Score** in the Spam Filters interface, choose a value, and save. Start with the default and only adjust it if you see too much spam getting through or too much good mail being flagged.
## Auto-Delete (Optional)
The **Automatically Delete New Spam (Auto-Delete)** option permanently discards messages that score at or above a level you choose, with no copy kept anywhere. It is effective but unforgiving: anything wrongly flagged is gone for good. For most accounts Spam Box is the safer choice, because it lets you review flagged mail before deleting it. Only use Auto-Delete once you are confident the filter is not catching legitimate messages.
## Troubleshooting
- **The toggle is greyed out**: Apache SpamAssassin is disabled at the server level and cannot be switched on from cPanel. Open a ticket with Noiz support to have it enabled for your account.
- **Genuine mail is landing in the Spam folder**: raise the Spam Threshold Score, or add the sender to the whitelist under **Additional Configurations (For Advanced Users)** in the Spam Filters interface. Check the `Spam` folder regularly until you are happy with the results.
- **Spam is still reaching the inbox**: lower the Spam Threshold Score so more messages are flagged, and confirm the **Process New Emails and Mark them as Spam** toggle is on. You can also blacklist a persistent sender under Additional Configurations.
- **Your mailbox is filling up**: the `Spam` folder counts towards your quota. Empty it periodically, or set an Auto-Delete score once you trust the filter.
If you are unsure which settings suit your mail, Noiz support can review your Spam Filters configuration and recommend a threshold for your account. Open a ticket from your client area and include the email address you want reviewed.
# How to Enable BoxTrapper in cPanel
Source: https://docs.noiz.ie/email/how-to-enable-boxtrapper-in-cpanel/
BoxTrapper is a challenge-response spam filter in cPanel. When it is enabled on an email address, any sender who is not already on your whitelist receives an automated verification message and must respond to it before their email reaches your inbox. Mail from senders who never verify stays held in a queue. This guide shows you how to enable BoxTrapper on a cPanel mailbox, explains the trade-offs before you switch it on, and points you to the configuration screens you will use afterwards.
**Last reviewed:** 27 July 2026, against cPanel **version 136** (current RELEASE tier). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [BoxTrapper in the cPanel & WHM Documentation](https://docs.cpanel.net/cpanel/email/boxtrapper/)
## Before you enable BoxTrapper
Challenge-response filtering is powerful but blunt, so it helps to understand what it does to your incoming mail before you turn it on.
- **Automated senders cannot verify.** Order confirmations, password resets, invoices, calendar invites, newsletters and anything sent from a `no-reply@` address will never answer a verification email. That mail sits in the review queue until you release it, so add trusted automated senders to the whitelist first.
- **Spammers forge sender addresses.** Because verification messages are sent back to whatever address appears in the **From** field, and spam usually carries a forged sender, your account can send verification requests to innocent third parties. This is known as backscatter and it can harm your domain's sending reputation.
- **Legitimate people occasionally miss the challenge.** A first-time contact who does not notice or trust the verification email will not get through until you release their message manually.
For many mailboxes, cPanel's built-in **Spam Filters** feature gives lower-friction protection because it scores and files spam without asking senders to prove themselves. BoxTrapper is best kept for a specific address that receives a lot of unwanted mail and only a small, known set of legitimate correspondents.
## How to enable BoxTrapper
1. Log in to your cPanel account.
2. In the **Email** section, click **BoxTrapper**. 
3. The BoxTrapper page lists your email addresses under the **Account** heading with each one's current state under the **Status** heading. Click **Manage** next to the address you want to protect. 
4. On the Manage page, if the status shows **Disabled**, click **Enable**. cPanel confirms with a message that BoxTrapper has been enabled for that address.
To switch BoxTrapper off again later, return to the same Manage page and click **Disable**.
## Configure BoxTrapper
Once BoxTrapper is enabled on an address, use the **Manage** page for that address to tune how it behaves:
- **Edit White/Black/Ignore Lists.** Add trusted senders to the whitelist so they bypass verification, block persistent offenders on the blacklist, and use the ignore list for addresses BoxTrapper should neither challenge nor deliver.
- **Configure Settings.** Set the spam score threshold at which mail is trapped, the sender's display name used on verification emails, and how many days queued messages and logs are kept.
- **Review Queue.** See messages awaiting verification and deliver or delete each one by hand. Check this regularly, especially in the first few days, so that genuine mail is not lost.
- **Review Log.** Review a day-by-day record of what BoxTrapper has trapped, delivered and challenged.
- **Edit Confirmation Messages.** Customise the wording of the verification, released, returned and blacklist messages that BoxTrapper sends on your behalf.
## Troubleshooting
**BoxTrapper does not appear in your cPanel Email section:** the feature is controlled per hosting package and may be switched off on your plan. Contact Noiz support and ask for the BoxTrapper feature to be enabled for your account.
**Expected mail never arrives:** open the **Review Queue** for that address, release the message, then add the sender to the whitelist so future mail is not held. Automated and `no-reply` senders should always be whitelisted rather than left to verify.
**Contacts complain about verification emails:** this is normal BoxTrapper behaviour for first-time senders. If it causes more friction than it is worth, disable BoxTrapper and rely on cPanel's **Spam Filters** instead.
If you would like a hand deciding between BoxTrapper and standard spam filtering, or setting up your whitelist, the Noiz support team is happy to help through your client area.
# How to Find and Read Full Email Headers for Diagnostics
Source: https://docs.noiz.ie/email/how-to-find-and-read-full-email-headers-for-diagnostics/
This is a reference guide to the full email headers, the hidden technical record that every message carries alongside the part you normally read. When an email is delayed, lands in spam, appears to be forged, or bounces for no obvious reason, the headers are where the answer lives: they show every server the message passed through, the exact times it did so, and the verdicts on whether the sender was genuine. This article shows you how to reveal those headers, sometimes called the **message source**, **raw source**, **original** or **internet headers**, in the mail programmes people actually use with a Noiz mailbox: Plesk Roundcube webmail, Microsoft Outlook (both the classic and the new versions), Mozilla Thunderbird, Apple Mail and Gmail on the web. It then explains, in plain language, what the important lines mean, and how to hand a complete, useful copy to the Noiz support team so a problem can be traced quickly.
You do not need to understand every line to benefit from this. Even copying the full headers correctly and sending them on is a real help, because the header block is the single richest piece of evidence about what happened to a message. Wherever you see `yourdomain.com` below, replace it with your own domain; it is only an example.
**Last reviewed:** 27 July 2026, against the current stable versions of Plesk Roundcube webmail, Microsoft Outlook (classic and new for Windows), Outlook on the web, Mozilla Thunderbird, Apple Mail and Gmail on the web. This guide is written for Noiz hosting and complements, and does not replace, each vendor's own documentation linked below. Email clients redesign their menus often, so if a button sits somewhere slightly different from the description here, the feature and the header content it reveals are the same; look for the wording given rather than the exact location.
### Official Documentation Reference
- [Microsoft: View internet message headers in Outlook](https://support.microsoft.com/en-us/office/view-internet-message-headers-in-outlook-cd039382-dc6e-4264-ac74-c048563d212c), covering the classic desktop, new Outlook for Windows and Outlook on the web.
- [Google: Trace an email with its full header](https://support.google.com/mail/answer/29436), the reference for Gmail on the web.
- [Google Admin Toolbox Messageheader](https://toolbox.googleapps.com/apps/messageheader/), a free analyser that turns a pasted header block into a readable timeline of hops and delays.
- [Mozilla Thunderbird Support](https://support.mozilla.org/en-US/products/thunderbird), the official support hub for the desktop client.
- [Apple Mail User Guide (macOS)](https://support.apple.com/guide/mail/welcome/mac), the official reference for the Mail app.
- [RFC 5322: Internet Message Format](https://www.rfc-editor.org/rfc/rfc5322), the open standard that defines what email headers are and how they are structured.
## Prerequisites
- The message you want to inspect is in front of you in one of the clients below. You are reading the message itself, not a forwarded summary of it (a forward usually strips the original headers away, as explained in Troubleshooting).
- For the webmail method, you can [access your email from Plesk webmail](/plesk/how-to-access-email-from-plesk-webmail/). Noiz webmail is Roundcube.
- You know which direction the problem runs: a message that arrived *into* your Noiz mailbox, or one you *sent* that went astray. This decides whose copy of the headers is useful, and it is the single most common thing people get wrong. See the next section.
## Why Full Headers Matter, and Which Copy to Use
The body of an email is written by the sender and proves nothing about where the message really came from. The headers are added and stamped by the mail servers that handle the message, which is why they can answer questions the body cannot:
- **Tracing the path a message took.** Every server that relays a message adds its own `Received:` line at the top. Reading that stack tells you exactly which systems the message travelled through, in order, and the timestamp on each hop lets you see where a delay was introduced.
- **Diagnosing spam and spoofing.** The receiving server records whether the sender passed the three sender-authentication checks, SPF, DKIM and DMARC, and whether the visible `From:` address matches the address the server actually accepted the mail from. A forged message very often fails one of these or shows a mismatch, and the headers make that visible.
- **Explaining delivery delays.** If mail arrived hours late, the gaps between the timestamps on successive `Received:` lines show which hop held the message up, so the problem can be pinned to the right side.
**The critical point about which copy to capture.** Headers describe the journey up to the point where they are read, so you must capture them from the copy at the destination end of the problem:
- For a message that **arrived badly** (unwanted, forged, or delayed) *into* your Noiz mailbox, open **your own copy** of that message and read its headers. This is the normal case, and everything below applies directly.
- For a message **you sent** that was marked as spam, delayed or rejected *at the far end*, your own Sent copy is of little use: it only shows the message leaving. The evidence lives in **the recipient's copy**. Ask the recipient to open the message they received, capture its full headers using the matching instructions below, and send those to you. Without the recipient-side headers, an outbound delivery problem is very hard to trace.
## Reveal the Full Headers in Each Client
Find your mail programme below. In every case the goal is the same: the complete **raw source** of the message, meaning the entire header block from top to bottom (not just the four or five lines shown in the normal message view).
### Plesk Roundcube Webmail (Noiz Webmail)
1. Sign in to your Noiz webmail and open the message so it fills the reading area.
2. In the message toolbar, open the **More** menu (shown as three dots, **โฆ**, or a **More** button depending on the window width).
3. Choose **Show source**. The complete raw message, headers first, opens in a new browser tab.
4. Select all of the text on that tab (`Ctrl`+`A`, or `Cmd`+`A` on a Mac) and copy it. Some Roundcube versions also offer a **Download** option in the same **More** menu, which saves the message as a `.eml` file; that file is the cleanest thing to attach to a support ticket.
### Microsoft Outlook, Classic Desktop
1. Double-click the message in the list so it opens in its own window (the header option is not available while the message is only previewed in the reading pane).
2. Click **File**, then **Properties**.
3. The full header text appears in the **Internet headers** box near the bottom of the Properties window. Click inside the box, select all of the text and copy it.
Note that the **Internet headers** box shows the header block only, which is exactly what is needed for diagnosis; it does not include the message body.
### New Outlook for Windows, and Outlook on the Web
The new Outlook app and Outlook on the web (Outlook.com and Microsoft 365 webmail) share the same steps:
1. Open the message.
2. Select **More actions** at the top of the message (the three-dots icon).
3. Choose **View**, then **View message details**. The header block appears in a panel; select all of it and copy it. Scroll within the panel to be sure you have captured every line.
### Mozilla Thunderbird
1. Select or open the message.
2. Press `Ctrl`+`U` (Windows and Linux) or `Cmd`+`U` (Mac), or use the menu path **View** โบ **Message Source**. You can also right-click the message and choose **View Source**.
3. The raw source opens in its own window. Select all and copy, or use **File** โบ **Save As** to keep it as a `.eml` file.
If your Noiz account is not yet in Thunderbird, set it up first with [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/), then return here.
### Apple Mail on macOS
1. Select the message in Mail.
2. For the complete raw source, use the menu path **View** โบ **Message** โบ **Raw Source** (keyboard shortcut `Option`+`Cmd`+`U`). This shows every header and the body exactly as received.
3. To expand just the headers within the normal message view instead, use **View** โบ **Message** โบ **All Headers** (`Shift`+`Cmd`+`H`). For a support ticket, **Raw Source** is the better choice because it is complete and easy to copy in full.
**On an iPhone or iPad**, the built-in Mail app has no option to display raw headers. The simplest route is to open the same mailbox in [Plesk webmail](/plesk/how-to-access-email-from-plesk-webmail/) on the device's browser and use the Roundcube steps above, or to view the message on a computer. If you are configuring mail on an iOS device, see [How to Set Up Email on iPhone or iPad](/email/how-to-set-up-email-on-iphone-or-ipad/).
### Gmail on the Web
1. Open the message.
2. Click the **More** menu (the three dots) at the top right of the message, next to the reply arrow, and choose **Show original**.
3. A new tab opens showing the full source, with a summary panel at the top that reports the **SPF**, **DKIM** and **DMARC** results. Use **Copy to clipboard** to grab the whole thing, or **Download Original** to save it as a file.
## Reading the Key Header Lines
Once you can see the raw source, a handful of lines carry most of the diagnostic value. Headers are listed with the newest at the top, so the very first lines were added last, by the server closest to delivery.
- **`Received:`** the journey, one line per hop. Each server that handled the message inserted its own `Received:` line above the previous one. Read the block *from the bottom upward* to follow the message in the order it actually travelled: the bottom line is the first sending server, the top line is the last server before it reached the mailbox. Each line carries a timestamp, so the gaps between them reveal where any delay occurred.
- **`Return-Path:`** the envelope sender, also called the bounce address. This is the address the receiving server actually accepted the mail from, and it is what SPF is checked against. It is not always the same as the visible `From:` address, and a large mismatch is a common sign of forged or bulk mail.
- **`From:` and `Reply-To:`** the sender and reply address you see in the client. These are written by the sender and can be set to anything, so on their own they prove nothing; their value comes from comparing them against the authentication results and the `Return-Path:`.
- **`Authentication-Results:`** the verdict on the sender, added by the receiving server. This single line usually reports all three checks, for example `spf=pass`, `dkim=pass` and `dmarc=pass`. A `fail` or `softfail` on SPF or DKIM, or a `dmarc=fail`, is the clearest signal that a message may be spoofed or was not properly authorised by the domain it claims to be from.
- **`DKIM-Signature:`** the cryptographic signature the sending domain attached. You do not read this by eye; the `dkim=` result in `Authentication-Results:` is the plain-language outcome of verifying it.
- **`Message-ID:`** a unique identifier for the message. Quote this to support: it lets the team find the exact message in the server logs.
- **`Date:`** when the sender's system says the message was composed. Compare it with the `Received:` timestamps to sanity-check timing.
- **`X-` headers** such as `X-Spam-Status`, `X-Spam-Score` or `X-Mailer:` are optional extras added by mail software. Spam-scoring headers can show why a filter treated a message the way it did.
Here is a shortened, sanitised example of the top of a header block, with the values replaced by examples. It shows the shape to look for rather than any real message:
```
Return-Path:
Received: from mail.yourdomain.com (localhost [127.0.0.1])
by mail.yourdomain.com with LMTP
for ; Tue, 21 Jul 2026 10:15:04 +0200
Received: from mx.example.net (mx.example.net [198.51.100.20])
by mail.yourdomain.com with ESMTPS
for ; Tue, 21 Jul 2026 10:15:02 +0200
Authentication-Results: mail.yourdomain.com;
spf=pass smtp.mailfrom=example.net;
dkim=pass header.d=example.net;
dmarc=pass header.from=example.net
From: "Example News"
Message-ID: <20260721081502.abc123@example.net>
Date: Tue, 21 Jul 2026 10:15:01 +0200
Subject: Your weekly update
```
Reading it: the lower `Received:` line is the sending server `mx.example.net` handing the message to the Noiz mail server; the upper one is the Noiz server delivering it to the mailbox two seconds later. The `Authentication-Results:` line, stamped by the receiving Noiz server, shows all three checks passing, and the `Return-Path:` domain matches the visible `From:` domain. That combination is what a legitimate, well-authenticated message looks like. A spoof would typically show an authentication `fail`, or a `Return-Path:` and `From:` that disagree.
If you want a friendlier view than raw text, paste the copied header block into the [Google Admin Toolbox Messageheader](https://toolbox.googleapps.com/apps/messageheader/) tool, which lays the hops out as a timeline and highlights the delay at each step. It reads only what you paste and needs no sign-in.
## How to Send the Headers to Noiz Support
The value of headers depends entirely on sending them *whole*. A screenshot of a few lines, or the visible `From` and `Subject`, is not enough to trace anything. When you open a ticket:
- **Send the complete raw source, not a partial copy.** Use the client's own **Show source**, **Internet headers**, **View message details**, **Message Source**, **Raw Source** or **Show original** output described above, and include all of it. The best format of all is the message saved as a `.eml` file and attached to the ticket, because it preserves every header exactly; Roundcube, Thunderbird and Gmail can all produce one.
- **Do not edit or redact the headers.** People sometimes remove IP addresses or the `Received:` lines to tidy them up, but those are precisely the parts that make tracing possible. Leave them intact.
- **State the direction and the details.** Say whether the message arrived into your Noiz mailbox or was sent from it, give the affected mailbox address, the approximate date and time *with your timezone* (Noiz mail timestamps are in `+0200`, South African time), and paste or quote the `Message-ID:`. For an outbound problem, remember the headers must come from the recipient's copy, not your Sent copy.
If you suspect a wider spam problem rather than a single message, the companion guide [How to determine the source of spam and reduce it](/email/how-to-determine-the-source-of-spam-and-reduce-it/) walks through using headers to identify where unwanted mail is coming from and how to cut it down.
## Troubleshooting
- **Symptom: you cannot find the header or source option.** In Outlook, make sure the message is open in its own window, not just previewed in the reading pane, then use **File** โบ **Properties** (classic) or **More actions** โบ **View** โบ **View message details** (new Outlook and web). In other clients, look for a **More** or three-dots menu on the open message. If the client is very old, update it; the wording above matches current versions.
- **Symptom: the copied text is only a few lines long.** You copied the short summary shown in the normal view rather than the raw source. Reopen using the exact **source** or **raw** option for your client and select the entire window contents. A genuine header block for a normal message runs to dozens of lines.
- **Symptom: an iPhone or iPad will not show the headers.** The iOS Mail app cannot display raw source. Open the same mailbox in Plesk webmail through the device's browser and use the Roundcube **Show source** steps, or view the message on a computer.
- **Symptom: you forwarded the problem message to support and the headers were gone.** A normal forward rewrites the message and discards the original headers. Instead, forward the message *as an attachment* (most clients offer **Forward as Attachment**), or attach the saved `.eml` file, so the original headers survive intact.
- **Symptom: the authentication results are blank or missing.** Not every server stamps an `Authentication-Results:` line, and a message that never left a single system may not have one. In that case the `Received:` chain and the `Return-Path:` are still useful, so send the whole source and let support interpret it.
Reading headers is a skill, and there is no need to master it to get help. If a message is behaving strangely, capture the full raw source using the steps for your client, attach it to a ticket with the Noiz support team, and note whether it was incoming or outgoing along with the time it happened. On Noiz managed plans the team can line your headers up against the mail server logs and tell you exactly what the servers saw, which is the fastest way to settle a delivery, spam or spoofing question.
# How to Fix the Webmail Error 'Invalid Request. No Data Was Saved.'
Source: https://docs.noiz.ie/email/how-to-fix-the-webmail-error-invalid-request-no-data-was-saved/
If webmail shows the message **"Invalid request. No data was saved."** at the moment you try to do something, this guide explains what it means, why it happens, and how to clear it. Webmail is the version of your mailbox you open in a browser (the software behind it is called Roundcube). The message is a normal protective response from webmail, not a sign that anything is broken. Your mail is safe, nothing has been lost, and there is nothing wrong with your account.
This is written for anyone who reads their email through Noiz webmail. If you would rather skip to the fix, go to **How to Fix It** below. If you want to understand why it happens first, read the two sections before it.
**Last reviewed:** 27 July 2026, against Roundcube webmail (the software behind Noiz webmail), **latest stable**. This guide is written for Noiz hosting and is kept current against the webmail Noiz runs. It complements, and does not replace, the official Roundcube documentation linked below. Webmail screens shift slightly between updates, so where a screen differs from the wording here, the behaviour described still applies.
### Official Documentation Reference
- [Roundcube webmail project](https://roundcube.net/): the home of the open-source webmail software that powers Noiz webmail, for background on how it works.
- [Mozilla Thunderbird](https://www.thunderbird.net/): the free desktop mail application recommended below for anyone who keeps their mail open all day.
## How the Error Looks
The message appears in the browser, on the webmail page itself, reading exactly **"Invalid request. No data was saved."** It shows up at the moment you submit something: sending a message, saving a setting, saving a contact or an identity, or even on the sign-in page as you try to log in.
A few things are worth knowing straight away. It is intermittent, and it usually affects one person rather than everyone on a domain. It does not mean mail has stopped flowing: messages already sent and received are unaffected, and because nothing was actually sent or saved, the attempt leaves no trace in your mail records. It is not an outage, it is not a sign your account has been compromised, and it is not a fault with how your mail is delivered. In almost every case it is the webmail session having quietly timed out, which the next section explains.
## Why It Happens
Every webmail session carries a small security token, and that token has to match a live session held on the server. This is how webmail confirms that the request really came from your active, signed-in session and not from somewhere else.
The session has a limited lifetime. After a period of inactivity the server ends the session automatically. This is a standard, built-in default of the webmail software, not a setting Noiz has chosen for you, and because it is enforced on the server it behaves the same way in every browser.
Once that session has lapsed, the token your browser still holds no longer matches anything on the server. At that point webmail refuses the request and shows **"Invalid request. No data was saved."** rather than half-saving your work against a session that is no longer valid. A stale session still held by the browser produces the same message, which is why it can survive a page reload until the old session is cleared out.
It helps to read this as a protection rather than an error. It exists to stop a forgotten, unattended session, left open on a shared or public computer, from being used to submit data later. The message is webmail doing its job.
## A Common Cause: A Bookmarked Address That No Longer Works
There is one habit that brings this on far more often than any other. After signing in, people frequently bookmark whatever address is showing in the browser bar at that moment. That address carries session and mailbox details that were only valid for that one visit, so the bookmark later lands you on a page that can never finish loading properly, and the message follows.
The bookmark should be the plain webmail address only, and nothing after it. For a Noiz mailbox that is:
```
https://webmail.yourdomain.com
```
Replace `yourdomain.com` with your own domain. It is an example placeholder, not a real address. Save that plain address as your bookmark, sign in fresh each time, and this particular cause disappears.
## How to Fix It
Work through these in order. Most people are back to normal by the first step.
1. **Sign in again.** Return to the webmail sign-in page and log in fresh. This starts a new session and clears most occurrences on its own.
2. **If the message persists, clear the browser's stored data for webmail.** Clear the cookies and site data for your webmail address, close the browser fully (every window, not just the tab), reopen it, and sign in again. This removes the stale session the browser was holding on to.
3. **Check your bookmark or saved shortcut.** If you reach webmail through a bookmark, replace it with the plain address `https://webmail.yourdomain.com` as described above, then sign in from there.
4. **Confirm the cause with a different browser or a private window.** Opening webmail in another browser, or in a private or incognito window, tells you whether a stale session was to blame, because a private window starts with none of your saved data. Treat this as a check, not a permanent cure: the session lifetime applies everywhere, so it is not a setting you can switch off by changing browser.
## How to Avoid It
A few small habits keep it from coming back.
- Try not to leave webmail sitting open and idle part-way through a task. If you start a message, finish and send it rather than leaving it half-written for a long stretch.
- If a webmail tab has been left unattended for a while, reload the page before you submit anything. A fresh page load will tell you immediately if you need to sign in again, before you have typed out a whole message.
- If you keep your mail open all day, use a desktop or mobile mail application rather than webmail. A mail application holds its own connection to the mailbox and is not subject to the webmail session timeout at all, so this message simply cannot happen there. I recommend **Mozilla Thunderbird** as the free option that runs on Windows, macOS and Linux. For setup, see [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/); if you use a different application, the mail settings are available on request.
For a wider view of email problems and how to narrow them down, see [Why Is My Email Not Working? An Email Troubleshooting Guide](/email/why-is-my-email-not-working-an-email-troubleshooting-guide/). For getting into webmail in the first place, see [How to Access Your Noiz Webmail](/plesk/how-to-access-email-from-plesk-webmail/).
If you have worked through the steps above and webmail still shows the message every time, the Noiz support team is glad to help. Reach out with your domain and the exact moment the message appears (signing in, sending, or saving a setting), and support will take it from there.
# How to Forward an Email as an Attachment
Source: https://docs.noiz.ie/email/how-to-forward-an-email-as-an-attachment/
When investigating spam, phishing, or suspicious email activity, the Noiz support team will often ask you to forward the original message **as an attachment** rather than as an ordinary forward. This article explains why that matters and how to do it in the most common email clients.
**Last reviewed:** 27 July 2026. Email client interfaces change often, and Microsoft in particular is moving Windows users from the classic Outlook desktop app to the new Outlook. Menu names may shift between versions, so where a menu item has moved, the drag-into-a-new-message method described below works reliably in every modern client.
## Where to Send It
Forward the message as an attachment to `support@noiz.co.za`. If you would prefer to work through a ticket, you can instead save the message as an `.eml` file and attach it to a support ticket in your Noiz client area. Either route preserves the original message intact.
## Why Forward as an Attachment?
Every email carries a set of hidden technical details called **headers**. Headers record the full path the message took to reach you, the sending server, authentication results (SPF, DKIM, DMARC), the originating IP address, and other forensic data that helps Noiz support identify the sender and improve spam filtering.
When you use the standard **Forward** button, your email client strips the original headers and replaces them with your own. This means the support team can see only that *you* forwarded the message, not where it actually came from. Useful investigation becomes impossible.
Forwarding the email as an **attachment** preserves the original message intact, headers and all. This allows Noiz support to:
- Trace the message back to its true origin.
- Submit accurate samples to the spam filter for training.
- Block the sender or sending server at the mail-system level if appropriate.
- Investigate phishing campaigns and report them upstream.
Screenshots and PDF copies of emails are **not** a substitute. They lose the headers in the same way an ordinary forward does.
## Outlook (Classic Desktop, Windows)
1. Open Outlook and locate the email you want to forward.
2. Single-click to select the message in your inbox (do not open it in a separate window).
3. On the **Home** tab of the ribbon, in the **Respond** group, click **More** (a small drop-down arrow next to the Reply and Forward buttons).
4. Select **Forward as Attachment**.
5. A new message window opens with the original email attached as an Outlook item (`.msg`).
6. Address the message to `support@noiz.co.za` and click **Send**.
**Keyboard shortcut:** `Ctrl + Alt + F`
## Outlook (New Outlook for Windows and Outlook on the Web)
The new Outlook for Windows and the Outlook web app share the same interface. Most recent Windows installs default to the new Outlook, so if your app does not look like the classic desktop version above, follow these steps instead.
1. Open Outlook in your browser, or launch the new Outlook desktop app.
2. Open the email you want to forward.
3. Click the **three-dot menu** (More actions) on the message toolbar, usually at the upper right of the message.
4. Depending on your build, click **Forward as attachment** directly, or hover over **Other reply actions** (also labelled **Advanced actions** in some versions) and then click **Forward as attachment**.
5. A new message window opens with the original email attached.
6. Address the message to `support@noiz.co.za` and click **Send**.
**If the menu option is missing or silently fails:** this is a known and long-running inconsistency in the new Outlook, where the option is absent on some accounts or does nothing when clicked. The reliable workaround is to open a new blank email, then drag the original message from your inbox list directly into the body of the new email. It attaches as an `.eml` file, which preserves the headers in exactly the same way.
## Outlook for Mac
1. Open Outlook and select the email you want to forward.
2. From the menu bar, click **Message**.
3. Select **Forward as Attachment**.
4. A new message opens with the original attached.
5. Address it to `support@noiz.co.za` and click **Send**.
**Keyboard shortcut:** `Shift + Command + J`
## Mozilla Thunderbird
1. Open Thunderbird and locate the email in your inbox.
2. Right-click the message.
3. Hover over **Forward As**.
4. Click **Attachment**.
5. A new compose window opens with the original message attached as an `.eml` file.
6. Address the message to `support@noiz.co.za` and click **Send**.
You can also set Attachment as the default forwarding behaviour under **Settings โ Composition โ Forward messages**.
## Apple Mail (macOS)
1. Open Mail and select the email you want to forward.
2. From the menu bar, click **Message**.
3. Select **Forward as Attachment**.
4. A new message opens with the original attached as an `.eml` file.
5. Address it to `support@noiz.co.za` and click **Send**.
**Keyboard shortcut:** `Shift + Command + F`
## Apple Mail (iOS and iPadOS)
The native Mail app on iPhone and iPad does not have a direct **Forward as Attachment** option, and there is no fully reliable on-device workaround that preserves headers. If you have access to a desktop, Mac, or web browser, forwarding from there is the best option.
1. Open the same mailbox in webmail (see the Roundcube section below) on a desktop or mobile browser, where forwarding as an attachment is supported natively.
2. Alternatively, open the message on a Mac or PC using any of the clients above and forward it as an attachment from there.
## Gmail (Web)
1. Open Gmail in your browser and locate the email you want to forward.
2. Click **Compose** in the top left to open a separate **new message**.
3. Return to your inbox in another browser tab, or by clicking back.
4. Find the email you want to attach and **drag it** from the message list directly into the body of your new compose window.
5. The email attaches as an `.eml` file, preserving all original headers.
6. Address the message to `support@noiz.co.za` and click **Send**.
Alternatively, tick the checkbox next to one or more messages in the inbox list, click the **three-dot menu** at the top of the inbox, and select **Forward as attachment**. A new compose window opens with the selected messages attached.
## Roundcube Webmail (Noiz Webmail)
If you access your Noiz mailbox through webmail (Roundcube), forwarding as an attachment is supported natively and is the most reliable option when your desktop or mobile client is uncooperative.
1. Log in to webmail at the address provided by Noiz, typically `https://webmail.yourdomain.com` (replace `yourdomain.com` with your own domain) or via a link in your control panel.
2. Open the email you want to forward.
3. Click the **Forward** button at the top of the message.
4. From the drop-down arrow next to Forward, select **Forward as attachment**.
5. A new compose window opens with the original email attached as an `.eml` file.
6. Address the message to `support@noiz.co.za` and click **Send**.
## After You Send It
Once the email has been forwarded as an attachment, Noiz support can extract the headers and investigate. Include a brief note describing the issue (for example, "This message bypassed the spam filter" or "I believe this is a phishing attempt"), along with any relevant context such as the date received, whether the sender claims to be someone you know, and whether you clicked any links or opened any attachments.
If you are unsure whether your client is forwarding correctly, send a test message to yourself first. Open the forwarded copy and check that the attachment is an email file (`.eml` or an Outlook item) and not just inline quoted text. If you see only quoted text, the message has been forwarded as an ordinary forward and the headers will have been stripped.
If you are still stuck, contact the Noiz support team and someone will walk you through the process for your specific email client. See [How to Contact Noiz for Support](/getting-started/how-to-contact-noiz-for-support/) for all the ways to reach the team.
# How to Forward an Email in Mozilla Thunderbird
Source: https://docs.noiz.ie/email/how-to-forward-an-email-in-mozilla-thunderbird/
Forwarding passes a message you have already received on to somebody else, with the original text carried underneath your own note. This guide shows you how to forward mail from a Noiz mailbox in Mozilla Thunderbird, how to choose between forwarding *inline* and forwarding *as an attachment*, and why that one choice decides whether a support desk or an IT team can actually trace the message you sent them.
**Last reviewed:** 27 July 2026, against Mozilla Thunderbird **153 ESR** ("Meadow"), the current extended support release. This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below.
### Official Documentation Reference
- [Thunderbird Help](https://support.mozilla.org/en-US/products/thunderbird) for the full support library.
- [Keyboard shortcuts](https://support.mozilla.org/en-US/kb/keyboard-shortcuts-thunderbird) including the forward shortcut used below.
- [How to use attachments](https://support.mozilla.org/en-US/kb/how-use-attachments) for what happens to files when a message is passed on.
- [Thunderbird 153 ESR release notes](https://www.thunderbird.net/en-US/thunderbird/153.0esr/releasenotes/) if your menus do not match the screenshots below.
## Prerequisites
- Thunderbird installed, with your Noiz mailbox already added. If it is not, follow [How to set up your existing email address in Thunderbird](/email/how-to-set-up-email-in-thunderbird/) first.
- A working outgoing (SMTP) connection. A forward is a brand new outgoing message, so it needs the same authenticated SMTP settings that sending a normal message does.
- The message you want to forward fully downloaded. On an IMAP account that syncs headers only, open the message once while online before forwarding it.
## Forward a Single Message
1. Open Thunderbird and click the **Inbox** of the account that holds the message.
2. Select the message in the message list. In the message header, at the top right of the reading pane, Thunderbird shows **Reply**, **Reply All**, **Forward**, **Archive**, **Junk** and **Delete**. Click **Forward**. The keyboard shortcut is `Ctrl` + `L` on Windows and Linux, or `Cmd` + `L` on macOS.

3. A compose window opens with the subject already prefixed `Fwd:` and the original message quoted below the cursor. Type the recipient address in the **To** field, for example `colleague@yourdomain.com`.
4. Type your own note above the quoted text. Leave the subject line and the quoted original alone. The recipient needs the original wording, the original sender and the original date to make sense of why you sent it.
5. Check the **From** dropdown if you have more than one mailbox in Thunderbird. A forward is sent from whichever identity is shown there, and a Noiz mail server will only accept outgoing mail from an address the signed in mailbox is allowed to send as.
6. Click **Send**. A copy is filed in that account's **Sent** folder.

## Inline or as an Attachment
Thunderbird can forward a message in two very different ways, and the difference matters more than it looks.
- **Inline** pastes the original text into the body of your new message. It is easy to read, and it is what most people expect. Files attached to the original are re-attached to your forward. What it does *not* carry is the original message headers: the sending server, the delivery path, the authentication results and the message ID are all rewritten as your message.
- **As attachment** sends the original untouched as a `.eml` file clipped to a short covering message. Every original header survives intact, which is exactly what is needed to trace where a message really came from.
The practical rule: forward inline for ordinary correspondence, and forward as an attachment whenever the message itself is the evidence. Reporting spam, phishing, a spoofed sender or a mail that arrived late or never arrived at all is useless as an inline forward, because the information needed to investigate is stripped out before it reaches the support desk.
### Change the Default
Go to **Settings**, open **Composition**, and set **Forward messages** to **Inline** or **As Attachment** under the General options. Inline is the sensible default for daily use.
### Override It for One Message
Right click the message in the message list, choose **Forward As**, then pick **Inline** or **Attachment**. This ignores the default for that message only, so you do not need to change your settings back and forth. There is more detail in [How to Forward an Email as an Attachment](/email/how-to-forward-an-email-as-an-attachment/).
## Forward Several Messages at Once
Hold `Ctrl` and click each message you want, or click the first and `Shift` click the last for a run of them, then click **Forward**. Thunderbird builds one outgoing message with every selected message attached to it as a separate `.eml` file, whatever your inline setting says. That is the right behaviour for handing a batch of messages to somebody who needs to examine them, but bear in mind the recipient needs a proper mail client to open `.eml` files. Some webmail interfaces will only offer to download them.
## What Forwarding in Thunderbird Does Not Do
Forwarding in Thunderbird is manual and one message at a time. It only happens while you are sitting at the computer with Thunderbird open.
- **To pass every incoming message on automatically**, set up a forwarder on the mail server instead, in your hosting control panel. See [How to Set Up Email Forwarding in Plesk](/plesk/how-to-set-up-email-forwarding-in-plesk/) or [How to Set Up Email Forwarding in ISPConfig](/ispconfig/how-to-set-up-email-forwarding-in-ispconfig/), depending on the panel your hosting uses. A server side forwarder runs whether your computer is on or not.
- **Think twice before auto-forwarding everything to a free mailbox.** When a server forwards mail on to another provider, the message arrives at the destination from your server rather than from the original sender, which breaks SPF alignment and can break DMARC for that message. Large providers frequently mark blanket-forwarded mail as spam or reject it outright, and the bounces come back to your mailbox. Collecting the mail directly with an IMAP client, or with the other provider's own fetch tool, avoids the problem entirely.
- **Thunderbird message filters can forward automatically**, but only while Thunderbird is running and connected. Filters are covered in [How to Organise Your Email with Folders and Filters in Thunderbird](/email/how-to-organise-your-email-with-folders-and-filters-in-thunderbird/).
## Troubleshooting
**Symptom**: recipients say your forwards arrive as an unreadable `.eml` file. Your default is set to **As Attachment**. Change it in **Settings** then **Composition**, or right click the message and use **Forward As** then **Inline** for that one message.
**Symptom**: the attachments on the original message are missing from your forward. The message was not fully downloaded when you forwarded it. This is common on IMAP accounts set to synchronise headers only, and on messages read while offline. Open the message fully while connected, then forward it again.
**Symptom**: sending fails with a relay or authentication error. The outgoing server is either not authenticating or the address in the **From** dropdown does not belong to the mailbox Thunderbird signed in with. Pick the matching identity, and confirm the outgoing server settings against [How to set up your existing email address in Thunderbird](/email/how-to-set-up-email-in-thunderbird/).
**Symptom**: the forward is rejected as too large. A forward re-sends the entire original, attachments included, so a message that arrived close to the size limit will exceed it once your note and the quoting are added. Remove the heavy attachments from the compose window and send them as a download link, or use Thunderbird's Filelink feature.
**Symptom**: the forwarded message lands in the recipient's spam folder. The forward carries the original's content, links and images along with it, so anything that scored badly the first time scores badly again. Forwarding as an attachment usually gets it through, because the suspect content is inside the `.eml` file rather than in the body of your message.
## Getting Help
If a forward will not leave your Noiz mailbox, or mail you forward keeps bouncing back, open a ticket in the Noiz client area with the exact error text from Thunderbird and the date and time of the attempt. On managed plans the Noiz team will match that against the mail server logs and tell you precisely where the message stopped. If you are reporting spam or a phishing attempt, forward it **as an attachment** so the original headers reach the Noiz team intact.
# How to Identify Spam and Phishing Emails
Source: https://docs.noiz.ie/email/how-to-identify-spam-and-phishing-emails/
Phishing and spam emails are one of the most common ways that fraudsters attempt to steal credentials, money, or sensitive information. Modern phishing attempts have become sophisticated and can be very convincing at first glance. This article walks you through the most reliable techniques for identifying suspicious emails, with reference to a real-world example recently received by Noiz.
**Last reviewed:** 27 July 2026. Phishing techniques change constantly, so this guide is reviewed regularly and reflects real attacks recently seen against Noiz customers.
## A Real-World Example
The Noiz support team recently received a phishing email impersonating a "domain renewal notice" for noiz.co.za. The message claimed the domain was about to expire and instructed the recipient to click a link to log in to the control panel and pay.
The email looked superficially professional. It used official-sounding language, listed the consequences of non-renewal, and even passed the major email authentication checks (SPF, DKIM, and DMARC). Yet it was a clear scam. The remainder of this article explains exactly how to spot the warning signs in this and similar attacks.
## 1. Check the Sender Address Carefully
The single most important check is the actual sender email address, not the display name.
In the example above, the display name read **"no-reply"**, which sounds official and impersonal. However, the actual sender address was `newsletter@news.**[unrelated-business].co.za**`, a completely unrelated third-party domain that had no legitimate reason to be sending a notice about noiz.co.za.
**What to check:**
- Does the sender domain match the company they claim to represent? A legitimate Noiz email always comes from a `@noiz.co.za` address.
- Look for lookalike domains designed to deceive (for example, `n0iz.co.za`, `noiz-support.co.za`, or `noiz.com` instead of `noiz.co.za`).
- Be suspicious of "official" communications sent from free email services (Gmail, Outlook.com, Yahoo).
- Mobile email apps often hide the actual address behind the display name. Tap on the sender name to reveal the underlying address before you trust the message.
## 2. Look for Branding Inconsistencies
Legitimate companies invest heavily in consistent branding. A phishing email will almost always get this wrong somewhere.
In the example, the email contained:
- No Noiz logo, colours, or visual identity anywhere in the message.
- A generic placeholder logo hosted on an unrelated content delivery network, with the filename literally `logomylogo.png`.
- No physical company address, registration number, or genuine contact details.
- A vague "ยฉ 2026 All rights reserved" with no company name attached.
If a message claims to be from a company you do business with but looks nothing like their normal communications, treat it as suspicious by default.
## 3. Read the Subject Line Critically
Phishing subject lines almost always try to trigger urgency, fear, or curiosity.
The example used the subject `noiz.co.za [notice-#N1778897375]`, combining the recipient's domain name with a fake-official-looking reference number. The format is designed to look like a system-generated notification, which adds false legitimacy.
Common phishing subject patterns to watch for:
- Urgent renewal or payment notices ("Your domain expires in 24 hours")
- Account suspension threats ("Your account will be deactivated")
- Delivery or shipping notifications you were not expecting
- Refund or prize offers ("You're owed R3,500, claim now")
- Security alerts ("Suspicious login detected, verify now")
- Fake reference numbers or ticket IDs to look official
## 4. Check the Greeting
Legitimate companies with whom you have an account know who you are and will address you by name. The example email began with a generic **"Hello,"** with no first name, no account number, and no domain owner detail.
If a "domain renewal notice" cannot even greet you with the name on the account, it is not from anyone who actually holds your account.
## 5. Hover Over Links Before Clicking
This is one of the most reliable checks and one of the easiest to perform. Before clicking any link in an email, **hover your mouse cursor over it** (on desktop) or **long-press it** (on mobile) to reveal the actual destination URL.
In the example, the prominent "Log in to your Control Panel" link did not point to `noiz.co.za` or anything Noiz-related. It pointed to `https://share.google/...`, a Google share-link redirector designed to disguise the true destination. A legitimate Noiz email would link directly to a Noiz domain, never to a third-party redirector.
**Red flags in links:**
- The link domain does not match the supposed sender's domain
- URL shorteners or redirectors (`bit.ly`, `tinyurl.com`, `share.google`, and similar) in "official" emails
- Numeric IP addresses instead of domain names
- Subdomains designed to deceive (`noiz.co.za.malicious-site.com`; the actual domain is `malicious-site.com`, not `noiz.co.za`)
- Long, random-looking URL paths or query strings
HTTPS in the URL is **not** a guarantee of safety. Anyone can obtain a free SSL certificate for a malicious domain. A green padlock only means the connection is encrypted, not that the site is trustworthy.
## 6. Watch for Pressure and Threats
Phishing emails almost always include a sense of urgency or threat to bypass your critical thinking. The example email warned that:
- The website would go offline
- Email services would stop functioning
- All DNS configurations would cease
- All associated content would be permanently deleted
These dire consequences, combined with an expiration date only two days in the future, are designed to make you act without thinking. Legitimate registrars send renewal reminders well in advance and do not threaten immediate, catastrophic data loss.
Whenever an email pressures you to act *immediately*, slow down and verify through other channels.
## 7. Be Aware of Hidden Technical Tricks
Modern phishing emails use sophisticated techniques to evade spam filters. You may not see these directly, but they explain why even a smart filter occasionally lets one through:
- **HTML entity obfuscation**: the visible text in the example email was encoded character-by-character as HTML entities (for example, `Hello` instead of "Hello"). The message looks normal when rendered but appears as gibberish to text-based spam filters.
- **Hidden content camouflage**: the example email contained a large block of unrelated newsletter text hidden in a paragraph styled with `font-size: 0`. The recipient never sees this text, but spam filters do, and may mistakenly classify the message as a legitimate marketing email.
- **Image-only content**: some phishing emails are essentially one big image with no readable text, defeating content-based filtering entirely.
The takeaway: spam filters are helpful but not infallible. A clean spam folder does not guarantee that everything in your inbox is safe.
## 8. Authentication Pass Does Not Mean Legitimate
This is perhaps the most important and least-understood point in modern email security.
SPF, DKIM, and DMARC are three technical standards that verify whether an email was sent by a server authorised to send mail for the sender's domain. In the example email, all three checks **passed**. So why was it still a phishing attempt?
Because the spammer set up their own SPF, DKIM, and DMARC on an unrelated domain they controlled (or had compromised). Authentication confirms only that *the message genuinely came from the domain it claims to be from*. It does not confirm that the sender has any legitimate relationship with you, or that the content is trustworthy. A perfectly authenticated email from a domain you have never heard of is not safer than any other email from a domain you have never heard of.
Authentication is a useful signal alongside everything else in this article; it is not a substitute for the other checks.
## 9. Be Cautious With Attachments
The example phishing email did not contain attachments, but many do. Treat any unexpected attachment as suspicious, particularly:
- Executable files (`.exe`, `.bat`, `.scr`, `.js`, `.vbs`, `.msi`)
- Office documents (Word, Excel) requesting that you "enable macros" or "enable editing"
- Password-protected ZIP files (the password is usually in the email body; this technique is used specifically to evade antivirus scanning)
- Files with double extensions disguising the real file type (`invoice.pdf.exe`)
- HTML files that open a fake login page in your browser
If in doubt, do not open the attachment. Confirm with the supposed sender through a separate, trusted channel first.
## What to Do If You Receive a Suspicious Email
1. **Do not click any links** in the email.
2. **Do not open or download any attachments.**
3. **Do not reply** to the sender, even to tell them to stop.
4. If the email impersonates Noiz or a service you use through Noiz, **forward it to the Noiz support team as an attachment** so the headers can be analysed. See the related article on *How to Forward an Email as an Attachment* for instructions.
5. Mark the email as spam or phishing in your email client to help train your spam filter.
6. Delete the message after reporting it.
7. If you have already clicked a link or entered any credentials, change your password immediately and contact the Noiz support team for guidance.
## When in Doubt, Verify Through Another Channel
If an email claims to be from Noiz, your bank, your registrar, or any other service you trust, and something about it does not feel right, do not act on the email. Instead:
- Log in to the service directly through a bookmark or by typing the address into your browser, and check whether any genuine notice is waiting for you in the account.
- Phone the company on a number you already know to be correct (not the one in the email).
- For Noiz-related concerns, contact the Noiz support team directly through the client area or the published support address.
A few minutes of verification is always worth more than the cost of a successful phishing attempt.
## Further Reading
- [Google: Avoid and report phishing emails](https://support.google.com/mail/answer/8253): how to recognise and report phishing from within Gmail.
- [Anti-Phishing Working Group](https://apwg.org/): an industry coalition that collects and acts on reported phishing; you can forward suspected phishing to `reportphishing@apwg.org`.
# How to Organise Your Email with Folders and Filters in Thunderbird
Source: https://docs.noiz.ie/email/how-to-organise-your-email-with-folders-and-filters-in-thunderbird/
This guide shows you how to keep a busy mailbox under control in Mozilla Thunderbird using five built-in tools: **folders** to file your mail, **message filters** to sort incoming mail automatically, **tags** (older versions called them labels) to colour-code messages, **saved searches** to build living views across folders, and the **archive** to clear the inbox without deleting anything. It is written for Noiz clients whose mailbox is hosted on the Noiz mail platform and connected to Thunderbird over IMAP. The emphasis here is on the decisions that matter on hosted, synced mail, especially the difference between folders that live on the server and folders that live only on your computer, because that single distinction changes what everyone else sees.
**Last reviewed:** 27 July 2026, against Thunderbird **140** (the current monthly Release; the parallel ESR track behaves the same for these features). This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below. Thunderbird's menus move slightly between versions, so if a label or path differs from what you see, the concept still applies and the official pages below carry the exact current wording.
### Official Documentation Reference
- [Organizing your messages using Filters (Mozilla Support)](https://support.mozilla.org/en-US/kb/organizing-your-messages-using-filters): the official reference for the Message Filters dialog, including every condition and action.
- [Archived Messages (Mozilla Support)](https://support.mozilla.org/en-US/kb/archived-messages): the official explanation of the Archive button and Archive Options.
- [Thunderbird Support (Mozilla Support)](https://support.mozilla.org/products/thunderbird): the full support hub, covering folders, tags, search folders and the current interface for your exact version.
## Prerequisites
- Your Noiz mailbox already [added as an account in Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/) over IMAP. Almost everything below depends on that IMAP connection. Thunderbird's autoconfig often cannot find custom-domain settings, so if the account is not yet set up you will usually enter the server details by hand: incoming IMAP host `mail.yourdomain.com`, port `993`, SSL/TLS; outgoing SMTP host `mail.yourdomain.com`, port `465`, SSL/TLS; username the full email address; normal password authentication. Replace `yourdomain.com` with your own domain.
- An actual mailbox to organise. If you have not yet [created the mailbox on the Noiz platform](/plesk/how-to-create-an-email-address-in-plesk/), do that first.
## The One Thing to Understand First: Server Folders vs Local Folders
Before you create a single folder, it is worth understanding where a folder actually lives, because this is the source of most confusion with hosted mail.
In the folder pane on the left, your Noiz mailbox appears as an account named after your email address, and below all your accounts there is a separate account called **Local Folders**. The two behave very differently:
- **Folders under your Noiz account are IMAP folders.** They live on the Noiz mail server. Anything you do to them is synced back: create a folder and it appears in webmail and on your phone; move a message into one and it moves there everywhere. This is usually what you want, because your filing follows you across every device.
- **Folders under Local Folders live only on this computer.** They are stored in Thunderbird's profile on your hard drive and are never uploaded. Nobody else sees them, they are not in webmail, and they are not on your phone. They also are not part of any Noiz backup of your mailbox, because the server never receives them.
**The gotcha to keep front of mind:** a folder you create under your IMAP account is a real folder on the Noiz server, so it turns up in the Noiz webmail folder list too, exactly as you named it. If you would rather webmail stayed tidy, keep your filing structure deliberate, because it is shared. Conversely, moving a message into a Local Folder quietly pulls it off the server, so it disappears from webmail and from your other devices. That can be exactly what you want (to free server space) or a nasty surprise (mail you thought was safely filed is now on one laptop only). Decide on purpose.
## Create and Manage Folders
### Create a New Folder
1. In the folder pane, right-click the account or the parent folder you want the new folder to sit inside. Right-click your Noiz account name to create a top-level folder on the server, or right-click **Local Folders** to create one only on this computer.
2. Choose **New Folder**.
3. In the **New Folder** dialog, type a name, confirm the **Create as a subfolder of** location, and click **Create Folder**.
A folder created under the Noiz account is created on the server immediately and will appear in webmail within moments. Renaming or deleting an IMAP folder in Thunderbird likewise renames or deletes it on the server for every device, so treat those actions with the same care you would in webmail.
### If a Server Folder Is Missing: Subscribe to It
With IMAP, Thunderbird only shows the server folders you are subscribed to. If a folder exists in webmail but is not visible in Thunderbird, right-click your Noiz account name and choose **Subscribe**. Tick the folders you want Thunderbird to show and sync, then click **OK**. This is the usual fix when a folder created elsewhere, or on another device, does not appear.
## Message Filters: Sort Incoming Mail Automatically
A message filter is a rule that Thunderbird applies to mail as it arrives (or on demand): if a message matches your conditions, Thunderbird performs the actions you chose, such as moving it to a folder, tagging it, flagging it, or forwarding it.
**Important distinction for hosted mail:** Thunderbird filters run on your computer, inside Thunderbird, only while Thunderbird is open and collecting mail. They are not the same as server-side rules. If you want mail sorted even when Thunderbird is closed, or the same sorting to apply on your phone and in webmail, that has to be done as a server-side rule in the Noiz webmail settings instead. Thunderbird filters are perfect for how one person works at one desk; they are not a mailbox-wide policy.
### Open the Message Filters Dialog
1. Click the **app menu** button (the three-line menu, top-right) and choose **Message Filters**. If you keep the classic menu bar visible, **Tools** > **Message Filters** does the same thing.
2. At the top of the dialog, set **Filters for** to your Noiz account. Filters belong to a specific account, so choose the right one.
### Create a Filter
1. Click **New**. The Filter Rules window opens.
2. Give the filter a clear **Filter name**, for example `Invoices to Accounts folder`.
3. Under **Apply filter when**, tick when it should run. **Getting New Mail** handles incoming mail automatically; **Manually Run** lets you trigger it yourself later; other options cover archiving and after sending. You can tick more than one.
4. Choose how conditions combine: **Match all of the following** (every condition must be true), **Match any of the following** (any one is enough), or **Match all messages**.
5. Build each condition from the three dropdowns: a property (such as **From**, **Subject**, **To**, **To or Cc**, **Body**, **Date** or **Age in Days**), a test (such as **contains**, **is**, **begins with**), and a value. Use the **+** button to add more conditions.
6. Under **Perform these actions**, choose what to do. Common choices are **Move Message to** or **Copy Message to** a folder, **Add Tag**, **Mark As** (read or starred), **Set Priority**, **Forward Message to** an address, and **Delete Message**. You can add several actions, and **Stop Filter Execution** tells Thunderbird to run no further filters on that message.
7. Click **OK** to save the filter.
**Where the action sends the mail matters.** If a filter moves a message into a folder under your Noiz account, it moves on the server and stays visible in webmail and on your phone. If it moves the message into a Local Folder, it leaves the server, so it vanishes from webmail and your other devices even though the filter looks like it just tidied your inbox. Pick the destination with the earlier section in mind.
### Filter Order and Running Filters by Hand
Filters run from top to bottom in the list, so order matters. Select a filter and use the up and down controls to reorder it, and remember that a **Stop Filter Execution** action ends processing for that message at that point.
To apply filters to mail that is already sitting in a folder (for example after you create a new rule), select the folder, then at the bottom of the Message Filters dialog set **Run selected filter(s) on** to that folder and click **Run Now**. You can also right-click a folder and use the run-filters option, or select messages and apply filters to just those.
## Tags: Colour-Code Without Moving Anything
Tags let you label a message (Important, Work, and so on) with a colour, without moving it out of its folder. A message can carry several tags at once, which is their advantage over folders: a mail can be both *Work* and *To Do* without you having to choose one folder for it.
### Apply and Remove Tags
- Select one or more messages and press a number key `1` to `9` to apply the matching tag; press `0` to clear all tags from the selection.
- Or right-click the message, open the **Tag** submenu, and pick a tag. The same submenu removes tags.
### Create Your Own Tags and Colours
1. Open the **app menu** > **Settings** and go to the **General** panel.
2. Scroll to the **Tags** section. Here you can **Add** a tag, edit or delete existing ones, and set each tag's colour.
3. The order tags appear in this list is the order the number keys map to, so put the tags you use most at the top.
**Do tags sync to webmail?** Partly. Thunderbird stores tags as IMAP keywords on the server, so the fact that a message is tagged does travel with the message. However, the Noiz webmail interface and other mail apps will not necessarily show your tag *names* and *colours* the same way Thunderbird does; the built-in tags map to standard keywords, while custom tag names may appear only as plain keyword text elsewhere. Treat tags as a Thunderbird-first organising tool that mostly, but not perfectly, carries across.
## Saved Searches: Living Views Across Folders
A saved search (also called a search folder or virtual folder) looks like a folder in the pane, but it holds no mail of its own. Instead it shows every message, wherever it is filed, that matches criteria you set. Nothing is moved or copied, so a saved search is completely non-destructive and never changes what webmail shows.
They are ideal for questions like "every unread message tagged Important across all my folders" or "everything from one client, wherever I filed it".
1. Right-click your Noiz account name and choose **New** > **Saved Search** (the classic menu bar route is **File** > **New** > **Saved Search**).
2. Name the search and confirm where it should appear in the pane.
3. Under **Search for messages which match**, build conditions exactly as you did for filters (match all or any, then property, test and value).
4. Click **Choose** and tick the folders to include; tick the option to search subfolders if you want the whole tree covered.
5. Click **OK**. The saved search appears in the folder pane with a search-folder icon and updates itself as matching mail arrives.
Because a saved search is only a view, deleting it deletes the view, not the messages. The real mail stays exactly where it was filed.
## The Archive: Clear the Inbox Without Deleting
Archiving moves a message out of the inbox and into a dated **Archives** folder, so your inbox shows only live items while nothing is thrown away. Select one or more messages and click the **Archive** button in the message toolbar, or press the `A` key.
On your IMAP-connected Noiz account the **Archives** folder is a folder on the server. That has two consequences worth knowing:
- **Archived mail is still on the server**, so it appears in webmail and on your phone, and it still counts towards your Noiz mailbox quota. Archiving tidies the inbox; it does not free up mailbox space and it is not a backup.
- If your goal is to reduce what is stored on the server (for quota reasons), that means moving mail into a **Local Folder** instead, which removes it from the server. Accept the trade-off from the first section: that mail then lives only on this computer and leaves webmail and your other devices.
### Set How the Archive Is Organised
1. Right-click your Noiz account name and choose **Settings** to open Account Settings.
2. Go to **Copies & Folders** and find the **Message Archives** section. Confirm **Keep message archives in** points at the Archives folder you want.
3. Click **Archive Options**. Choose how archives are grouped: a **single folder**, **yearly** folders (for example `Archives/2026`), or **monthly** folders. You can also tick the option to keep the original folder structure of archived messages, so a message archived from a subfolder lands in a matching path inside Archives.
4. Click **OK**.
## Troubleshooting
- **Symptom**: a folder you created in Thunderbird shows up in webmail and you did not expect it. That folder is under your IMAP account, so it is a real server folder shared everywhere. If you wanted it private to this computer, create it under **Local Folders** instead and move the contents across (accepting that it then leaves the server).
- **Symptom**: a filter is not running. Check that **Getting New Mail** is ticked in the filter, that the filter is enabled (its checkbox in the list), that it belongs to the correct account in **Filters for**, and remember filters only run while Thunderbird is open. For mail sorted around the clock, use a server-side rule in Noiz webmail instead.
- **Symptom**: filtered mail seems to have disappeared from webmail and your phone. The filter is moving messages into a Local Folder, which removes them from the server. Edit the filter's **Move Message to** action to point at a folder under your Noiz account so filing stays synced.
- **Symptom**: a server folder exists in webmail but not in Thunderbird. Right-click your account, choose **Subscribe**, and tick the missing folder.
- **Symptom**: your mailbox is over quota even though you have been archiving. Archiving keeps mail on the server, so it still counts. Empty the **Trash**, and for anything you must keep but do not need on the server, move it into a Local Folder or export it, understanding it then lives only on that computer.
- **Symptom**: tags you applied in Thunderbird look different or missing in webmail. Tag keywords sync, but names and colours are a Thunderbird presentation; other clients may show custom tags as plain keyword text or not at all. This is expected, not a fault.
If you get stuck, open a support ticket with the Noiz support team. Include your email address, whether the folder in question is under your account (IMAP) or Local Folders, and a screenshot of your folder pane or the filter or archive setting you are working on, and Noiz will help you get it sorted.
# How to Protect Your Domain from Spoofing and Improve Email Deliverability
Source: https://docs.noiz.ie/email/how-to-protect-your-domain-from-spoofing-and-improve-email-deliverability/
Email is the backbone of business communication, but without the right authentication controls your domain can be spoofed, your legitimate messages can land in spam, and your sending reputation can suffer. This guide explains how to secure your domain with SPF, DKIM and DMARC, and how to roll those protections out in stages so you never accidentally block your own mail.
**Last reviewed:** 27 July 2026. SPF, DKIM and DMARC are stable, published internet standards (RFC 7208, RFC 6376 and RFC 7489). This guide is written for Noiz hosting and is kept current against those standards and the published sender guidance of the major mailbox providers. It complements, and does not replace, the reference documents linked below.
### Official Documentation Reference
- [RFC 7208: Sender Policy Framework (SPF)](https://www.rfc-editor.org/rfc/rfc7208)
- [RFC 6376: DomainKeys Identified Mail (DKIM)](https://www.rfc-editor.org/rfc/rfc6376)
- [RFC 7489: Domain-based Message Authentication, Reporting and Conformance (DMARC)](https://www.rfc-editor.org/rfc/rfc7489)
- [Google: Email sender guidelines](https://support.google.com/mail/answer/81126)
- [Microsoft: Email authentication in Microsoft 365](https://learn.microsoft.com/en-us/defender-office-365/email-authentication-about)
- [DMARC.org: Overview](https://dmarc.org/overview/)
## Prerequisites
- You can edit the DNS (TXT) records for your domain. On Noiz hosting this means the domain uses the Noiz nameservers (`ns1.noiz.co.za` and `ns2.noiz.co.za`) so records are managed in your control panel, or you have access to wherever the domain's DNS is hosted.
- You know which servers and services actually send mail as your domain: your Noiz mailbox, plus any third-party senders such as a marketing platform, CRM, help desk or billing system.
- A little patience for DNS to propagate. Changes usually take effect within minutes, but allow up to the record's TTL before testing.
## Why Basic Authentication Isn't Enough
Attackers can spoof the visible `From:` address that your recipients see even when they are not sending from your servers. SPF on its own only checks the envelope sender (the Return-Path), which end users never see, so a message can pass SPF and still show a forged `From:` address. To properly protect your brand you need all three controls working together: SPF to authorise your sending sources, DKIM to sign your mail, and DMARC to tie authentication to the visible `From:` address and tell receivers what to do when it fails.
## Step 1: Publish a Strict SPF Record
SPF defines which mail servers are allowed to send for your domain. Limit it to your actual outbound IP addresses or mail providers, and end it with `-all` so everything else is rejected. Publish it as a single TXT record on the domain apex.
```
yourdomain.com. 300 IN TXT "v=spf1 ip4:203.0.113.25 include:mailprovider.example -all"
```
Replace `203.0.113.25` with your real sending IP and `mailprovider.example` with any provider you send through. Add one `ip4:`, `ip6:` or `include:` for each legitimate source.
**Verification:** Run `dig +short TXT yourdomain.com` and confirm exactly one line begins with `v=spf1`. Send a test message and check the headers for `spf=pass`.
## Step 2: Enable DKIM Signing
DKIM signs each outgoing message with a private key held on the sending server and publishes the matching public key in DNS under a named selector. Receivers use the published key to confirm the message was genuinely sent by you and was not altered in transit.
```
default._domainkey.yourdomain.com. 300 IN TXT "v=DKIM1; k=rsa; p=MIIBIjANBgkqh..."
```
On Noiz Plesk hosting you can switch DKIM on per domain under **Mail Settings** for that domain (the option to sign outgoing mail with DKIM). When the domain uses the Noiz nameservers, the panel generates the key pair and publishes the public key for the `default` selector automatically, so there is nothing to paste by hand. If your DNS is hosted elsewhere, copy the generated public-key record into that provider. Use a 2048-bit key where you have the choice.
**Verification:** Query your selector with `dig TXT default._domainkey.yourdomain.com` and send a test email. The headers should show `dkim=pass header.d=yourdomain.com`.
## Step 3: Enforce Alignment With DMARC
DMARC requires that SPF or DKIM passes *and* that the domain it authenticated matches the visible `From:` address (this is called alignment). It also lets you collect reports and tell receivers what to do with mail that fails. Roll it out in three stages so you can watch the reports before you enforce anything.
### Monitoring Mode
```
_dmarc.yourdomain.com. 300 IN TXT "v=DMARC1; p=none; adkim=s; aspf=s; fo=1; rua=mailto:dmarc-reports@yourdomain.com"
```
This generates aggregate reports without affecting delivery. Stay here until the reports show all of your legitimate mail authenticating correctly, which usually takes one to two weeks.
### Quarantine Mode
```
_dmarc.yourdomain.com. 300 IN TXT "v=DMARC1; p=quarantine; sp=quarantine; adkim=s; aspf=s; fo=1; rua=mailto:dmarc-reports@yourdomain.com"
```
Messages that fail alignment are typically delivered to the spam or junk folder rather than rejected. This is a safe middle step before full enforcement.
### Reject Mode
```
_dmarc.yourdomain.com. 300 IN TXT "v=DMARC1; p=reject; sp=reject; adkim=s; aspf=s; fo=1; rua=mailto:dmarc-reports@yourdomain.com"
```
Messages that fail alignment are rejected outright. This is the strongest protection against spoofing and is the policy the major mailbox providers now expect from bulk senders.
### A Note on Strict Versus Relaxed Alignment
The records above use `adkim=s` and `aspf=s`, which demand an exact domain match. Strict alignment is the tightest option, but it can trip up legitimate mail that authenticates on a subdomain or a slightly different envelope domain. The DMARC default is relaxed alignment (the same registered domain is enough), and relaxed is often the safer starting point unless you have a specific reason for strict. If test mail fails DMARC while SPF and DKIM individually pass, loosen to `adkim=r` and `aspf=r` and re-test.
## Subdomain Considerations
If you send mail from subdomains such as `mail.yourdomain.com` or `alerts.yourdomain.com`, either publish a DMARC record for each subdomain or use the `sp=` tag in the parent record to set their policy. If you do not send from any subdomains, keep `sp=reject` so attackers cannot abuse them to impersonate your brand.
## Adding These Records on Noiz Hosting
When your domain uses the Noiz nameservers, all three records are TXT records you add through your control panel's DNS management for the domain (on Plesk this is **Websites & Domains** > **DNS Settings**). SPF and DMARC are single TXT records you create by hand; DKIM is best switched on through the mail settings so the panel manages the key for you. If the domain's DNS is hosted with a third party, add the same records there instead. If you are not sure where your DNS is answered from, the Noiz support team can confirm it for you.
## Operational Best Practices
- **Reverse DNS (PTR):** The IP address of your mail server should resolve to a hostname you control, and that hostname should resolve back to the same IP.
- **HELO/EHLO identity:** Your mail server should present its own hostname consistently in the SMTP banner.
- **Consistent From addresses:** Use clear role addresses such as `noreply@` or `support@` rather than system accounts like `root@`.
- **One SPF record:** A domain may publish only one SPF record. Multiple SPF TXT records cause validation to fail, so merge every source into a single record.
- **Stay under the SPF lookup limit:** SPF allows a maximum of ten DNS lookups. Too many `include:` mechanisms cause a permanent error (permerror) and break authentication, so keep the record lean.
- **Third-party senders:** Authorise every SaaS platform that sends as you (marketing, CRM, billing) with the correct SPF include and, where offered, DKIM signing for your domain.
## Testing and Monitoring
1. Send test emails to Gmail, Outlook and other major providers.
2. Open the *Authentication-Results* header on each and confirm `spf=pass`, `dkim=pass` and `dmarc=pass`.
3. Review the DMARC aggregate reports delivered to your `rua` address to see which servers are sending on your behalf and whether they authenticate. A DMARC report analyser makes these XML reports far easier to read.
**About failure reports:** the older per-message failure reports (the `ruf` tag) are barely supported by the major mailbox providers today for privacy reasons, so aggregate reports are what you should rely on for monitoring.
## Common Pitfalls
- **Malformed DNS records:** Watch for stray quotes, semicolons or line breaks in TXT records.
- **Overly permissive SPF:** Avoid `+all`, and treat `~all` (softfail) as a stepping stone only. Use `-all` to actually enforce.
- **Unaligned third-party mail:** Newsletters or services that are not DKIM-signed with your domain will fail DMARC unless you configure them properly.
- **Multiple SPF TXT records:** Only one is valid. Consolidate every sending source into a single record.
- **Enforcing too early:** Moving straight to `p=reject` before the aggregate reports are clean is the quickest way to block your own legitimate mail.
Email authentication rewards patience: monitor first, tighten in stages, and read the reports before you enforce. If you host with Noiz and would like a hand publishing or verifying your SPF, DKIM and DMARC records, contact the Noiz support team and they will help you get to a clean `p=reject` policy safely.
# How to Read, Send and Delete Email on Android
Source: https://docs.noiz.ie/email/how-to-read-send-and-delete-email-on-android/
This guide shows you how to read, send and delete email on an Android phone or tablet using the Gmail app. It covers opening and reading messages, switching between accounts, viewing all your inboxes in one list, composing and sending, replying, attaching files, deleting messages, controlling new-mail notifications, and refreshing your inbox when messages are slow to arrive. It applies whether you use a Gmail address or a mailbox at your own domain, a mailbox is sometimes called an email account, and the Gmail app can display both types side by side.
The single most important thing in this guide is the section on what deleting a message on your phone actually does on the mail server. On a mailbox hosted with Noiz that one behaviour decides whether a deleted message is gone from every device you own, or still sitting safely in webmail. Google's documentation explains the buttons; this guide explains the consequences on your hosting account, the decisions you have to make, and how to prove to yourself that it worked.
**Last reviewed:** 27 July 2026, against the current Gmail for Android release. This guide is written for Noiz hosting and is kept current against Gmail for Android. It complements, and does not replace, the official Gmail documentation linked below.
### Official Documentation Reference
- [Sign in to Gmail (Android)](https://support.google.com/mail/answer/8494?co=GENIE.Platform%3DAndroid): signing in and adding a Google account
- [Add another email account (Android)](https://support.google.com/mail/answer/6078445?co=GENIE.Platform%3DAndroid): adding accounts, switching, and All inboxes
- [Send or unsend Gmail messages (Android)](https://support.google.com/mail/answer/6588?co=GENIE.Platform%3DAndroid): composing, sending, replying and forwarding
- [Send attachments with your Gmail message (Android)](https://support.google.com/mail/answer/6584?co=GENIE.Platform%3DAndroid): attaching files and size limits
- [Delete messages in Gmail (Android)](https://support.google.com/mail/answer/7401?co=GENIE.Platform%3DAndroid): deleting, Trash, and recovering deleted mail
- [Archive Gmail messages (Android)](https://support.google.com/mail/answer/6576?co=GENIE.Platform%3DAndroid): how archiving differs from deleting
- [Change Gmail notifications (Android)](https://support.google.com/mail/answer/1075549?co=GENIE.Platform%3DAndroid): notification levels, sounds, and label alerts
- [Fix sync errors with the Gmail app (Android)](https://support.google.com/mail/answer/6383854?co=GENIE.Platform%3DAndroid): refreshing the inbox and repairing sync
- [RFC 9051: Internet Message Access Protocol (IMAP), version 4rev2](https://www.rfc-editor.org/rfc/rfc9051.html): the standard that defines server-side mailbox behaviour
- [RFC 1939: Post Office Protocol, version 3 (POP3)](https://www.rfc-editor.org/rfc/rfc1939.html): the standard that defines download-and-remove behaviour
## Prerequisites
- An Android phone or tablet with the **Gmail** app installed and up to date (update it from the Play Store if unsure).
- A working mailbox and its password. If your email is hosted with Noiz on a Plesk plan and the mailbox does not exist yet, first [create an email address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/).
- The mailbox already added to the device. If it is not, work through [how to set up email on Android](/email/how-to-set-up-email-on-android/) first.
- An active internet connection (Wi-Fi or mobile data).
## Open and Read Your Email
1. Unlock your device and open the **Gmail** app.
2. The app opens in the inbox of the account you last used. Unread messages appear in bold, with the newest at the top.
3. Tap any message to open and read it. Attachments appear at the bottom of the message, tap one to preview or download it.
4. Tap the back arrow in the top left to return to your inbox.
## Switch Between Accounts
If you have more than one account in the Gmail app, for example a personal Gmail address plus a mailbox at your own domain, you can move between them without signing out.
### Switch to Another Account
1. Open the **Gmail** app.
2. In the top right, tap your **Profile picture** (or your initial, if you have not set a picture).
3. In the panel that opens, tap the account you want to view.
4. The inbox reloads and shows that account's mail. Repeat the same steps to switch back.
### View All Your Inboxes in One List
1. Open the **Gmail** app.
2. In the top left, tap the **Menu** icon (three horizontal lines).
3. Tap **All inboxes**. Mail from every account on the device now appears in a single combined list, and each message shows which account it belongs to.
### Add Another Account to the Gmail App
If the account you want to read is not on the device yet:
1. In the top right, tap your **Profile picture**, then tap **Add another account**.
2. For a Gmail address, choose **Google** and follow the sign-in prompts.
3. For a mailbox at your own domain, choose **Other**, enter the full address, for example `info@yourdomain.com` (an example only, replace it with your real address), tap **Next**, choose **Personal (IMAP)**, enter the mailbox password, and follow the on-screen steps. The incoming and outgoing server settings for a Noiz-hosted mailbox are shown in your hosting control panel and in your welcome email.
That **Personal (IMAP)** versus **Personal (POP3)** choice is the most consequential tap in the whole setup, and it is easy to make once and forget about for years. It decides what happens every time you delete a message, and it is explained in full further down this guide.
## Send, Reply and Forward Mail
### Compose and Send a New Message
1. Open the **Gmail** app and make sure the account you want to send from is the one showing (see **Switch Between Accounts** above).
2. Tap **Compose**, the pencil button in the bottom right.
3. In the **To** field, type the recipient's address. To copy other people in, tap the small chevron at the end of the **To** row to reveal **Cc** and **Bcc**.
4. Fill in **Subject**, then type your message in the body.
5. Tap **Send**, the paper-plane icon in the top right.
### Check Which Address the Message Is Coming From
This is the most common avoidable mistake on a phone with more than one account, and it costs you replies rather than throwing an error.
- The **From** line at the top of the compose screen shows the sending address. If only one account is on the device the line is often hidden, tap the **From** row or the chevron to reveal and change it.
- If you started composing from the **All inboxes** view, Gmail picks your default account rather than the one whose message you were just reading. Always glance at the **From** line before tapping **Send**.
- The address in **From** is the address your recipient sees and the address their reply goes to. A quote sent from a personal Gmail address instead of `sales@yourdomain.com` looks less credible, and the reply lands in a mailbox nobody at the business is watching.
- Replying to an existing message always uses the account that received it, so replies are safe. Only new messages are at risk.
### Attach a File
1. In the compose screen, tap the **paperclip** icon in the top toolbar.
2. Choose **Attach file** to pick something from the device (Downloads, Photos, Documents), or **Insert from Drive** to send a link to a file in Google Drive instead of the file itself.
3. The attachment appears as a chip below the subject line. Tap the **X** on the chip to remove it before sending.
Size is the gotcha, not the procedure. Google caps a Gmail message at **25 MB**, and most receiving mail servers apply a ceiling in the same region. Mail attachments are encoded for transport, which inflates them by roughly a third, so a 20 MB video leaves your phone as a message of about 27 MB and can bounce even though the file itself was under the limit. Phone cameras produce files that cross this line easily.
If a large file has to go out, upload it somewhere and send the link, or compress it first. A bounce for an oversized attachment can take minutes or hours to come back, so by the time you know it failed the recipient has been waiting all morning.
### Reply and Forward
1. Open the message.
2. Tap **Reply** (the single curved arrow) to answer the sender only, **Reply all** (the double arrow) to answer everyone on the message, or open the three-dot menu and tap **Forward** to pass it on to somebody new.
3. Type your text above the quoted original and tap **Send**.
Two things worth knowing on a small screen. **Reply** and **Reply all** sit next to each other and are easy to confuse in a hurry, so check the recipient chips before sending anything you would not want the whole distribution list to read. And **Forward** carries the original attachments with it, which is convenient until you forward a thread that contains something further down that you had not scrolled to.
### Confirm the Message Actually Went
Right after you tap **Send**, a short confirmation appears at the bottom of the screen with an **Undo** option. Once that disappears the message is on its way.
For a mailbox at your own domain the real proof is server-side. Open **Menu**, tap **Sent**, and confirm the message is listed. Then sign in to webmail in a browser on any device and check that the same message is in the **Sent** folder there. If it is in webmail, the message reached your mail server and left it. If the phone shows it as sent but webmail does not, the account is almost certainly set up as POP3 rather than IMAP, which is covered next. Depending on the control panel on your plan, see [accessing email from Plesk webmail](/plesk/how-to-access-email-from-plesk-webmail/) or [accessing email from cPanel webmail](/cpanel/how-to-access-email-from-cpanel-webmail/).
## Delete Mail, and What That Does on the Server
Deleting on a phone is two taps. Understanding where the message went is the part that saves you from ringing support about a contract you thought you still had.
### Delete a Single Message
1. Open the **Gmail** app and go to the inbox holding the message.
2. Press and hold the message for a second. It becomes selected and a toolbar appears at the top of the screen.
3. Tap the **bin** icon in that toolbar. You can also open the message first and tap the bin at the top.
4. A short confirmation appears at the bottom of the screen with an **Undo** option. Tapping **Undo** straight away puts the message back. Wait a few seconds and the option disappears.
### Delete Several Messages at Once
1. Press and hold the first message to select it.
2. Single-tap each additional message you want to remove. The counter at the top of the toolbar shows how many are selected.
3. Tap the **bin** icon once. All of them go together, and a single **Undo** restores the whole batch.
Swiping a message sideways is quicker, but check what your swipe is set to do before you rely on it. Under **Menu**, **Settings**, **General settings**, **Swipe actions**, you can assign the left and right swipe to **Archive**, **Delete**, **Mark as read**, **Move to** or **Snooze**. People clear an inbox for months on the assumption they are deleting, then discover the mail was being archived all along, or the reverse.
### Archive Is Not Delete
**Archive** takes a message out of the inbox and leaves it on the server, findable through search or the **All Mail** or archive folder. **Delete** moves it to **Trash**, which is a staging area before it is destroyed. Archiving keeps a message, and keeps it counting against your mailbox space. Deleting is a decision to lose it.
### The Part That Matters: IMAP Versus POP3
When the mailbox was added to the phone, it was set up as either **IMAP** or **POP3**. Those two protocols treat your phone completely differently, and nothing on the delete screen tells you which one you have.
**IMAP** treats the server as the master copy. Your phone is a window onto the mailbox that lives on the mail server. Every action you take is sent back to the server, so deleting a message on the phone deletes it on the server, and it then vanishes from webmail, from your laptop, from your tablet and from anywhere else that mailbox is open, as each of them syncs. This is the correct behaviour and it is what almost everyone wants, but it surprises people the first time.
**POP3** treats your phone as the destination. It downloads copies of messages and then, depending on a setting chosen at setup, either leaves the originals on the server or removes them. Deleting a downloaded message on the phone removes the phone's copy. Whether the server copy also goes depends entirely on the **Delete email from server** option in the account's settings, which is typically set to either **Never** or **When I delete from Inbox**.
The practical difference:
| What you do on the phone | IMAP | POP3 |
| --- | --- | --- |
| Delete a message | It moves to **Trash** on the server and disappears from webmail and every other device at their next sync. | The phone's copy goes. The server copy usually stays, so the message is still in webmail and still arrives on other devices. |
| Read a message | It shows as read everywhere. | It stays bold and unread on every other device. |
| Send a message | A copy is saved to the server **Sent** folder and is visible in webmail. | The sent copy usually stays on the phone only. |
| Lose, wipe or replace the phone | Nothing is lost. The server holds the mailbox. | Anything downloaded and removed from the server is gone with the handset. |
| Fill the mailbox quota | Everything counts, including **Trash** and **Junk**, until you empty them. | Downloaded mail may already have been removed from the server, so quota use can look deceptively low. |
Unless you have a specific reason to do otherwise, use IMAP for a Noiz-hosted mailbox. It keeps every device showing the same mailbox, it keeps your mail on a backed-up server rather than on a phone, and it makes replacing a handset a non-event. POP3 is worth choosing only when you deliberately want mail pulled down to one machine and off the server, for example to work within a small mailbox quota.
### Work Out Which One Your Phone Is Using
The quickest tell is the folder list. Open **Menu** and scroll down.
- **IMAP**: you see the mailbox's real server folders, typically **Inbox**, **Sent**, **Drafts**, **Trash**, **Junk** or **Spam**, plus any folders you created in webmail. Folders you make in webmail appear on the phone, and that is the giveaway.
- **POP3**: you see a short, purely local set such as **Inbox**, **Outbox**, **Sent** and **Trash**, and nothing you created in webmail ever shows up.
The definitive test takes a minute. Send yourself a test message, delete it on the phone, then open webmail in a browser. If it has gone from the webmail inbox and turned up in the webmail **Trash**, you are on IMAP. If it is still sitting in the webmail inbox, you are on POP3.
To switch a POP3 account to IMAP, remove the account from the phone and add it again choosing **Personal (IMAP)**. Before you remove it, check whether any mail exists only on that phone, because removing a POP3 account takes its downloaded messages with it.
### Recover a Message You Deleted by Mistake
1. If the **Undo** confirmation is still on screen, tap it. That is the easy path.
2. Otherwise open **Menu**, tap **Trash**, press and hold the message, then use **Move to** and pick **Inbox**.
3. If the phone is not showing it, look in the **Trash** folder in webmail. On an IMAP mailbox that is the same folder, and it is often faster to work with on a full-size screen.
Trash is not permanent storage. For a Google account, messages in Trash are destroyed automatically after 30 days. For a mailbox at your own domain, messages stay in the server **Trash** folder until you empty it. Either way, emptying Trash is final, and there is no per-message undo after that point.
### Emptying Trash and Your Mailbox Quota
On a hosted mailbox this catches people out. **Trash** and **Junk** are ordinary folders on the mail server and their contents count towards the mailbox size limit on your hosting plan. Deleting thousands of messages on your phone frees nothing until the Trash folder is emptied, and a mailbox that hits its limit starts rejecting incoming mail with the sender getting a bounce. Open **Menu**, tap **Trash**, then tap **Empty trash now** at the top of the list, and do the same for **Spam** or **Junk**.
## Manage New Mail Notifications
Notifications alert you to new mail without opening the app.
### Turn Gmail Notifications On or Off
1. Open the **Gmail** app, tap the **Menu** icon, then tap **Settings**.
2. Tap **General settings**, then **Manage notifications**.
3. Turn **All Gmail notifications** on or off. From this screen you can also choose a notification sound, or select **None** to silence alerts.
### Choose Which Emails Notify You
1. Open the **Gmail** app, tap the **Menu** icon, then tap **Settings**.
2. Tap the account you want to change.
3. Tap **Email notifications** and pick a level: **All** (every new message), **High priority only** (messages Gmail marks as important), or **None**.
Notifications only work while **Sync Gmail** is turned on for the account, see the next section if alerts have stopped arriving.
## Refresh Your Inbox When Mail Seems Slow
1. From the top of your inbox, swipe down. A refresh icon appears briefly while Gmail checks for new mail.
2. Allow time for delivery: syncing can take up to 15 minutes, and longer if the device has not been used for a while.
### Check That Sync Is Turned On
1. Open the **Gmail** app, tap the **Menu** icon, then tap **Settings**.
2. Tap the account.
3. Under **Data usage**, make sure the box next to **Sync Gmail** is ticked. If it was unticked, new mail only arrives when you open the app and refresh manually.
## Troubleshooting
- **New mail only appears when you open the app**: turn **Sync Gmail** back on under **Settings**, your account, **Data usage**, and check that **Email notifications** is not set to **None**.
- **Swiping down does not load new messages**: confirm the device is online by opening a website in a browser such as Chrome, update the Gmail app from the Play Store, then restart the device.
- **Mail has stopped arriving entirely**: check your storage. A full Google Account (storage is shared across Gmail and other Google services) stops messages from sending and receiving, and the app also stops syncing when the device itself is low on space. On a mailbox at your own domain, check the mailbox is not at its quota, and empty **Trash** and **Junk** if it is. Delete messages with large attachments and remove unused apps or downloaded files.
- **Gmail keeps asking for a password**: if you recently changed the mailbox password, enter the new one when prompted. For a mailbox at your own domain, removing the account and adding it again with the new password is the quickest fix.
- **A message sits in Outbox and never sends**: the outgoing (SMTP) side is failing while the incoming side works, so the inbox looks healthy. Confirm the outgoing server settings match your welcome email, that authentication is enabled for outgoing mail using the same username and password as incoming, and that the port is the submission port your mail server expects rather than port `25`, which many mobile networks block outright. Toggling from mobile data to Wi-Fi is a fast way to prove a network block.
- **Recipients reply to the wrong address**: you sent from the wrong account. Check the **From** line before sending, especially when composing from the **All inboxes** view.
- **An attachment bounces**: the encoded message exceeded a size limit at your server or the recipient's. Send a link to the file instead, or compress it.
- **Sent mail does not appear in webmail**: the account is set up as POP3, so sent copies are staying on the phone. Re-add the account as **Personal (IMAP)**.
- **Deleting on the phone also deleted it on the laptop**: that is IMAP working correctly, both devices are looking at the same server mailbox. Recover the message from the **Trash** folder in webmail.
- **Deleted messages keep coming back**: another device is set up as POP3 and re-downloading mail that is still on the server, or the delete never reached the server because the phone was offline. Put every device on IMAP so they all agree.
- **Nothing above helps**: as a last resort, clear the app's stored data under your device's **Settings**, **Apps**, **Gmail**, **Storage & cache**, **Clear storage**, then restart the device and sign in again. Note that this removes unsaved drafts and app settings stored on the device, and on a POP3 account it removes downloaded mail that exists nowhere else.
If you get stuck, open a support ticket with the Noiz support team and include the email address involved, whether it is set up as IMAP or POP3, and exactly what happens when you send, delete or refresh, and a technician will help you get your mail working properly on Android.
# How to Remove an Email Account in Thunderbird
Source: https://docs.noiz.ie/email/how-to-remove-an-email-account-in-thunderbird/
This guide shows you how to remove an email account from Mozilla Thunderbird cleanly, so that Thunderbird stops checking that mailbox and the account disappears from the folder list, without any nasty surprises. It is written for Noiz email clients who use Thunderbird on a desktop, and it assumes you already have the account set up in the program. People describe this task in different ways: removing an account, deleting an account, taking a mailbox out of Thunderbird, or "getting rid of" an old address. They all mean the same thing here. The single most important point to understand before you begin is this: removing an account from Thunderbird only unhooks Thunderbird from the mailbox. It does not cancel your Noiz email service, and for a normal IMAP setup it does not touch the mail sitting on the Noiz server. Your address keeps working, and you can view it in webmail or add it back to Thunderbird at any time.
**Last reviewed:** 27 July 2026, against Thunderbird **140 ESR and the current monthly Release (version numbers in the 140s)**. This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below. Thunderbird's exact wording and layout shift slightly from one version to the next, so a label may sit a little differently in your copy; the sequence below holds across recent versions.
### Official Documentation Reference
- [Mozilla Thunderbird Support (home)](https://support.mozilla.org/en-US/products/thunderbird): the official help hub. If a menu label in your version differs from the one described here, search this site for the current wording.
- [Account Settings (Mozilla Support)](https://support.mozilla.org/en-US/kb/account-settings): describes the Account Settings window and the **Account Actions** menu that holds the **Remove Account** command used throughout this guide.
- [Manual account configuration (Mozilla Support)](https://support.mozilla.org/en-US/kb/manual-account-configuration): the reference for incoming (IMAP/POP) and outgoing (SMTP) server settings, useful for understanding the outgoing server you may need to remove separately.
## Prerequisites
- Thunderbird is installed and the account you want to remove is currently set up in it.
- You know whether the account is **IMAP** or **POP**, because this decides what happens to your mail. If you are unsure, open **Account Settings**, click **Server Settings** under the account, and read the **Server Type** line. This matters, and the "What removing an account actually does" section below explains why.
- You have decided whether you want to keep a copy of any mail that lives only on this computer. If the account is POP, or holds messages you filed into **Local Folders**, back those up first. See "Before you start" below.
- If you might want this mailbox in Thunderbird again later, you do not need to save the settings; you can simply add it back afterwards using [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/).
## What Removing an Account Actually Does
It is worth a minute to understand what you are about to do, because the word "remove" worries people into thinking their email will be destroyed. It will not be, as long as you know which of two very different actions you are taking.
### Removing an account is not the same as deleting mail
Removing an account tells Thunderbird to forget a mailbox: it deletes the account's settings and the folders it shows, and it stops Thunderbird from connecting to that server. Deleting mail is something else entirely: it is when you select messages inside a folder and delete them. On an IMAP account, deleting a message inside a folder removes it from the server too, so it vanishes from webmail and from your phone as well. Simply removing the account never does that. This is the distinction to hold on to: removing an account unplugs Thunderbird from the mailbox, while deleting mail throws messages away. This guide is about the first.
### IMAP: the server keeps your mail
Noiz client mailboxes are normally set up as **IMAP**, which means the master copy of every message lives on the Noiz mail server and Thunderbird holds a synchronised local cache so you can read mail quickly and offline. When you remove an IMAP account, that server copy is left completely alone. Everything stays in your mailbox, reachable through webmail or any other device, and if you add the account back to Thunderbird later it simply re-downloads everything. The only thing removal can clear is the local cache on this one computer, and even that is your choice, controlled by a checkbox described in Step 3.
### POP: your mail may live only on this computer
A **POP** account behaves in the opposite way. POP downloads messages onto your computer and, depending on how it was configured, often deletes them from the server as it does so. That means the only copy of older mail can be the one sitting in Thunderbird on this machine. If you remove a POP account and also clear its local data, that mail can be gone for good. So if your account is POP, treat removal with care and back up first.
## Before You Start: Back Up Mail You Cannot Afford to Lose
For a straightforward IMAP account you can usually skip this, because the server holds everything. Take a moment over it in two cases. First, if the account is **POP**, as just explained. Second, if you have dragged or filed messages into **Local Folders**, which is the separate on-disk store that appears at the bottom of your folder list and belongs to no single account. Local Folders content is never on any mail server, so make sure anything precious there is copied out before you make changes.
The simplest way to keep individual messages is to select them, then use **File > Save As** to write each out as an `.eml` file, or drag them into a folder on your desktop. To keep whole folders, the **ImportExportTools NG** add-on can export a folder to a single file, and Thunderbird's own **Tools > Export** can save a full profile backup. Whichever route you take, confirm the backup opens correctly before you remove anything.
## Step 1: Open Account Settings
Everything to do with removing an account happens in the **Account Settings** window. Open it in whichever of these ways suits your version:
- Click the menu button (the three stacked lines, **โฐ**, at the top right) and choose **Account Settings**.
- Or, if the classic menu bar is showing, choose **Tools > Account Settings**.
- Or right-click the account's name in the folder list on the left and choose **Settings**.
## Step 2: Select the Account, Then Open Account Actions
The left-hand pane of the Account Settings window lists every account you have, each one a heading with a set of pages beneath it such as **Server Settings** and **Copies & Folders**. Click the account's top-level name, the heading itself rather than one of the pages under it, so that the whole account is selected. This step matters: the removal command acts on whatever is selected, so selecting a sub-page instead of the account is the usual reason the option later appears greyed out.
Now find the **Account Actions** button. It sits at the bottom of that left-hand pane. Click it to open its menu.
## Step 3: Choose Remove Account and Decide About Local Data
From the **Account Actions** menu, choose **Remove Account**. Thunderbird opens a confirmation dialog that names the account and asks you to confirm. The dialog also offers a checkbox, usually labelled something like **Remove message data**, and this is the single decision that matters most. The exact wording varies a little by version, but its job is always the same: it decides what happens to the copies of your mail stored locally on this computer.
- **Leave the checkbox unticked** to remove the account while leaving its downloaded mail sitting in your Thunderbird profile on disk. The account vanishes from Thunderbird, but the local files are kept. This is the cautious choice, and it is the one to use if you are at all unsure.
- **Tick the checkbox** to also delete the local copies of this account's messages and folders from your computer, freeing the disk space they used. For an IMAP account this is safe, because the server still holds the master copy, so ticking it just clears the local cache and nothing is truly lost. For a POP account, treat this as permanent deletion of that mail, which is why the earlier backup step matters.
Note that the dialog is talking only about the copies on this computer. Ticking the box does not reach out and delete anything from the Noiz server, and for IMAP your mailbox stays intact online regardless of the choice you make here.
When you are happy with the choice, confirm to remove the account. Thunderbird closes the account, and it disappears from the folder list. There is no separate "apply" to click; the removal takes effect immediately.
## Step 4: Remove the Leftover Outgoing (SMTP) Server
Here is a detail many people miss. Thunderbird keeps outgoing servers, the **SMTP** servers that send your mail, in a shared list that is separate from your accounts. It does this on purpose, because one SMTP server can be shared by several accounts. Because of that, removing an account does not automatically remove the SMTP server it used. The account is gone, but its old sending server can quietly remain in the list. It causes no harm, but it is untidy, and if you are removing the account to declutter you will want to clear it too.
To do so, stay in **Account Settings** and look at the very bottom of the left-hand pane, below all your accounts and below **Local Folders**, for the entry named **Outgoing Server (SMTP)**. Click it. The right-hand side then lists every SMTP server Thunderbird knows about. Find the one that belonged to the account you just removed, for example a server on `mail.yourdomain.com` (where `yourdomain.com` stands in for your own domain), select it, and click **Remove**.
Two cautions before you click. First, only remove a server that is genuinely orphaned; if another account still relies on it, removing it will stop that account sending. Second, one server in the list is marked as the **default**, and you should not remove the default while other accounts still use it. If in doubt, leave the SMTP entry alone; a spare one does no damage.
## What Happens to Your Noiz Mailbox on the Server
To be completely clear, because this is the question people worry about: nothing you have done above deletes or closes your mailbox on the Noiz side. Removing an account in Thunderbird is a change on your own computer only. The mailbox continues to exist on the Noiz mail server, new mail keeps arriving into it, and you can still sign in to webmail to read and send. Your Noiz email service and billing are entirely unaffected.
If what you actually want is to get rid of the mailbox itself, that is a separate task carried out on the Noiz hosting platform rather than in Thunderbird. On the Plesk platform that Noiz uses for client mailboxes, mailboxes are created and deleted from the panel; the counterpart to deletion, creating one, is covered in [How to Create an Email Account in Plesk](/plesk/how-to-create-an-email-address-in-plesk/), and the Noiz support team can remove a mailbox for you if you prefer. Bear in mind that deleting the mailbox on the server does permanently destroy the mail it holds, so it is a bigger step than removing the account from Thunderbird.
## Re-Adding the Account Later
Because removal changes nothing on the server, adding the mailbox back to Thunderbird whenever you like is straightforward, and for IMAP it will re-sync all your mail from the server. The full walkthrough is in [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/). One thing to expect: Thunderbird's automatic setup often cannot look up the correct settings for a custom domain, so it may guess wrong or come back empty, and you will need to enter the Noiz settings by hand. For reference, those are:
- **Incoming (IMAP):** server `mail.yourdomain.com`, port `993`, connection security **SSL/TLS**.
- **Outgoing (SMTP):** server `mail.yourdomain.com`, port `465`, connection security **SSL/TLS**.
- **Username:** your full email address, for example `you@yourdomain.com`, not just the part before the @.
- **Authentication:** normal password.
Throughout, `yourdomain.com` is an example; replace it with your own domain.
## Troubleshooting
- **Symptom**: **Remove Account** is greyed out or does nothing. You almost certainly have a sub-page selected, such as **Server Settings**, rather than the account itself. Click the account's top-level name in the left pane so the whole account is highlighted, then open **Account Actions** again.
- **Symptom**: you cannot remove **Local Folders**. That is expected. Local Folders is a built-in on-disk store, not a mail account, so Thunderbird does not let you remove it through Account Actions. It has no server behind it, so there is nothing to disconnect from.
- **Symptom**: after removing an account, mail has also vanished from webmail or from your phone. Removing an account never deletes server mail, so this points to messages having been deleted inside a folder before or instead of removal, which on IMAP syncs the deletion to the server. Removal itself does not do this. Check the mailbox's **Trash** in webmail; recently deleted mail may still be recoverable there.
- **Symptom**: an old outgoing server still shows in the list after the account is gone. That is normal, because SMTP servers are held separately, as explained in Step 4. Remove it there if you want it gone, taking care not to remove the default or one still used by another account.
- **Symptom**: you removed the account but its old mail is still using disk space. You left the **Remove message data** checkbox unticked, so the local copies remain in your Thunderbird profile. If you no longer need them, add the account back briefly and remove it again with the box ticked, or ask the Noiz support team for guidance on clearing the profile folder safely.
- **Symptom**: you only want Thunderbird to stop checking this mailbox for a while, not remove it. In that case you do not need to remove the account at all; you can leave it in place and simply stop it fetching mail automatically. Removal is the right tool only when you want the account gone for good.
If you are unsure whether an account is IMAP or POP, whether it is safe to tick the local-data checkbox, or whether an outgoing server is still needed, do not guess. Open a support ticket with the Noiz support team, tell them the address involved and what you are trying to achieve, and they will confirm the safe way through. On managed plans the team can walk you through the removal or handle any server-side mailbox changes for you.
# How to Reply to Email in Mozilla Thunderbird
Source: https://docs.noiz.ie/email/how-to-reply-to-email-in-mozilla-thunderbird/
This guide shows you how to reply to an email in Mozilla Thunderbird, the free desktop email client for Windows, macOS and Linux. Replying looks like a single button, and most of the time it is, but the choice between **Reply** and **Reply All**, and the question of which of your addresses the reply is sent from, are where mistakes actually happen. This article covers the basic procedure and then the handful of details worth knowing so your replies go to the right people, from the right address, every time.
**Last reviewed:** 27 July 2026, against Mozilla Thunderbird **140 ESR** and the current monthly Release channel. This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below. Thunderbird's interface was rebuilt in the 115 "Supernova" release and continues to be refined, so if a button sits somewhere slightly different from the screenshots, the names and behaviour are unchanged.
### Official Documentation Reference
- [Thunderbird Support (Mozilla)](https://support.mozilla.org/en-US/products/thunderbird): the official support hub, kept current with the latest release.
- [Thunderbird keyboard shortcuts](https://support.mozilla.org/en-US/kb/thunderbird-keyboard-shortcuts): the full list, including the reply shortcuts mentioned below.
## Prerequisites
- Thunderbird installed on your computer, with your Noiz mailbox already added. If you have not added the account yet, start with [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/).
- A working outgoing (SMTP) server on that account. Receiving mail and sending mail are two separate connections, so an account can happily download your inbox and still fail when you press **Send**.
- An email in your inbox that you want to answer.
## Reply to an Email
1. Open Mozilla Thunderbird. 
2. Double-click the message you want to answer. It opens in its own tab. 
3. In the message header area at the top of the open message, click **Reply**. 
4. Type your message in the compose window and click **Send**. 
**You do not have to open the message first.** Selecting it once in the message list shows it in the preview pane, and the same **Reply** button appears there. Opening in a tab is useful for long threads, but for a quick answer, click the message once and press `Ctrl + R` (`Cmd + R` on macOS).
## Reply, Reply All or Reply List
The arrow beside the **Reply** button hides the options that matter most. Choosing the wrong one is the single most common email mistake, and it cannot be undone once the message has left your outbox.
- **Reply** (`Ctrl + R`): answers the sender only. Everyone else who was copied in is dropped. This is the safe default.
- **Reply All** (`Ctrl + Shift + R`): answers the sender plus every address in the original **To** and **Cc** fields. Use it deliberately, when the whole group genuinely needs the answer.
- **Reply List** (`Ctrl + Shift + L`): appears when the message came from a mailing list, and sends your answer back to the list address rather than to the individual who posted.
Anyone who was in **Bcc** on the original stays hidden, so they receive nothing from either Reply or Reply All. Before you send, read the **To** and **Cc** lines in the compose window rather than trusting the button you pressed. Removing a recipient is as simple as clicking the small x on their address pill.
## Check Which Address You Are Replying From
If you have more than one mailbox in Thunderbird, which is normal once you have a personal address and one or more addresses on your own domain, look at the **From** line at the top of the compose window. Thunderbird picks the identity that the original message was addressed to, which is usually correct, but it gets this wrong when a message arrived at an alias or was forwarded internally.
Click the **From** dropdown to change it before you start typing. Getting this right matters more than it looks:
- Sending from an address that does not belong to the account you are authenticated on will usually be rejected outright by the outgoing server, or delivered and then filed as spam by the recipient. SPF and DKIM checks are done against the sending domain, so a mismatched **From** address fails them.
- The reply carries the signature attached to that identity, so switching the **From** address after typing your message can silently swap or drop your signature.
## Useful Things to Know About Replies
### Quoting Only the Part You Are Answering
Select a sentence or paragraph in the original message before you click **Reply**, and Thunderbird quotes only that selection instead of the entire message. On long threads this is the difference between a clear answer and a wall of quoted history.
### Where Your Text Goes
By default Thunderbird places your cursor above the quoted original, which is what most business correspondence expects. If you prefer to answer beneath the quote, or point by point inside it, change it per account under **Account Settings** then **Composition & Addressing**, where you can set the reply to start below the quote. You can also simply click into the quoted text and type between the lines, which Thunderbird handles correctly.
### Attachments Are Not Carried Over
A reply deliberately leaves the original attachments behind, because the sender already has them. If you need to send a file back with the thread intact, use **Forward** rather than **Reply**, or attach the file to your reply yourself. See [How to Forward an Email in Mozilla Thunderbird](/email/how-to-forward-an-email-in-mozilla-thunderbird/).
### Drafts and Sending Later
Thunderbird autosaves a reply to your **Drafts** folder every few minutes, so closing the compose window by accident is recoverable. If you would rather queue a message instead of sending it now, use **File** then **Send Later**. The message waits in **Outbox** and goes out the next time you choose **File** then **Send Unsent Messages**.
### Replies Land Back in the Thread
Your sent reply keeps the thread's message identifiers, so it appears in the same conversation for the recipient and in your own **Sent** folder. If the mailbox is set up with IMAP, which is the recommended setup on Noiz hosting, that **Sent** copy is stored on the server, so the reply is also visible from webmail and from your phone. Nothing extra needs to be configured for this to work. On a POP account the sent copy stays only on the computer that sent it.
## Troubleshooting
**Symptom**: the reply is addressed to somebody other than the person who wrote to you. The original message carried a **Reply-To** header, which Thunderbird honours by design. This is normal for newsletters, ticket systems and shared team mailboxes. If you meant to answer the individual, correct the **To** field manually before sending.
**Symptom**: the reply sits in **Outbox** and never leaves. Thunderbird is in offline mode. Go to **File** then **Offline** and choose **Work Online**, then **File** then **Send Unsent Messages**.
**Symptom**: sending fails with an authentication or connection error, even though new mail arrives fine. The outgoing server settings are wrong or the password was never saved for it. Check **Account Settings** then **Outgoing Server (SMTP)**: the username must be your full email address, not just the part before the `@`, and the connection should use SSL/TLS on port `465` with normal password authentication.
**Symptom**: your reply bounces, or the recipient says it went to their spam folder. Confirm the **From** address is a mailbox that genuinely exists on the account you are sending through. Replying from an address on a domain whose DNS is not pointed at Noiz mail will fail SPF and DKIM checks at the receiving end.
**Symptom**: your formatting, colours or signature image vanish for the recipient. Either their client is set to display plain text, or your account is set to compose in plain text. The composition format is set per account under **Account Settings** then **Composition & Addressing**.
**Symptom**: the **Reply** button is greyed out or missing. You are looking at a folder summary or a message that is still downloading rather than at the message itself. Click the message body once, or wait for the download to finish, and the buttons return.
## Related Guides
- [How to Send an Email Using Mozilla Thunderbird](/email/how-to-send-an-email-using-mozilla-thunderbird/)
- [How to Forward an Email in Mozilla Thunderbird](/email/how-to-forward-an-email-in-mozilla-thunderbird/)
- [How to Create a Professional HTML Email Signature in Thunderbird](/email/how-to-create-a-professional-html-email-signature-in-thunderbird/)
- [The Best Thunderbird Settings to Configure First](/email/the-best-thunderbird-settings-to-configure-first/)
If your replies are not arriving, or the outgoing server rejects them, contact Noiz support with the exact error text Thunderbird shows and the address you were sending from, and the team will check the mailbox and mail routing for you.
# How to Send Encrypted and Signed Email with OpenPGP in Thunderbird
Source: https://docs.noiz.ie/email/how-to-send-encrypted-and-signed-email-with-openpgp-in-thunderbird/
Once you have OpenPGP keys set up in Mozilla Thunderbird, this guide shows you how to actually use them: how to send a message that is encrypted so only the intended recipient can read it, how to add a digital signature that proves a message genuinely came from you and has not been altered, and how to read encrypted and signed mail that arrives in your Noiz mailbox. It also explains, in plain language, the difference between encryption and signing (they protect different things), what you need before you can encrypt to someone, and the real-world limitations worth knowing before you rely on OpenPGP. This article is for anyone using a Noiz email account in Thunderbird who wants genuine end-to-end privacy on individual messages. OpenPGP is built directly into Thunderbird, so no add-on such as Enigmail is required.
**Last reviewed:** 27 July 2026, against Mozilla Thunderbird **140+** (2026 monthly Release channel, and equally applicable to the current ESR release). This guide is written for Noiz hosting and is kept current against Thunderbird. Exact button and menu labels can vary slightly between versions, so where your screen differs, check the official Thunderbird documentation linked below. This article complements, and does not replace, that documentation.
### Official Documentation Reference
- [Mozilla Support: OpenPGP in Thunderbird, HOWTO and FAQ](https://support.mozilla.org/en-US/kb/openpgp-thunderbird-howto-and-faq), the authoritative reference for keys, encryption, signing, and troubleshooting
- [Mozilla Support: Introduction to End-to-end encryption in Thunderbird](https://support.mozilla.org/en-US/kb/introduction-to-e2e-encryption), the conceptual overview of how OpenPGP protects messages
- [Mozilla Support: Thunderbird Privacy and Security Settings](https://support.mozilla.org/en-US/products/thunderbird/privacy-and-security-settings), the topic hub for all encryption and security articles
## Prerequisites
- OpenPGP keys already configured in Thunderbird, that is, your own personal key generated or imported, and the public key of anyone you want to encrypt to already imported and accepted. If you have not done this yet, follow [How to Set Up OpenPGP Encryption Keys in Mozilla Thunderbird](/email/how-to-set-up-openpgp-encryption-keys-in-thunderbird/) first. Everything in this guide depends on that setup.
- A working Noiz email account in Thunderbird. If your account is not yet added, see [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/).
- For anyone you want to send encrypted mail to: their OpenPGP public key. You cannot encrypt to a person whose public key you do not hold.
## Encryption Versus Signing: What Each One Protects
OpenPGP gives you two independent protections. They are often used together, but they are not the same thing and it is worth understanding which does what, because people frequently expect one to do the job of the other.
- **Encryption protects confidentiality.** The message body and any attachments are scrambled so that only someone holding the matching private key can read them. You encrypt *to* a recipient using *their* public key; only their private key can unlock it. This is what stops anyone in between, including mail servers, from reading the content.
- **A digital signature protects authenticity and integrity.** A signature proves the message really came from you and that not a single character was changed in transit. You sign *with* your own private key, and recipients verify the signature using *your* public key. Signing does **not** hide the content: a signed-but-not-encrypted message is still perfectly readable by anyone.
A useful way to remember it: encryption is a sealed envelope, a signature is a tamper-proof wax seal with your mark on it. You can use either alone, but for sensitive mail it is common to do both, so the recipient knows the message is private *and* genuinely from you.
## Before You Can Encrypt: You Need the Recipient's Public Key
This is the single point that trips people up most. Because you encrypt using the recipient's public key, you must already have that key imported and marked as accepted in Thunderbird before you can send them an encrypted message. If Thunderbird does not hold a usable key for every recipient, it will not let you send the message encrypted and will tell you which recipient is missing a key.
Signing is different: you sign with your own private key, so you can digitally sign a message to anyone, whether or not you have their key. They only need your public key to verify it, which is why attaching your public key (covered below) is a helpful habit.
Importing and accepting recipient keys is covered in the [key setup guide](/email/how-to-set-up-openpgp-encryption-keys-in-thunderbird/). If you have imported a key but encryption is still refused, open **Tools** then **OpenPGP Key Manager**, select the recipient's key, and confirm its acceptance status is set so that the key is trusted for encryption.
## Sending an Encrypted or Signed Message
Encryption and signing are chosen per message, in the compose window, at the point of writing. You can set sensible defaults for an account as well (see the next section), but the per-message controls always let you decide for the message in front of you.
### Step by step in the Write window
1. Start a new message as usual with **Write**, and fill in the recipient and subject.
2. In the Write window toolbar, find the encryption controls. Depending on your Thunderbird version these appear as a padlock **Encryption** button and a **Security** dropdown (older layouts group everything under a single **Security** menu, and the classic menu bar exposes the same items under **Options**).
3. To make the message private, turn on **Encrypt** (labelled **Require Encryption** in some versions). The padlock icon closes to show encryption is active.
4. To add your digital signature, turn on **Digitally Sign This Message**. You can enable signing, encryption, or both.
5. Watch the status indicator. Thunderbird shows whether it has a usable key for every recipient. A green or closed padlock means it is ready to encrypt to everyone on the message; a warning means at least one recipient has no accepted key, and you will need to obtain and import that key first.
6. Send the message as normal. If you enabled encryption but a key is missing, Thunderbird stops you and explains which recipient is the problem rather than sending in the clear by accident.
When you send an encrypted message, Thunderbird also encrypts a copy to your own key. This is intentional: it means the copy saved in your **Sent** folder remains readable by you later. Without it, you would be unable to reopen your own sent encrypted mail.
## Setting Encryption and Signing Defaults for an Account
If you exchange encrypted mail regularly, you can make Thunderbird apply your preferences automatically to new messages from a given account, so you are not toggling the controls every time.
1. Open **Account Settings** from the menu (or right-click the account in the folder pane and choose **Settings**).
2. Select the **End-to-End Encryption** section for the account.
3. Confirm your **personal key** is selected here. This is the key Thunderbird signs with and the key it uses to keep your own copy of encrypted mail readable.
4. Optionally tick **Add my digital signature by default** so every new message is signed automatically.
5. Optionally set encryption to be required by default. Bear in mind that a default of "always encrypt" only works when you hold a key for the recipient, so it suits accounts used mainly with a fixed set of correspondents.
## Attaching Your Public Key So Others Can Reply Securely
For someone to send *you* encrypted mail, or to verify your signature, they need your public key. The simplest way to hand it over is to attach it to a message.
In the Write window, open the **Security** menu and choose **Attach My Public Key**. Thunderbird adds your public key to the outgoing message. Sharing a public key is safe by design: it can only be used to encrypt mail to you and to verify your signatures, never to read your mail or impersonate you. A common pattern is to sign your first message to a new contact and attach your public key, so they can verify you and reply encrypted from then on.
## Reading Encrypted and Signed Mail You Receive
Incoming mail is handled automatically. You do not run a separate decrypt step.
- **Encrypted messages** are decrypted on the fly using your private key, as long as that key is present in Thunderbird (and unlocked, if you protected it with a master password). The message simply displays as normal readable text.
- **Signed messages** are verified automatically against the sender's public key. Thunderbird shows the result in the message header area.
The message header carries small status indicators, typically a **padlock** for encryption and a **signature or seal** icon for a verified signature. Click the OpenPGP or padlock indicator to open the **Message Security** panel, which spells out whether the message was encrypted, whether the signature is valid, and which key was used.
Signature results are worth reading rather than glancing at. A **good signature** confirms the message is genuine and unaltered. An **unverified** or **unknown** result usually means you do not yet hold, or have not accepted, the sender's public key: verification is not possible until you import and accept it. A **bad or invalid signature** is a genuine warning that the message may have been altered or does not match the claimed sender, and should be treated with suspicion.
## How Encryption Works With Your Noiz Mailbox
OpenPGP is end-to-end and works on top of your existing Noiz email account, whatever mail server it uses. Your account still sends and receives over the standard Noiz settings (IMAP `mail.yourdomain.com` on port `993` with SSL/TLS, and SMTP `mail.yourdomain.com` on port `465` with SSL/TLS, where `yourdomain.com` is your own domain). The encryption happens in Thunderbird before the message ever leaves your computer, so the Noiz mail servers only ever carry the scrambled ciphertext and never see the plaintext of an encrypted message. Nothing needs to be enabled on the hosting side, and OpenPGP is entirely separate from the transport security (SSL/TLS) that already protects the connection between Thunderbird and the server.
Two practical consequences follow from this on any hosting, including Noiz. Server-side spam and virus scanning cannot inspect the contents of an encrypted message, and neither webmail search nor server-side rules can look inside it. And because only your private key can decrypt stored encrypted mail, that key is the only way back in: if you lose it with no backup, the encrypted messages sitting in your mailbox become permanently unreadable. Keep a secure backup of your private key, as covered in the key setup guide.
## Limitations Worth Knowing
- **The subject line is not encrypted.** OpenPGP protects the message body and attachments, but the subject travels in the clear. Avoid putting anything sensitive in the subject.
- **Metadata is not hidden.** Who the message is from and to, and when it was sent, remain visible even on an encrypted message. Encryption hides the contents, not the fact that you corresponded.
- **Both parties need OpenPGP.** Encryption and signature verification only work if the other person also uses OpenPGP-capable software and, for encryption, has shared their public key with you. There is no way to send an OpenPGP-encrypted message to someone who has no key.
- **Signing is not encryption.** A signed message that is not also encrypted is fully readable by anyone who intercepts it. If confidentiality matters, you must encrypt, not just sign.
- **Lose the key, lose the mail.** As noted above, there is no password reset for OpenPGP. A lost private key with no backup means lost access to everything encrypted to it.
## Troubleshooting
- **Symptom: Thunderbird will not let you send encrypted and names a recipient**: you do not hold an accepted public key for that person. Obtain and import their public key, mark it accepted in the **OpenPGP Key Manager** (**Tools** then **OpenPGP Key Manager**), then try again.
- **Symptom: the Encrypt button is greyed out or missing**: no personal key is selected for the account. Open **Account Settings**, go to **End-to-End Encryption**, and select (or generate) your personal key first.
- **Symptom: a received encrypted message shows as unreadable or asks for a key you do not have**: it was encrypted to a different key than the one in this Thunderbird profile, or your private key is missing from this profile. Import your private key into this profile, and make sure the sender used your current public key.
- **Symptom: an incoming signature shows as unverified or unknown**: you have not imported or accepted the sender's public key yet. Import it and set its acceptance so Thunderbird can verify future messages from that sender.
- **Symptom: a signature shows as bad or invalid**: treat this as a warning. The message may have been altered, or it may not genuinely be from the claimed sender. Do not act on its contents until you have confirmed the sender's identity through another channel.
OpenPGP is powerful but unforgiving, and the plumbing behind it (keys, transport, mailbox) has several moving parts. If you get stuck sending or reading encrypted mail on a Noiz account, open a support ticket with the Noiz support team. Noiz cannot read or recover your private key by design, but the team can confirm your mailbox and its `mail.yourdomain.com` connection settings are correct so that you can rule out account issues and focus on the OpenPGP side.
# How to Send an Email Using Mozilla Thunderbird
Source: https://docs.noiz.ie/email/how-to-send-an-email-using-mozilla-thunderbird/
This guide shows you how to compose and send an email message from Mozilla Thunderbird, the free desktop email client for Windows, macOS and Linux. Once your Noiz mailbox is set up in Thunderbird, you do not need to open webmail in a browser to send mail. Everything happens in the Thunderbird window, a copy of what you send is filed for you, and your address book and signature are available as you type.
The sending itself is about three clicks. Most of the trouble people actually hit is not the clicking: it is picking the wrong **From** address when several mailboxes share one Thunderbird profile, running into a message size limit with an attachment, or an outgoing server setting that only reveals itself the first time a message refuses to leave. Those are covered here too, so that your first message goes out cleanly and lands in the inbox rather than the spam folder.
**Last reviewed:** 27 July 2026, against Mozilla Thunderbird **153** (latest stable Release) and Thunderbird **140 ESR** (Extended Support Release). This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below. Thunderbird ships a new Release every month, so button wording and toolbar layout can shift slightly between versions and between the Release and ESR channels. Where a screen looks different from the screenshots here, the fields and the values you enter into them remain the same even when their arrangement moves.
### Official Documentation Reference
- [Send and receive messages in Thunderbird](https://support.mozilla.org/en-US/kb/sending-and-receiving-messages-thunderbird): Mozilla's reference for the Write window, recipient fields and the formatting bar.
- [How to use attachments](https://support.mozilla.org/en-US/kb/how-use-attachments): attaching, removing and saving files.
- [Filelink for large attachments](https://support.mozilla.org/en-US/kb/filelink-large-attachments): sending a link instead of a file when an attachment is too big for email.
- [Cannot send messages](https://support.mozilla.org/en-US/kb/cannot-send-messages): Mozilla's own diagnostic page for outgoing mail failures.
- [Thunderbird keyboard shortcuts](https://support.mozilla.org/en-US/kb/keyboard-shortcuts-thunderbird): the full list, including the compose and send shortcuts used below.
- [Thunderbird Support](https://support.mozilla.org/en-US/products/thunderbird): the official support hub, kept current with the latest release.
## Prerequisites
- Thunderbird is installed on your computer. Download it from the [official Thunderbird website](https://www.thunderbird.net/) and keep it updated, so you have current security fixes and the interface described here.
- Your Noiz mailbox is already added to Thunderbird. If it is not, set it up first: [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/). Thunderbird can only send through an account that has been configured with a working outgoing (SMTP) server.
- You know the recipient's email address, and you have an internet connection. Thunderbird will happily let you write a message offline, but it cannot deliver one.
## Step 1: Open Thunderbird
Launch Thunderbird from your desktop, Start menu, Applications folder or app launcher.

If you have more than one account configured, Thunderbird opens on the folder pane with each account listed down the left side. Take note of which account is selected, because that selection decides which address a new message starts from.
## Step 2: Open a New Message Window
On the toolbar at the top left, click **New Message**. A separate compose window (Thunderbird also calls it the Write window) opens.

**A note on the label.** This button was called **Write** in older versions of Thunderbird, and that is what the screenshot above shows. Current versions label it **New Message** and put a **+** symbol on it. It is the same button in the same place, so use whichever wording your copy of Thunderbird displays.
Two faster routes to the same window:
- Press **Ctrl** + **N** (**Cmd** + **N** on macOS) while the mail window has focus.
- Click the small arrow beside **New Message** to choose which account the message should come from before the window even opens. This is the tidiest way to work if you juggle several addresses.
## Step 3: Check the Address You Are Sending From
At the top of the compose window is a **From** row. If you only have one mailbox in Thunderbird, there is nothing to decide here. If you have several, click the **From** drop-down and pick the address the message should be sent from. Thunderbird pre-selects whichever account was highlighted in the folder pane, which is not always the one you meant.
**Why this matters more than it looks.** The **From** address does not only decide what the recipient sees. It also decides which outgoing server Thunderbird authenticates against. Sending a message stamped with one domain through the credentials of a different domain is exactly the pattern that anti-spoofing checks (SPF, DKIM and DMARC) are built to catch, so those messages are frequently rejected outright or filed as spam by the receiving side. Send each address through its own account, and delivery stays clean.
If you have set up alias identities on an account, they appear in the same drop-down. Choose the identity you want, and Thunderbird uses its signature and reply-to address as well.
## Step 4: Address the Message
Click into the **To** field and type the recipient's email address, for example `someone@example.com`. Press **Enter** or **Tab** after each address, which turns it into a recipient chip and gives you a fresh line for the next one. If the address is already in your address book, Thunderbird autocompletes it after a few characters.
To the right of the **To** field are the **Cc** and **Bcc** buttons, which reveal those extra recipient rows. Use them deliberately:
- **To**: the people the message is actually for, and who you expect to act on it.
- **Cc** (carbon copy): people who should see the message for information. Every recipient can see every Cc address.
- **Bcc** (blind carbon copy): copies that stay hidden from the other recipients. Use Bcc whenever you mail a group of people who do not know one another, otherwise you disclose everyone's address to everyone else.
**Gotcha worth knowing.** A message sent to a long list of addresses in **To** or **Cc** looks like bulk mail to receiving spam filters, and one careless **Reply All** then hits the whole list. For anything beyond a handful of people, put your own address in **To** and the rest in **Bcc**. If you send genuine bulk or marketing mail, use a proper mailing list service rather than a mail client, because sending large volumes from a normal mailbox harms the sending reputation of your domain.
## Step 5: Write the Subject and the Message
Enter a clear subject in the **Subject** field, then press **Tab** or click into the large message pane below it and type your message.

A few things that make the difference between a message that arrives and one that does not:
- **Always write a subject.** Empty subject lines are a well-known spam signal and score against your message at the receiving server. Thunderbird warns you if you try to send without one.
- **Formatting.** The formatting bar above the message pane provides bold, italic, lists, links, images and tables. This composes an HTML message. If you would rather send plain text, hold **Shift** while choosing **New Message**, or set the default per account under **Account Settings** and then **Composition & Addressing**.
- **Signatures.** If a signature is configured for the account, Thunderbird inserts it automatically. See [How to Create a Professional HTML Email Signature in Thunderbird](/email/how-to-create-a-professional-html-email-signature-in-thunderbird/) if you have not set one up yet.
- **Autosave.** Thunderbird saves a draft every five minutes by default, so a crash or an accidental close rarely loses your work. Look in the **Drafts** folder of the sending account to pick a message back up. You can change the interval under **Settings** and then **Composition**.
### Attaching Files
Click **Attach** in the compose window toolbar and select your file, or simply drag the file from your desktop or file manager onto the message. Attachments are listed in a pane at the bottom of the compose window, where you can remove any you added by mistake.
**The size limit nobody expects.** Email attachments are encoded for transport, and that encoding inflates them by roughly a third. A 20 MB file therefore travels as about 27 MB. Both the sending server and the receiving server enforce their own maximum message size, and the smaller of the two wins, so an attachment that leaves your mailbox successfully can still be bounced by the recipient's provider. As a practical rule, keep total message size under about 10 MB, and send anything larger as a download link instead. Thunderbird's Filelink feature does this for you and prompts automatically for attachments over 5 MB.
## Step 6: Send the Message
Click **Send**, or press **Ctrl** + **Enter** (**Cmd** + **Enter** on macOS). The compose window closes and a progress indicator appears briefly in the status bar at the bottom of the main window while Thunderbird hands the message to the outgoing server.
Two useful alternatives sit in the **File** menu of the compose window:
- **Send Later** queues the message in the **Outbox** folder instead of sending it now. Nothing leaves until you choose **File** and then **Send Unsent Messages**, which is handy when you are writing offline or want a moment to reconsider.
- **Save as Draft** stores the message so you can finish it later, without sending anything.
**Once sent, it is gone.** Email has no recall. Thunderbird cannot pull a message back after the outgoing server has accepted it, whatever any other mail system may claim. If that worries you, use **Send Later** as a deliberate pause before delivery.
## Where Your Sent Message Goes
Thunderbird files a copy of every sent message in the **Sent** folder of the sending account. On an IMAP account, which is what Noiz recommends, that folder lives on the mail server, so the same copy appears in webmail and on your phone. On a POP account the copy is stored only on the computer that sent it, and no other device will ever see it.
If sent messages are not appearing where you expect, open **Account Settings**, then **Copies & Folders** for that account, and confirm that **Place a copy in** points at the **Sent** folder on the server rather than at Local Folders.
## Troubleshooting
- **Symptom: "Sending of the message failed" or "unable to connect to the outgoing (SMTP) server".** Open **Account Settings**, scroll to **Outgoing Server (SMTP)** and check the entry for your account. It should use your mail hostname, port `465`, connection security **SSL/TLS**, authentication method **Normal password**, and your **full email address** as the username. A username of just the part before the `@` is the single most common cause of this failure.
- **Symptom: Thunderbird asks for the outgoing server password repeatedly.** The stored password is wrong or has been changed. Confirm the password by signing in to your webmail with the same details. If webmail also rejects it, reset the mailbox password where the mailbox was created, then update it in Thunderbird.
- **Symptom: "Relaying denied" or the server refuses the recipient.** The outgoing server is not authenticating you, or you are sending from an address that this account is not permitted to use. Check the **From** address in Step 3, and make sure the SMTP entry attached to that identity is the one belonging to that same mailbox.
- **Symptom: the message sits in the Outbox and never leaves.** Thunderbird is offline or the message was queued with **Send Later**. Click the connection indicator in the status bar to go back online, then choose **File** and **Send Unsent Messages**.
- **Symptom: sending works on some networks but not others.** Many mobile networks, hotel connections and corporate firewalls block outgoing mail ports. Test the same message on a different connection. If it sends elsewhere, the block is on the network, not on your mailbox.
- **Symptom: the recipient's server rejects the message as too large.** Remove the attachment and send a download link instead, or use Filelink. See the attachment guidance above for why the true size on the wire is larger than the file on your disk.
- **Symptom: your messages land in the recipient's spam folder.** Check that you are sending from the correct **From** address for the domain, that the subject is not empty, and that the message is not a single image or a bare link with no text. Persistent spam filing usually points at the domain's SPF, DKIM or DMARC records rather than at Thunderbird, and Noiz support can verify those for a domain hosted with Noiz.
## Next Steps
Sending a new message is one of four things you will do constantly in Thunderbird. The other three are covered separately:
- [How to Reply to Email in Mozilla Thunderbird](/email/how-to-reply-to-email-in-mozilla-thunderbird/)
- [How to Forward an Email in Mozilla Thunderbird](/email/how-to-forward-an-email-in-mozilla-thunderbird/)
- [How to Check for New Email in Mozilla Thunderbird](/email/how-to-check-for-new-email-in-mozilla-thunderbird/)
If a message still refuses to send after you have checked the outgoing server settings above, open a support ticket with the Noiz support team. Include the sending email address, the exact error text Thunderbird displays, and whether the problem affects one recipient or all of them. On Noiz managed plans the support team can check the mail server logs from the other side and tell you precisely which setting to correct.
# How to Set Up Email in Microsoft Outlook
Source: https://docs.noiz.ie/email/how-to-set-up-email-in-microsoft-outlook/
This guide shows you how to add a Noiz mailbox to Microsoft Outlook on your Windows or Mac computer, so that you can send and receive mail for your own domain from the Outlook desktop app. The single most important thing to know before you start is that "Outlook" is now two different programs that look and behave very differently: **classic Outlook** (the long-standing desktop application that ships with Microsoft 365 and Office) and **new Outlook** (the redesigned app Microsoft is rolling out to Windows, built on the same technology as Outlook on the web). Which one you have decides how you add the account, and it decides which quirks you will meet on a custom domain such as `yourdomain.com`. This article covers both, and is written for Noiz email clients whose mailbox lives on the Noiz mail platform.
The reliable route on a custom domain is a **manual IMAP setup**, where you type the exact Noiz server settings in yourself. Outlook's automatic discovery frequently fails or guesses wrongly for domains that are not large public providers, so knowing the correct values, and where to enter them, saves a great deal of trial and error. Those values are listed in full below.
**Last reviewed:** 27 July 2026, against Microsoft Outlook for Windows in both its **classic** and **new** forms, and Outlook for Mac. This guide is written for Noiz hosting and is kept current against Microsoft Outlook. It complements, and does not replace, the official Microsoft Outlook documentation linked below. Microsoft updates Outlook, and in particular the new Outlook app, very frequently: buttons move, and the account-setup screens change between builds. Where a screen differs from what is described here, the field names and the values you enter stay the same even when their arrangement moves. Where new Outlook is concerned, treat the exact wording as a guide rather than a guarantee, and fall back to classic Outlook if a manual IMAP option is not present in your build.
### Official Documentation Reference
- [Add an email account to Outlook (Microsoft)](https://support.microsoft.com/en-us/office/add-an-email-account-to-outlook-6e27792a-9267-4aa4-8bb6-c84ef146101b): Microsoft's own walkthrough, with separate tabs for new Outlook, classic Outlook and Outlook for Mac.
- [POP, IMAP and SMTP settings for Outlook (Microsoft)](https://support.microsoft.com/en-us/office/pop-imap-and-smtp-settings-d088b986-291d-42b8-9564-9c414e2aa040): the reference for the server, port and encryption fields you fill in during a manual setup.
## Prerequisites
- The mailbox already exists on the Noiz mail server. If you have not created it yet, do that first: see [How to Create an Email Address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/). Outlook can only connect to a mailbox that has already been provisioned.
- You know the full email address, for example `you@yourdomain.com`, and the password that was set when the mailbox was created. The username for Noiz mail is always the full email address, not just the part before the `@`. If you have lost the password, you can reset it from Plesk: see [How to log in to Plesk](/plesk/how-to-log-in-to-plesk/).
- Microsoft Outlook is installed and signed in. Outlook is part of Microsoft 365 and Office; keep it updated so you have current security fixes and the setup screens described here.
- A working internet connection, and a domain whose mail is hosted at Noiz. If your domain was only recently pointed to Noiz, allow DNS changes time to take effect before `mail.yourdomain.com` will resolve.
## Know Which Outlook You Have
This step decides everything that follows, so do it before you touch any settings. In new Outlook there is a labelled toggle in the top-right corner of the window that reads **New Outlook**. If you can see that switch, you are in the new app. If there is no such toggle and the ribbon along the top is dense with tabs such as **File**, **Home**, **Send / Receive** and **View**, you are in classic Outlook.
The distinction matters because the two apps handle a custom-domain mailbox in fundamentally different ways:
- **Classic Outlook** connects directly to the Noiz mail server and gives you a full manual setup screen where every field (server, port, encryption) is under your control. This is the dependable path for a domain such as `yourdomain.com`, and it is the one to use if you want certainty.
- **New Outlook** was built first for Microsoft accounts and only gained support for third-party IMAP mailboxes over time. Its manual options are far more limited, its automatic discovery often mis-handles custom domains, and, importantly, it routes your mail through Microsoft's cloud rather than talking to the Noiz server directly (explained in its own section below). It can work, but it is the fussier of the two.
If you have a choice and simply want the mailbox working quickly and predictably, use classic Outlook. If classic Outlook is not available to you, or you specifically want the new app, follow the new Outlook section and read the gotchas carefully.
## IMAP or POP: Choose IMAP
Outlook can collect your mail using one of two protocols, and the choice is not cosmetic.
- **IMAP** keeps your mail on the Noiz server and mirrors it into Outlook. Folders, and the read or unread status of every message, stay in sync across all your devices and Noiz webmail. This is the right choice for almost everyone, and it is what Noiz recommends.
- **POP** (POP3) downloads your mail to one computer and, in its traditional configuration, removes it from the server. Anything a POP client has already pulled down will not appear on your phone, your other computers, or in webmail. It suits only a single-device setup with a deliberate reason to store mail on one machine.
The practical rule: if you check mail on more than one device, or ever use webmail, choose **IMAP**. This guide uses IMAP throughout; the settings table also lists the POP values should you have a specific need for them.
## The Noiz Mail Settings
These are the settings a Noiz mailbox uses in any email program. Wherever you see `yourdomain.com`, replace it with your own domain. Keep this table to hand: a manual setup is simply a matter of typing these values into the matching fields.
| Setting | Incoming (IMAP, recommended) | Outgoing (SMTP) |
| --- | --- | --- |
| Server / hostname | `mail.yourdomain.com` | `mail.yourdomain.com` |
| Port | `993` | `465` |
| Encryption method | SSL/TLS | SSL/TLS |
| Require sign-in / authentication | Yes, normal password | Yes, normal password |
| Username | Your full email address, e.g. `you@yourdomain.com` | Your full email address, e.g. `you@yourdomain.com` |
| Password | The mailbox password | The same mailbox password |
If you have a specific reason to use POP instead of IMAP, change only the incoming server: use the same hostname `mail.yourdomain.com` with port `995` and SSL/TLS. The outgoing SMTP settings are identical either way.
Two points that catch people out on a custom domain:
- The username is the **whole address**, including `@yourdomain.com`. A username of just `you` will fail to authenticate.
- Both incoming and outgoing use **SSL/TLS** on the encrypted ports (993, 465 and 995). Do not fall back to the older unencrypted ports (143 for IMAP, 110 for POP, or 25 for SMTP); Noiz mail is encrypted throughout. Note that Noiz uses **SMTP on port 465 with SSL/TLS**, not the alternative 587 with STARTTLS that some providers default to. If Outlook pre-fills 587, change it to 465 and set the encryption to SSL/TLS.
## Set Up in Classic Outlook (Manual IMAP)
This is the dependable path. It gives you the full manual form and connects Outlook straight to the Noiz mail server.
### Start the Account Wizard
1. Open Outlook and go to **File** in the top-left, then **Add Account**. (On the very first run, Outlook may present the account screen automatically.)
2. Type your full Noiz email address, for example `you@yourdomain.com`.
3. Click **Advanced options**, tick **Let me set up my account manually**, then click **Connect**. This is the step that skips Outlook's guesswork and lets you enter the exact Noiz values.
### Choose IMAP and Enter the Servers
1. When asked to **Choose account type**, select **IMAP**.
2. Under **Incoming mail**, set the **Server** to `mail.yourdomain.com`, the **Port** to `993`, and the **Encryption method** to **SSL/TLS**.
3. Under **Outgoing mail**, set the **Server** to `mail.yourdomain.com`, the **Port** to `465`, and the **Encryption method** to **SSL/TLS**.
4. Leave **Require logon using Secure Password Authentication (SPA)** unticked. Noiz mail uses a normal password, not SPA.
5. Click **Next**.
### Enter the Password and Finish
1. Type the mailbox password when prompted and click **Connect**.
2. Outlook tests the connection to the incoming and outgoing servers. When it succeeds, you see a confirmation that the account was added.
3. Click **Done**. Outlook creates the account and begins downloading your folders and messages.
Your Noiz mailbox now appears in the folder list on the left. Send yourself a short test message and reply to it, to confirm that sending and receiving both work end to end.
## Set Up in New Outlook for Windows
New Outlook can host a Noiz mailbox, but it treats third-party domains very differently from classic Outlook, and there are real pitfalls. Read the whole section before you begin.
### Add the Account
1. Click the **Settings** gear at the top right, then choose **Accounts** and **Email accounts**. (If new Outlook opens with a welcome screen, use the **Add account** prompt there instead.)
2. Click **Add account** and type your full Noiz email address, for example `you@yourdomain.com`.
3. Click **Continue**. New Outlook now tries to detect the settings on its own.
### When Automatic Detection Fails, Enter IMAP Manually
On a custom domain, automatic detection usually does not settle cleanly. When new Outlook cannot detect the mailbox, look for an option to choose the account type and pick **IMAP**, then enter the Noiz settings from the table above: incoming server `mail.yourdomain.com` on port `993` with SSL required, outgoing server `mail.yourdomain.com` on port `465` with SSL required, and your full email address as the username. Confirm and let new Outlook connect.
### New Outlook Custom-Domain Gotchas
These are the specific issues Noiz clients meet with new Outlook on a custom domain. None of them apply to classic Outlook.
- **An IMAP option may simply not be there.** New Outlook's support for manual, third-party IMAP mailboxes has arrived gradually and varies by build. If, after entering your address, you are offered no IMAP or advanced-setup choice at all, and instead only a Microsoft sign-in, your build does not yet support what you need. Switch to classic Outlook, or use Thunderbird or Noiz webmail, rather than fighting it.
- **Do not sign in with a "Microsoft account" password.** New Outlook may present a Microsoft sign-in box and ask for a password. Your Noiz mailbox is not a Microsoft account, and its password will be rejected there. You are looking for the path that lets you add an IMAP account and enter server details, not the one that signs you in to Microsoft.
- **Auto-detection often mis-classifies the domain.** New Outlook may try to treat `mail.yourdomain.com` as a Microsoft 365 or Exchange account and loop on a password prompt. That is the detection guessing wrongly, not a problem with your mailbox. The cure is to choose IMAP explicitly and type the settings yourself.
- **New Outlook routes your mail through Microsoft's cloud.** This is the most important difference to understand. When you add a third-party IMAP mailbox to new Outlook, your messages are synchronised through Microsoft's own cloud servers rather than fetched directly from the Noiz server the way classic Outlook, Thunderbird and webmail do. Your mail works, but a copy passes through and is held on Microsoft infrastructure to power features such as search. If keeping your business mail on Noiz infrastructure matters to you, whether for privacy, data-residency or POPIA reasons, prefer classic Outlook, Thunderbird or Noiz webmail, all of which talk to the Noiz server directly.
- **Fewer manual controls.** New Outlook exposes fewer connection settings than classic Outlook. Make sure SSL is required and the ports are 993 (incoming) and 465 (outgoing); if the app will not let you set those, that is another sign to use classic Outlook for this mailbox.
## Set Up in Outlook for Mac
On a Mac, open **Outlook** > **Settings** > **Accounts**, click **+** and **Add Account**, and enter your full email address. When Outlook for Mac cannot detect a custom domain, choose **IMAP** as the type and enter the same Noiz values: incoming `mail.yourdomain.com` port `993` SSL, outgoing `mail.yourdomain.com` port `465` SSL, username the full address. The recent Outlook for Mac shares much of its design with new Outlook, so the same custom-domain caveats above are worth keeping in mind.
## Troubleshooting
- **Symptom: Outlook keeps asking for the password, or reports the credentials are wrong.** The most common cause is a username that is not the full address. Check that both the incoming and outgoing usernames are the complete `you@yourdomain.com`, not just `you`. Then confirm the password itself by signing in to Noiz webmail with the same details: see [How to Access Email from Plesk Webmail](/plesk/how-to-access-email-from-plesk-webmail/). If webmail also rejects the password, reset it in Plesk and try again.
- **Symptom: Outlook cannot find the settings automatically, or offers Microsoft 365 / Exchange when you want IMAP.** This is normal for a custom domain. In classic Outlook, tick **Let me set up my account manually** and choose **IMAP**. In new Outlook, look for the IMAP or advanced-setup option and enter the Noiz values by hand; if none is offered, use classic Outlook instead.
- **Symptom: mail is received but will not send.** This is an outgoing (SMTP) problem. Confirm the SMTP server is `mail.yourdomain.com` on port `465` with **SSL/TLS**, using your full email address to authenticate. If Outlook set the outgoing port to 587, change it to 465. Some public networks block outbound mail ports; if sending fails only on one network, test on another connection to confirm.
- **Symptom: a certificate or security warning about the mail host.** Make sure the encryption is **SSL/TLS** on ports 993 and 465, and that the hostname is spelled exactly `mail.yourdomain.com`. A warning that the certificate name does not match usually means the domain's mail is not yet fully live on Noiz, or DNS has not finished pointing to the mail server. If the domain has only recently moved to Noiz, wait for DNS to take effect and try again.
- **Symptom: new Outlook only offers a Microsoft sign-in and no way to enter server settings.** Your new Outlook build does not support the manual IMAP mailbox you need. Use classic Outlook (toggle **New Outlook** off, top-right), or set the mailbox up in Thunderbird or Noiz webmail instead.
If you work through the settings above and the account still will not connect, open a support ticket with the Noiz support team. Include the email address, whether the problem is sending, receiving or both, which version of Outlook you are using (classic or new), and a screenshot of any error message. On Noiz managed plans the support team can verify the mailbox and its settings from the server side and point you to the exact value to correct.
# How to Set Up Email in Thunderbird
Source: https://docs.noiz.ie/email/how-to-set-up-email-in-thunderbird/
Thunderbird, from the Mozilla Foundation, is a **free and open source** email client for Windows, macOS and Linux. It connects to almost any mail provider so you can read, write, send and receive email from your own computer rather than from a browser tab. This guide walks you through adding an existing mailbox, one that already lives on your Noiz hosting account, to Thunderbird, using both the automatic path and the manual path.
Thunderbird is a genuine drop-in replacement for the classic desktop Outlook that many businesses grew up on, and it is the client Noiz recommends most often to clients who want a real desktop inbox without a subscription attached to it.
**Last reviewed:** 27 July 2026, against Mozilla Thunderbird **153** (latest monthly Release) and **140 ESR** (Extended Support Release). This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below. Thunderbird ships a new monthly release alongside a slower-moving ESR, so button wording and the exact arrangement of the Account Setup screen can shift slightly between versions. The field names and the values you enter stay the same even when their position on screen moves, and the screenshots below remain representative.
### Official Documentation Reference
- [Thunderbird Support (Mozilla)](https://support.mozilla.org/en-US/products/thunderbird): the official support hub, kept current with every release.
- [Automatic Account Configuration](https://support.mozilla.org/en-US/kb/automatic-account-configuration): how Thunderbird tries to discover mail settings for you, and why it sometimes cannot.
- [Manual Account Configuration](https://support.mozilla.org/en-US/kb/manual-account-configuration): the reference for every field in the manual setup form.
- [Install, Migrate and Update Thunderbird](https://support.mozilla.org/en-US/products/thunderbird/install-migrate-and-update): installation and upgrade guidance for each operating system.
## Prerequisites
- The mailbox already exists on the server. Thunderbird can only connect to a mailbox that has been created first. If you have not created it yet, see [How to Create an Email Address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/), [How to Create an Email Account in cPanel](/cpanel/how-to-create-an-email-account-in-cpanel/), [How to Create an Email Account in DirectAdmin](/directadmin/how-to-create-an-email-account-in-directadmin/) or [How to Create an Email Mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/), depending on the control panel that came with your package.
- You know the full email address, for example `you@yourdomain.com`, and the mailbox password that was set when the address was created. That password is set at server level, not inside Thunderbird.
- Your domain's mail is already pointed at Noiz. If the domain was only recently moved across, allow DNS changes time to propagate before the mail hostname will resolve.
## Overview
- Download and install Thunderbird.
- Enter your email address and password.
- Let Thunderbird configure the account automatically, or configure it manually.
The video below walks through the same process end to end if you prefer to watch rather than read.
## Download Thunderbird
- If Thunderbird is not already installed, start there. From your web browser, go to [https://www.thunderbird.net/en-US/](https://www.thunderbird.net/en-US/) and click the free download button. Always download from thunderbird.net rather than a third-party download site, so you get a genuine, unmodified build.
- Run the installer for your operating system. Software installation sits outside the scope of this guide, but Mozilla's [install, migrate and update articles](https://support.mozilla.org/en-US/products/thunderbird/install-migrate-and-update) cover every platform.
- Once installation finishes, Thunderbird opens and asks you to **Set Up Your Existing Email Address**. If Thunderbird is already installed and you are adding a second mailbox, open that same screen from the **โฐ** menu at the top right, then **New**, then **Existing Mail Account**.

## Set Up Your Existing Email Address
- This first screen is much the same in every email client. You are asked for a **name**, an **email address** and a **password**. The name is the display name recipients see, so it can be your full name, a nickname, your company name, or the role of whoever mans the mailbox. That choice is yours. The **email address** and **password**, however, must match exactly what was created on the mail server.
- Click **Continue**. Thunderbird then tries to work out the mail server settings for your address on its own.
- If you already know your server settings, or you would rather not rely on discovery, click **Configure manually** and skip ahead to the manual section below.

- **IMAP** is the recommended configuration on every Noiz mail server, because it keeps your mail on the server and mirrors it to Thunderbird. Folders, read and unread status, and every message stay in sync across your laptop, your phone and webmail. **POP** downloads mail to one computer and, by default, removes it from the server, so your other devices and webmail will not see it. Unless you have a specific reason to keep mail on a single machine, choose IMAP and click **Done**.
Switching between IMAP and POP later means removing the account and adding it again, so it is worth getting this right at setup. If you do need to remove one, see [How to Remove an Email Account in Thunderbird](/email/how-to-remove-an-email-account-in-thunderbird/).
That is it. If all went well, your account is set up and ready to send and receive.
**Note**: If you are not sure whether the mailbox exists on the server yet, check in the control panel that came with your hosting account, or contact the Noiz support team through the client area or by emailing [support@noiz.co.za](mailto:support@noiz.co.za).
## Manual Configuration
You may want to enter the server settings yourself for several reasons:
- Automatic configuration failed or timed out. This is common on custom domains, because discovery relies on optional DNS records and well-known URLs that a domain need not publish.
- Discovery returned settings you do not recognise, such as a generic hostname belonging to a previous provider.
- You want to connect to a specific hostname, for example the server hostname rather than `mail.yourdomain.com`, while DNS is still settling after a migration.
Clicking **Configure manually** expands the form so you can enter incoming and outgoing server details directly.

Noiz mail settings follow a standard template. Replace `yourdomain.com` with your own domain throughout.
| Setting | Incoming | Outgoing |
| --- | --- | --- |
| Protocol | IMAP (recommended) or POP | SMTP |
| Hostname | `mail.yourdomain.com` | `mail.yourdomain.com` |
| Port | `993` for IMAP, `995` for POP | `465` |
| Connection security | SSL/TLS | SSL/TLS |
| Authentication method | Normal password | Normal password |
| Username | Your full email address, `you@yourdomain.com` | Your full email address, `you@yourdomain.com` |
| Password | The mailbox password set at server level | The same mailbox password |
Two details catch people out most often:
- The username is the **whole address**, including the `@yourdomain.com` part. Entering just the portion before the `@` will fail authentication, even though the password is correct.
- Both directions use **SSL/TLS** on the encrypted ports. Do not fall back to the unencrypted ports (143 for IMAP, 110 for POP, or plain 25). These are secure settings and they are strongly recommended. If you have an unusual requirement that appears to need insecure settings, contact Noiz support before changing anything.
The mailbox password is set or reset through the control panel that comes with your hosting package, whether that is Plesk, cPanel, DirectAdmin or ISPConfig. Thunderbird never changes it: if you reset the password in the panel, you must update it in Thunderbird as well, or the account will keep prompting.
### When the Done Button Is Greyed Out
After entering the settings, click **Re-test** first. Thunderbird will attempt a live connection and, if it succeeds, enable **Done**. This is the cleanest outcome, because it proves the hostname, port and credentials all work before the account is created.
If **Done** stays greyed out, Thunderbird could not verify the settings itself. You can still proceed: click **Advanced config**, then choose **OK** on the **Confirm Advanced Configuration** prompt to force the account to use exactly the values you entered.

Be aware of what this does. Advanced config creates the account and drops you into Account Settings without a successful test, so if a value is wrong you will find out later as a repeating password prompt or a send failure rather than as a clear error now. Use it when you are confident the settings are right and something transient, such as DNS still propagating, is blocking the test.
## Troubleshooting
- **Thunderbird keeps asking for the password**: the username is almost always the cause. Open **Account Settings**, then **Server Settings**, and confirm the username is the full email address. Check the same under **Outgoing Server (SMTP)**, which stores its username separately.
- **Mail arrives but will not send**: incoming is configured and outgoing is not. Confirm the SMTP entry uses `mail.yourdomain.com` on port `465` with SSL/TLS and normal password authentication. Some networks, particularly mobile and hotel Wi-Fi, also block outbound mail ports, so test on a different connection before assuming the settings are wrong.
- **Certificate warning on connect**: this usually means the hostname you entered does not match the certificate, most often because the domain is still pointing at a previous host. Do not click through the warning permanently. Wait for DNS to complete, or contact Noiz support to confirm the correct hostname for your server.
- **Automatic configuration finds the wrong provider**: an old autodiscover record from a previous host can survive a migration. Use **Configure manually** with the settings in the table above, then ask Noiz support to check for stale DNS records.
## Next Steps
With the account connected, a few small adjustments make Thunderbird considerably more pleasant to live in day to day:
- [The Best Thunderbird Settings to Configure First](/email/the-best-thunderbird-settings-to-configure-first/)
- [How to Organise Your Email with Folders and Filters in Thunderbird](/email/how-to-organise-your-email-with-folders-and-filters-in-thunderbird/)
- [How to Create a Professional HTML Email Signature in Thunderbird](/email/how-to-create-a-professional-html-email-signature-in-thunderbird/)
- [How to Set Up OpenPGP Encryption Keys in Thunderbird](/email/how-to-set-up-openpgp-encryption-keys-in-thunderbird/) and [How to Send Encrypted and Signed Email with OpenPGP in Thunderbird](/email/how-to-send-encrypted-and-signed-email-with-openpgp-in-thunderbird/)
For a fuller reference on the Account Setup screen itself, including a side-by-side comparison of IMAP and POP, see [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/).
## Conclusion
Thunderbird is one of the best desktop email clients available for reading, writing, sending and receiving mail, and it costs nothing to run. You have now connected a domain mailbox to it both automatically and manually, and you know which settings to reach for when discovery does not cooperate.
If you get stuck at any point, open a support ticket from the Noiz client area or email [support@noiz.co.za](mailto:support@noiz.co.za), and a Noiz hosting agent will walk you through the setup.
# How to Set Up Email on Android
Source: https://docs.noiz.ie/email/how-to-set-up-email-on-android/
This guide shows you how to add your domain email address, sometimes called a mailbox or email account, to the Gmail app on an Android phone or tablet. The Gmail app is the default mail app on most Android devices, so you do not need to install anything extra. By the end you will be able to send and receive mail for an address such as `you@yourdomain.com` directly from your phone, alongside any Gmail addresses you already use in the app. The setup uses IMAP, which keeps your mail synchronised between your phone, webmail, and any other devices.
Google's own documentation describes the Gmail app in general. What it cannot tell you is what the screens look like when the mailbox is hosted at Noiz, which values to type, which of the choices on those screens are effectively permanent, and how to prove afterwards that both halves of the connection actually work. That local detail is what this guide adds.
**Note on which app to use.** Many Android phones ship with a second mail app beside Gmail, usually called simply **Email** and supplied by the handset manufacturer. Its setup screens use different wording and it stores its settings separately, so following these steps in that app will not work. The steps below are for the **Gmail** app, because it is the one Google maintains on every Android device and the one Noiz support can talk you through reliably. If your phone shows two mail apps, use Gmail and ignore the other.
**Last reviewed:** 27 July 2026, against the current Gmail for Android release. This guide is written for Noiz hosting and is kept current against the Gmail app. It complements, and does not replace, the official Google documentation linked below. Google updates the Gmail app silently and often, so the wording of a button or the order of two screens can move between releases. The values you enter do not change when the layout does, so work from the settings in Step 1 rather than from the exact position of a field on screen.
### Official Documentation Reference
- [Add another email account in the Gmail app (Android)](https://support.google.com/mail/answer/6078445?hl=en&co=GENIE.Platform%3DAndroid): Google's reference for both the automatic and the manual IMAP setup used in this guide.
- [Gmail on Google Play](https://play.google.com/store/apps/details?id=com.google.android.gm): install or update the Gmail app before you start.
- [Fix sync errors with the Gmail app (Android)](https://support.google.com/mail/answer/6383854?co=GENIE.Platform%3DAndroid): what to try when an account connects but stops fetching mail.
- [Get the most life from your Android device's battery (Android Help)](https://support.google.com/android/answer/7664358): the battery restrictions that can silently stop background mail sync.
## Prerequisites
- An existing mailbox on your Noiz hosting plan. A mail app can only connect to a mailbox that already exists on the server, so create it first if you have not: see [How to Create an Email Address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/), [How to Create an Email Account in cPanel](/cpanel/how-to-create-an-email-account-in-cpanel/), [How to Create an Email Account in DirectAdmin](/directadmin/how-to-create-an-email-account-in-directadmin/) or [How to Create an Email Mailbox in ISPConfig](/ispconfig/how-to-create-an-email-mailbox-in-ispconfig/), depending on the control panel that came with your package.
- The full email address and its password.
- Your mail server name, which is included in your Noiz welcome email.
- An Android phone or tablet with the Gmail app installed, updated, and connected to the internet.
## Before You Start: Two Choices That Are Hard to Undo
The Gmail setup screens present two decisions without explaining what either one costs you later. Both are worth thirty seconds of thought now, because changing your mind afterwards means deleting the account from the phone and starting again.
### IMAP, Not POP3
When the app asks what type of account this is, it offers **Personal (IMAP)** and **Personal (POP3)**. Choose **Personal (IMAP)**.
- **IMAP** keeps the mail on the Noiz mail server and mirrors it to the phone. Folders, read and unread status, and deletions stay in step across your phone, your computer and webmail.
- **POP3** downloads mail to the phone and, on the usual default, removes it from the server. Anything the phone collects while you are out is then missing from webmail and from your laptop, and it exists only in that one handset. If the handset is lost, so is the mail.
A POP3 account on a phone is a frequent explanation behind a report that mail has "disappeared from webmail", because the handset has quietly collected it and taken it off the server. There is no switch inside the Gmail app that converts a POP3 account to IMAP afterwards: you have to remove the account and add it again, which is covered under **If You Need to Start Over** below.
### Which Mail Hostname to Use
The hostname `mail.yourdomain.com` only resolves once your domain's DNS is pointing at the Noiz nameservers, `ns1.noiz.co.za` and `ns2.noiz.co.za`. That matters in two situations:
- **You have just moved the domain to Noiz.** Until the change has propagated, `mail.yourdomain.com` may still be answering from your previous host, and the phone will happily connect to the old provider's empty mailbox. Use the server hostname given in your Noiz welcome email until the domain has fully moved, then switch to `mail.yourdomain.com`.
- **Your website is behind a proxy or CDN.** If `mail.yourdomain.com` has been pointed at a proxy along with the website, the mail ports will not answer. Use the hostname from your welcome email instead, and ask Noiz support to check the record.
If you cannot find your welcome email, the mail hostname for your package is also shown in the Noiz client area and in the control panel that came with your plan. Do not guess it, and do not copy it from an old device that has not connected in months.
## Step 1: Gather Your Mail Settings
Have the following details ready before you start. Everywhere you see `yourdomain.com` below, replace it with your own domain name, because it is an example placeholder and not a real value.
- **Username**: your full email address, for example `you@yourdomain.com`
- **Password**: the mailbox password you chose when the mailbox was created
- **Incoming (IMAP) server**: `mail.yourdomain.com`, port `993`, security `SSL/TLS`
- **Outgoing (SMTP) server**: `mail.yourdomain.com`, port `465`, security `SSL/TLS` (port `587` with `STARTTLS` also works)
The Gmail app chooses secure ports automatically in most cases, so you may never be asked for them. If the app does prompt you for a port or security type, use the values above. If your welcome email lists a different server name, use that instead of `mail.yourdomain.com`.
Two points about these values are specific to Noiz and worth knowing before a setting looks broken to you:
- **Encryption is not optional.** Noiz mail servers accept IMAP and SMTP only over an encrypted connection negotiating TLS 1.2 or higher. There is no unencrypted fallback on port `143` or plain `25` to drop back to, so if a screen offers a security type of `None`, that setting will simply fail rather than working less securely. The background to this is in [Why Some Email Apps Stop Working After a Mail Security Upgrade](/email/why-some-email-apps-stop-working-after-a-mail-security-upgrade/).
- **Outgoing mail must authenticate.** Port `25` is reserved for server-to-server delivery and will not relay mail from your phone. Sending always goes out on `465` or `587` with your full email address and password supplied, which is why the app asks for the credentials twice.
## Step 2: Add the Account in the Gmail App
These steps follow the official Google procedure for a manual IMAP setup.
### Open the Account Menu
1. Open the **Gmail** app on your Android device.
2. At the top right, in the search bar, tap your **profile icon** (your photo or initial).
3. Tap **Add another account**.
### Choose the Account Type
1. On the **Set up email** screen, tap **Other**. Do not choose Google, Outlook, or Yahoo, because those options are only for accounts hosted with that provider.
2. Enter your full email address, for example `you@yourdomain.com`, then tap **Next**.
3. When asked what kind of account this is, select **Personal (IMAP)**.
4. Enter your mailbox password, then tap **Next**.
A Noiz-hosted mailbox at your own domain is always an **Other** account, even if you also use Gmail personally, and even if your domain's mail once passed through Google in the past. Tapping **Google** here starts a Google sign-in that your mailbox password will not satisfy, and the failure message it returns does not make the cause obvious.
### Confirm the Server Settings
The app now tries to detect your server settings automatically. If it shows the server screens, check each one against the values from Step 1.
1. On the **Incoming server settings** screen, confirm the **Username** is your full email address, the **Password** is correct, and the **Server** is `mail.yourdomain.com` (using your own domain). Tap **Next**.
2. On the **Outgoing server settings** screen, leave **Require sign-in** switched on, confirm the same username and password, and set the **SMTP server** to `mail.yourdomain.com`. Tap **Next**.
Two things commonly go wrong on these two screens:
- **The app skips them entirely.** If detection succeeds, Gmail moves straight to the account options and you never see the server fields. That is fine, but it also means you have not seen what it chose. Check the values afterwards under **Settings**, your account, **Incoming settings** and **Outgoing settings**, and correct the hostname there if detection picked up a stale record from a previous host.
- **The app pauses on "Checking incoming server settings" and then fails.** Nine times out of ten the username has been shortened to the part before the `@`. Noiz mail servers authenticate on the whole address, so `you` will be rejected where `you@yourdomain.com` succeeds, with the same password.
### Finish the Setup
1. On the **Account options** screen, choose how often the app checks for mail (**Sync frequency**) and whether to notify you when email arrives, then tap **Next**.
2. Give the account a name if you want one (this is only a label shown inside the app), and enter **Your name** as you want it to appear on outgoing messages. Tap **Next** to finish.
The name you type in **Your name** is the display name every recipient sees beside your address, so it is worth a moment's thought on a business mailbox. Use the person's full name for a personal address, or the business name for a shared address such as `info@yourdomain.com`. The **Account name** above it is private to the phone and only exists to help you tell accounts apart in the switcher, so something short like "Work" is ideal when you have several mailboxes on the same device.
## Step 3: Check That It Works
An account that appears in the switcher is not proof of a working setup. Incoming and outgoing mail are two separate connections with separate credentials, and it is entirely normal for one to work while the other quietly fails. The round trip below tests both, and tells you which half is at fault if it does not complete.
### Run a Round-Trip Test
1. Tap your **profile icon** at the top right and select your new address to switch to its inbox.
2. Tap **Compose** and, before typing anything, check the **From** field at the top of the message. If you have several accounts on the device, Gmail composes from whichever one you last used, not necessarily the one whose inbox you are looking at. Tap the **From** line and pick your domain address if it shows anything else.
3. Send the message to an address you control at a different provider, not to another mailbox on the same domain. Mail between two mailboxes on the same server never leaves it, so it proves far less than an external round trip.
4. Reply to that message from the other provider.
5. Confirm the reply arrives in the Gmail app within a few minutes.
### Read the Result
What happens tells you exactly where to look:
- **Both directions work.** The setup is complete and correct. Move on to the folder check below.
- **The test message never leaves the phone, or an error appears when sending.** Outgoing is the problem. Check the SMTP hostname, the port, and that **Require sign-in** is switched on with the full address as the username.
- **Sending works but the reply never arrives.** Incoming is the problem, or sync has been suspended in the background. Swipe down in the inbox to force a check before assuming the worst.
- **The reply arrives, but your original landed in the recipient's spam folder.** Nothing is wrong with the phone. That is a domain reputation and DNS matter, and it is fixed on the domain rather than on the device: see [How to Protect Your Domain from Spoofing and Improve Email Deliverability](/email/how-to-protect-your-domain-from-spoofing-and-improve-email-deliverability/).
### Confirm the Phone Is Writing to the Server
One last check catches a setup that looks healthy but is not properly synchronised. Open your mailbox in webmail on a computer, using [Plesk webmail](/plesk/how-to-access-email-from-plesk-webmail/) or the webmail that comes with your package, and look in the **Sent** folder for the test message you sent from the phone.
- **It is there.** The account is genuinely on IMAP and the phone is storing sent mail on the server, so every device sees the same history.
- **It is missing.** The phone is keeping sent mail to itself, which usually means the account was added as POP3 rather than IMAP. Remove it and add it again, choosing **Personal (IMAP)** this time.
## Where Your Sent and Deleted Mail Goes
On an IMAP account the folders you see on the phone are the folders on the Noiz mail server, so an action on the handset is an action on the server. That has three practical consequences worth knowing at setup time rather than discovering later.
- **Deleting on the phone deletes everywhere.** A message you remove on the train is gone from webmail and from your laptop too. That is the correct behaviour for IMAP and it is why the mailbox stays consistent, but it does surprise people arriving from a POP3 setup where the phone had its own private copy.
- **Deleted mail still uses your quota.** Deleting moves the message to the server's **Trash** folder, where it continues to occupy space against the mailbox quota set in your control panel until the Trash is emptied. If you are close to your quota and deleting messages has not helped, the Trash is almost always where the space has gone. Empty it from webmail or from the phone.
- **The Gmail app maps the server folders for you.** Unlike desktop clients, the Gmail app does not expose controls for choosing which server folder holds sent mail, drafts and deleted mail. It picks them automatically. That works fine in normal use, but if you ever find sent mail appearing in two folders in webmail, or a folder named for a previous mail provider still hanging around, that is a leftover on the server rather than a phone fault, and Noiz support can tidy it up for you.
Reading, replying, composing, deleting and tidying mail day to day are covered in [How to Read Email on Android](/email/how-to-read-send-and-delete-email-on-android/), which picks up where this guide finishes.
## If You Need to Start Over
If you chose POP3 by mistake, typed the wrong hostname into an account that then would not connect, or want to move a mailbox to a different phone, the cleanest fix is to remove the account and add it again. Removing an account added through **Other** takes the mailbox off the device only. It does not delete the mailbox, and nothing on the server is affected.
1. In the Gmail app, tap your **profile icon**, then **Manage accounts on this device**.
2. Select the address you want to remove, then choose **Remove account**. Android will ask you to confirm.
3. Any mail still waiting in the account's outbox on that phone goes with it, so send or copy out anything unsent first.
4. Work through Step 2 again from a clean start.
## Troubleshooting
- **"Username or password incorrect" or sign-in fails**: the username must be the full email address, not just the part before the @. Retype the password carefully. If it still fails, reset the mailbox password in your hosting control panel and try again with the new one.
- **A certificate or security warning appears**: this usually means the server name does not match the certificate. Double-check the server name against your Noiz welcome email. Never set the security type to `None` to silence the warning, as that would send your password unencrypted.
- **Mail arrives but sending fails**: open the outgoing server settings and confirm **Require sign-in** is on with the same username and password as incoming mail. If the port is set to `25`, change it to `465` with `SSL/TLS`, because many mobile networks block port 25.
- **No notifications for new mail**: in the Gmail app, tap your profile icon, then **Manage accounts on this device**, select the account, and check its sync and notification settings. Also make sure your phone's battery saver is not restricting the Gmail app in the background.
- **The Other option is missing**: update the Gmail app from Google Play, then reopen it and try again. Very old versions of the app use a different setup flow.
- **Mail only arrives when you open the app**: the handset is suspending Gmail in the background to save power, which many Android manufacturers do far more aggressively than stock Android. Open the phone's **Settings**, then **Apps**, then **Gmail**, then **Battery**, and set it to **Unrestricted**. Some devices also keep a separate power-saving or "sleeping apps" list that Gmail must be removed from.
- **Gmail keeps asking for the password after you changed it**: the app stores the password twice, once for incoming and once for outgoing, and updating one prompt does not update the other. Go to **Settings**, tap the account, and set the new password under both **Incoming settings** and **Outgoing settings**. If the panel password was reset, see [How to Change Email Account Password in Plesk](/plesk/how-to-change-email-account-password-in-plesk/) for where it is set.
- **The account connects on Wi-Fi but not on mobile data, or the other way round**: this is the network blocking mail ports rather than a settings fault. Test the same account on a different connection to confirm, then use port `587` with `STARTTLS` for outgoing mail, which is blocked less often than `465` on restrictive networks.
- **Everything was working and has now stopped for every device, not just the phone**: the fault is not in the Android setup. Work through [Why Is My Email Not Working? An Email Troubleshooting Guide](/email/why-is-my-email-not-working-an-email-troubleshooting-guide/), which covers the domain-wide and server-side causes.
## Next Steps
- [How to Read Email on Android](/email/how-to-read-send-and-delete-email-on-android/): reading and composing messages, switching accounts, combining inboxes, notifications, and deleting mail.
- [How to Access Email from Plesk Webmail](/plesk/how-to-access-email-from-plesk-webmail/): the browser view of the same mailbox, useful for checking what the server actually holds.
- [How to Set Up Email on iPhone or iPad](/email/how-to-set-up-email-on-iphone-or-ipad/): the same mailbox on an Apple device, using the same settings.
If you get stuck at any point, open a support ticket with the Noiz support team. Include the email address you are trying to add and a screenshot of any error message, and a technician will check the mailbox and server settings for you.
# How to Set Up Email on iPhone or iPad
Source: https://docs.noiz.ie/email/how-to-set-up-email-on-iphone-or-ipad/
This guide shows you how to add your hosted email address to an iPhone or iPad using the built-in Apple Mail app, so that new messages arrive on your device automatically. It is written for anyone with a mailbox on a Noiz hosting plan. A mailbox is sometimes called an email account, and the manual setup method described here is often referred to as an IMAP or POP configuration.
**Last reviewed:** 27 July 2026, against iOS **26.5.2** (latest stable). This article reproduces the official Apple procedure for adding an email account to an iPhone or iPad. Apple releases iOS updates frequently, so always cross-reference the current version of the official documentation before starting: direct links to every section used in this guide are provided below.
### Official Documentation Reference
- [Add an email account to your iPhone or iPad](https://support.apple.com/en-us/102619): the main Apple procedure this guide follows, covering both automatic and manual setup.
- [Set up mail, contacts and calendar accounts (iPhone User Guide)](https://support.apple.com/guide/iphone/set-up-mail-contacts-and-calendar-accounts-ipha0d932e96/ios): the same task in the official iPhone User Guide.
- [Choose the correct email provider when adding an account to Mail](https://support.apple.com/en-us/102088): explains why hosted mailboxes use the manual (Other) option rather than a listed provider.
- [If you can't send email on your iPhone or iPad](https://support.apple.com/en-us/102556): Apple's troubleshooting steps for outgoing mail.
- [If you can't receive email on your iPhone or iPad](https://support.apple.com/en-us/102578): Apple's troubleshooting steps for incoming mail.
## Prerequisites
- A mailbox that already exists on your hosting plan. If you still need to create one and your plan uses Plesk, see [How to create an email address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/).
- The full email address and the mailbox password.
- An iPhone or iPad connected to the internet.
- The menu paths below are for iOS 18 and later, including iOS 26. On iOS 17 and earlier, **Mail** appears directly in the main **Settings** list instead of under **Apps**.
## Your Mail Server Settings
Keep these values to hand before you start. Wherever you see `yourdomain.com`, replace it with your own domain name, as it is an example placeholder, not a real server.
- **Incoming mail server (IMAP, recommended):** `mail.yourdomain.com`, port `993`, SSL enabled
- **Incoming mail server (POP3, alternative):** `mail.yourdomain.com`, port `995`, SSL enabled
- **Outgoing mail server (SMTP):** `mail.yourdomain.com`, port `465`, SSL enabled
- **Username:** your full email address, for example `info@yourdomain.com`
- **Password:** your mailbox password
Choose IMAP unless you have a specific reason not to. IMAP keeps your mail on the server and synchronises it across all your devices, while POP3 downloads messages to a single device.
## Add the Email Account to Your Device
### Step 1: Open the Mail Account Settings
1. Open **Settings** on your iPhone or iPad.
2. Tap **Apps**, then tap **Mail**.
3. Tap **Mail Accounts**.
4. Tap **Add Account**.
### Step 2: Choose Manual Setup
Hosted mailboxes are not one of the listed providers such as iCloud or Google, so you set them up through the manual option.
1. Enter your email address, for example `info@yourdomain.com`, then tap **Next**.
2. Tap **Add Other Account**, then tap **Mail Account**.
### Step 3: Enter Your Account Details
1. Complete the **New Account** form:
- **Name:** your name as you want it to appear to recipients.
- **Email:** your full email address, for example `info@yourdomain.com`.
- **Password:** your mailbox password.
- **Description:** a label for the account, for example `Work Email`.
2. Tap **Next**. Mail tries to find your email settings automatically.
3. If Mail finds the settings, tap **Done**. The account is ready, and you can skip to the verification section below. If it cannot find them, tap **Next** and continue with Step 4.
### Step 4: Enter the Mail Server Settings Manually
1. Select **IMAP** at the top of the screen (recommended over POP).
2. Under **Incoming Mail Server**, enter:
- **Host Name:** `mail.yourdomain.com` (replace with your own domain)
- **User Name:** your full email address
- **Password:** your mailbox password
3. Under **Outgoing Mail Server**, enter the same three values. The outgoing username and password are marked optional on this screen, but you must fill them in, otherwise sending will fail later.
4. Tap **Next**. Verification can take a minute or two.
5. When verification completes, tap **Save**. If iOS reports that the settings are incorrect, check each value for typing errors and try again.
## Verify the Server Settings After Setup
iOS sometimes saves an account with defaults that stop outgoing mail from working. Checking these two screens now takes a minute and prevents the most common problems later.
### Outgoing (SMTP) Settings
1. Go to **Settings**, tap **Apps**, then **Mail**, then **Mail Accounts**, and tap your newly added account.
2. Tap the row showing your email address to open the account details.
3. Under **Outgoing Mail Server**, tap **SMTP**, then tap your server under **Primary Server**.
4. Confirm the following, then tap **Done**:
- **Use SSL:** on
- **Authentication:** `Password`
- **Server Port:** `465`
### Incoming (IMAP or POP3) Settings
1. Go back to the account details screen and tap **Advanced** at the bottom.
2. Confirm the following:
- **Use SSL:** on
- **Server Port:** `993` for IMAP, or `995` if you chose POP3
Once the account is saved, open the **Mail** app from your home screen. Your new account appears in the mailbox list and new messages arrive automatically.
## Troubleshooting
**iOS shows a "Cannot Verify Server Identity" warning:** the host name does not match the mail server certificate. Open the account settings and make sure both the incoming and outgoing host names are exactly `mail.yourdomain.com` (with your own domain), with no spelling mistakes or extra spaces.
**You can receive mail but cannot send it:** almost always an SMTP setting. Work through the Outgoing (SMTP) Settings section above and confirm the username and password are filled in, **Use SSL** is on and the port is `465`. Apple's guide [If you can't send email on your iPhone or iPad](https://support.apple.com/en-us/102556) covers further device-side checks.
**You can send mail but new messages do not arrive:** check the Incoming settings above, then see Apple's guide [If you can't receive email on your iPhone or iPad](https://support.apple.com/en-us/102578).
**Your password is rejected repeatedly:** confirm the username is your full email address, not just the part before the @ sign. If you are unsure of the password, reset it in your hosting control panel and try again with the new one.
**New mail only appears when you open the Mail app:** go to **Settings**, tap **Apps**, then **Mail**, then **Mail Accounts**, then **Fetch New Data**, and set a fetch schedule such as every 15 minutes. Standard IMAP accounts use fetch rather than push, so a schedule is needed for automatic delivery.
If you get stuck at any point, open a support ticket with the Noiz support team. Include the step where the setup fails and the exact error message shown on the screen, and the team will help you get your mailbox working on your device.
# How to Set Up OpenPGP Encryption Keys in Thunderbird
Source: https://docs.noiz.ie/email/how-to-set-up-openpgp-encryption-keys-in-thunderbird/
This guide walks you through setting up OpenPGP end-to-end encryption keys in Mozilla Thunderbird so you can send and receive private, signed email from your Noiz mailbox. You will generate your own personal key pair, decide how it expires and how it is protected, make a safe backup of the sensitive half, share the public half so people can write to you securely, and import the public keys of the people you correspond with. OpenPGP (sometimes written PGP, and closely related to the GnuPG or GPG tools) has been built directly into Thunderbird since version 78, so there is no Enigmail add-on to install any more. This article is for anyone running a Noiz email account in Thunderbird who wants genuine end-to-end privacy, and it is the foundation for actually sending encrypted mail: once your keys are in place, encrypting a message is a click away.
**Last reviewed:** 27 July 2026, against Thunderbird **140** (latest stable, covering both the monthly Release and ESR channels). This guide is written for Noiz hosting and is kept current against Thunderbird; wording and the exact position of a button can vary slightly between versions. It complements, and does not replace, the official Thunderbird documentation linked below.
### Official Documentation Reference
- [OpenPGP in Thunderbird: HOWTO and FAQ (Mozilla Support)](https://support.mozilla.org/en-US/kb/openpgp-thunderbird-howto-and-faq): the authoritative reference for every OpenPGP feature in Thunderbird, including key generation, backup, acceptance levels, and common questions.
- [Introduction to end-to-end encryption (Mozilla Support)](https://support.mozilla.org/en-US/kb/introduction-to-e2e-encryption): a plain-language explanation of what end-to-end encryption is and how public and secret keys work together.
- [keys.openpgp.org: about the verifying keyserver](https://keys.openpgp.org/about): how the modern, privacy-respecting keyserver verifies an email address before it will serve a public key.
- [OpenPGP.org](https://www.openpgp.org/): the home of the open standard that Thunderbird, GnuPG, and other tools all implement, so keys are interoperable between them.
## Prerequisites
- Thunderbird 78 or later (the guidance here is written for the current 140 series). The built-in OpenPGP feature is present in every recent version; older releases needed the separate Enigmail add-on, which is now retired.
- Your Noiz email account already added to Thunderbird. If you have not done this yet, follow [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/) first, then come back here.
- A few minutes of uninterrupted time, and somewhere safe and offline (an encrypted USB stick or a password manager's secure file store) to keep your key backup.
## How OpenPGP Fits With Your Noiz Mailbox
The most important thing to understand before you start is that OpenPGP is **end-to-end**. Your message is encrypted on your own computer, inside Thunderbird, before it ever reaches a mail server, and it is only decrypted on the recipient's computer. Nothing in the middle can read it, including the mail servers that carry it.
The practical upshot for Noiz customers is reassuring: you do not need to change anything about your mailbox to use OpenPGP. Your normal account settings, incoming IMAP on `mail.yourdomain.com` port `993` over SSL/TLS and outgoing SMTP on `mail.yourdomain.com` port `465` over SSL/TLS, carry an OpenPGP-encrypted message exactly as they carry any other. (Replace `yourdomain.com` with your own domain.) There is no server-side setting to switch on, no certificate to buy from Noiz, and no special mailbox type. OpenPGP is entirely a matter of the keys you set up in Thunderbird, which is what the rest of this guide covers.
It is worth being clear about what the two layers protect. The SSL/TLS on your Noiz connection protects the link between Thunderbird and the mail server (encryption in transit). OpenPGP protects the *contents* of the message itself, all the way to the person you are writing to (encryption end-to-end). They work together and neither replaces the other.
## Understanding Your Key Pair
OpenPGP works with a matched pair of keys that are generated together and belong to you:
- Your **public key** is meant to be handed out freely. People use it to encrypt mail so that only you can read it, and to check that a message really came from you. Think of it as an open padlock you give to anyone: they can snap it shut around a message, but they cannot reopen it.
- Your **secret key** (also called the private key) never leaves your control. It is the only thing that can decrypt mail sent to you and the only thing that can sign mail as genuinely yours. If someone else gets a copy of your secret key, they can read your encrypted mail and impersonate you, which is why protecting and backing it up carefully, covered below, matters so much.
You generate this pair once per email address. After that, setup is mostly about looking after your own secret key and exchanging public keys with the people you write to.
## Generate Your Personal Key Pair
### Open the End-To-End Encryption settings
1. Open **Account Settings** (the menu button **โก** at the top right, then **Account Settings**; or right-click your account in the folder list and choose **Settings**).
2. In the left-hand list, under your Noiz account, select **End-To-End Encryption**.
3. In the OpenPGP section, click **Add Key**.
4. Choose **Create a new OpenPGP Key** and click **Continue**. (The other option, importing an existing key, is for people who already have a key from GnuPG or another mail program.)
### Choose an expiry period
Thunderbird asks how long the key should stay valid. A key with an expiry date is generally the safer choice: if you ever lose access to it, it will eventually stop being used by others rather than lingering forever. A period of two to three years is a sensible default for most people, and you can always extend the date later before it lapses. Choosing **Key does not expire** is only worth it if you are confident you will manage the key for the long term. Whatever you pick is not permanent; expiry can be changed after the fact from the Key Manager.
### Pick the key type (optional Advanced settings)
The defaults are fine for almost everyone, so you can simply move on. If you expand the **Advanced** section, you can choose between two key types:
- **ECC (Elliptic Curve)**: a modern, fast key type that produces short keys with strong security. A good default on current hardware.
- **RSA**: the long-established type, offered at `3072` or `4096` bits. Choose RSA if you need to interoperate with older tools or a correspondent specifically asks for it. Larger RSA sizes are slower but no more compatible.
If in doubt, accept whatever Thunderbird has pre-selected. Both types are part of the OpenPGP standard and are understood by GnuPG and other mail clients.
### Generate
1. Click **Generate key** and confirm when prompted.
2. Generation can take from a few seconds to a minute or two. It is normal for it to pause while it gathers randomness; there is nothing to do but wait.
3. When it finishes, your new key appears listed under End-To-End Encryption, selected as the personal key for this account. Thunderbird is now ready to sign and, once you have a recipient's public key, encrypt.
## Protect Your Secret Key at Rest
This is the single most important gotcha in Thunderbird's OpenPGP feature, and it surprises people who have used GnuPG before. Thunderbird does **not** put a passphrase on the secret key itself when it creates it. Instead, your secret key is stored inside Thunderbird's own profile on your computer. If you set nothing else, anyone who can open Thunderbird on your unlocked machine can use your key.
The proper way to protect it is to set a **Primary Password** in Thunderbird, which encrypts the stored key material (and your saved mailbox passwords) so it cannot be used without that one password:
1. Open **Settings** from the menu button **โก**.
2. Go to **Privacy & Security**.
3. Under **Passwords**, tick **Use a Primary Password** and set a strong one you will remember.
Thunderbird will then ask for this password once per session before it will unlock your secret key. Combined with your device's own login and disk encryption, this keeps your key safe at rest. The separate password you are asked to invent in the next step protects the backup *file*, and is a different thing from the Primary Password.
## Back Up Your Secret Key
If your computer fails, is lost, or Thunderbird's profile is wiped, an unbacked-up secret key is gone for good, and with it the ability to read every message anyone ever encrypted to you. Make a backup straight away, while everything is working.
1. Open the **OpenPGP Key Manager**: from End-To-End Encryption click **OpenPGP Key Manager**, or use the **Tools** menu.
2. Select your own key in the list.
3. From the **File** menu (or the key's right-click menu), choose **Backup Secret Key(s) To File**.
4. Thunderbird asks you to **set a password to protect the backup file**. Choose a strong, unique one. This password is what stands between anyone who finds the file and your secret key, so do not skip it and do not reuse a weak password here.
5. Save the resulting `.asc` file somewhere genuinely safe and separate from your everyday computer: an encrypted USB stick kept offline, or the secure file vault of a reputable password manager. Do not email it to yourself or leave it in a synced Downloads folder.
Store the backup file's password somewhere you will still have it in a year, ideally in your password manager. A backup you cannot unlock is no backup at all.
## Share Your Public Key
People can only send you encrypted mail once they have your public key. Sharing it is safe and encouraged; it is the public half by design. Thunderbird gives you several ways to hand it out, all from the same place.
### Attach it to your signed messages
The easiest habit is to let Thunderbird include your public key on the messages you send. When you digitally sign a message, you can attach your public key to it, so anyone you write to receives it automatically and can reply securely. This is the least-effort way to spread your key to the people who actually correspond with you.
### Export or copy it on demand
In the **OpenPGP Key Manager**, right-click your key to:
- **Send Public Keys by Email**: opens a new message with your public key attached, ready to send to a specific person.
- **Copy Public Keys to Clipboard**: pastes the key as a block of text you can drop into a chat, a website, or an email signature.
- **Export Public Keys to File**: saves a `.asc` file you can hand over however you like.
### Publish it to a keyserver
To let people who do not yet know you find your key, you can upload the public key to a public directory. The modern, privacy-respecting choice is [keys.openpgp.org](https://keys.openpgp.org/), which verifies that you control the email address (by sending you a confirmation link) before it will serve your key to others. Export your public key as above, upload it on that site, and confirm the verification email. From then on, correspondents can look you up by your address.
## Import Someone Else's Public Key
To encrypt a message *to* someone, you need their public key first. There are three common ways it reaches you.
### From an email attachment
If a contact sends you their key, it usually arrives as a small `.asc` file attached to a message. Right-click the attachment and choose the option to **import an OpenPGP key**, or use the prompt Thunderbird shows when it recognises a key. It will preview the key details and ask you to confirm the import.
### From a file you were given
In the **OpenPGP Key Manager**, open the **File** menu and choose **Import Public Key(s) From File**, then select the `.asc` or `.pgp` file.
### By searching online
Thunderbird can look a contact up on keyservers such as keys.openpgp.org and, where the recipient's mail provider supports it, via Web Key Directory. When you start writing to someone whose key you do not have, Thunderbird offers to discover it for you.
### Accept or verify the key before you trust it
This step is easy to miss and it matters. After importing a key, Thunderbird will not use it until you set its **acceptance** level. Open the key in the Key Manager and choose **Set Acceptance**:
- **Accepted (unverified)** lets you start encrypting to the person straight away. It is fine for low-stakes correspondence, but you have not actually proven the key belongs to them.
- **Verified** is the stronger option and the one to use when it matters. Compare the key's **fingerprint** with the owner through a separate channel you trust (read it out over a phone call, or check it in person). If the fingerprints match, mark the key verified. This is what defeats an impostor who tries to slip you a key that is not really theirs.
Until a recipient's key is at least accepted, Thunderbird cannot encrypt to them and will tell you so when you try.
## Troubleshooting
- **The Encrypt option is greyed out when composing**: you do not yet have an accepted public key for every recipient, or you have not selected a personal key for the sending account. Import and accept the missing recipient's key, and confirm your own key is listed under **Account Settings > End-To-End Encryption**.
- **Thunderbird keeps asking to unlock, or reports it cannot access your secret key**: this is the Primary Password doing its job. Enter it when prompted. If you have genuinely forgotten it, the stored key cannot be recovered, which is exactly why the offline backup above exists.
- **A contact says your messages are not encrypted, only signed**: signing proves who sent a message but does not hide its contents; encryption needs *their* public key on your side. Make sure you have imported and accepted it, and that Encrypt (not just Digital Signature) is switched on for that message.
- **An imported key will not let you encrypt**: its acceptance is probably still unset. Open it in the Key Manager and choose **Set Acceptance**.
- **You reinstalled Thunderbird or moved computers and your old encrypted mail is unreadable**: restore your secret key from the backup file (Key Manager > **File** > **Import Secret Key(s) From File**) and enter the backup password you set. Without that file and password, previously encrypted mail cannot be recovered.
Setting up OpenPGP keys is a one-time job that pays off every time you need a genuinely private conversation. If you would like a hand getting your Noiz account added to Thunderbird before you start, or you run into trouble along the way, open a support ticket with the Noiz support team and describe what you are trying to do. Do note that the secret key and its passwords live only on your own device by design, so keep that backup safe: not even Noiz can recover a lost OpenPGP secret key for you.
# The Best Thunderbird Settings to Configure First
Source: https://docs.noiz.ie/email/the-best-thunderbird-settings-to-configure-first/
You have just added your Noiz mailbox to Mozilla Thunderbird and mail is flowing, so this is the moment to spend ten minutes tuning the handful of settings that decide how well Thunderbird behaves for the next few years. This guide is an editor's pick: the specific options worth changing first, in the order that matters, with the reasoning behind each one so you can decide what fits the way you work rather than following a checklist blindly. It is written for a Noiz client mailbox reached over IMAP, and it explains the choices that make the difference between an inbox that stays in step across your laptop, phone and webmail, and one that quietly drifts out of sync, fills your disk, or floods you with alerts. Thunderbird's own defaults are sensible, so nothing here is mandatory; think of it as the shortlist a long-time Thunderbird user would run through on a fresh account.
**Last reviewed:** 27 July 2026, against Mozilla Thunderbird **140** (latest stable Release and ESR). This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below. Thunderbird ships a new monthly Release alongside the yearly Extended Support Release, so a label or the exact position of a checkbox may differ slightly from the version in front of you; the meaning of each setting is stable across recent versions.
### Official Documentation Reference
- [IMAP synchronisation (Thunderbird Support)](https://support.mozilla.org/en-US/kb/imap-synchronization): the authoritative reference for how Thunderbird keeps a local copy of your IMAP mailbox and what the Synchronisation & Storage options do.
- [Thunderbird and Junk / Spam Messages (Thunderbird Support)](https://support.mozilla.org/en-US/kb/thunderbird-and-junk-spam-messages): how the adaptive junk filter learns, and how the per-account Junk Settings work.
- [Compacting Folders (Thunderbird Support)](https://support.mozilla.org/en-US/kb/compacting-folders): why deleted mail keeps taking up space until a folder is compacted, and how to automate it.
- [Thunderbird and return receipts (Thunderbird Support)](https://support.mozilla.org/en-US/kb/thunderbird-and-return-receipts): how read/return receipts are requested and answered, and how to stop them being sent automatically.
- [Manual account configuration (Thunderbird Support)](https://support.mozilla.org/en-US/kb/manual-account-configuration): the reference for entering server settings by hand, which is what a custom domain usually needs.
## Prerequisites
- The mailbox already exists on Noiz hosting. If you have not created it yet, do that first in your hosting control panel: [How to Create a Mailbox in Plesk](/plesk/how-to-create-an-email-address-in-plesk/).
- The account is already added to Thunderbird over IMAP. If it is not, or you are unsure whether it was added as IMAP or POP, follow [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/) first. The settings below assume IMAP; most of them do not apply to a POP account.
- You can reach the settings screens. Most account options live under the App Menu button (the three-line **โฐ** icon at the top right) then **Account Settings**, and the program-wide options under **โฐ > Settings**. You do not need to click a Save button: Thunderbird stores each change as you make it.
## Confirm the Account Is IMAP, Not POP
Before tuning anything, confirm the account type, because it changes almost everything that follows. Open **Account Settings**, select your address in the left-hand list, and open **Server Settings**. The **Server Type** is shown at the top and cannot be changed after the fact. For a Noiz mailbox you want it to read **IMAP Mail Server**, with **Server Name** `mail.yourdomain.com`, **Port** `993`, **Connection security** SSL/TLS, and **User Name** set to your full email address such as `you@yourdomain.com`. Replace `yourdomain.com` with your own domain throughout; it is only an example. The matching outgoing server, listed separately under **Outgoing Server (SMTP)**, should be `mail.yourdomain.com` on **Port** `465` with SSL/TLS and the same full-address user name.
IMAP matters here because it is the type that keeps every device looking at the same server-held mailbox: read something on your phone and it shows as read in Thunderbird, file a message into a folder and that folder appears in webmail. POP, by contrast, tends to pull mail down onto one machine and can remove it from the server, which breaks that shared view. If Server Type reads **POP Mail Server** and you use more than one device, the cleanest fix is to remove the account and add it back as IMAP using the guide linked above, rather than trying to convert it in place.
## Synchronisation and Storage: Decide What Lives Offline
An IMAP account can either fetch each message from the server the instant you click it, or keep a local copy so mail opens instantly and remains searchable when you are offline or on a poor connection. The offline copy is the better default for a primary machine, and it is controlled under **Account Settings > Synchronisation & Storage**.
### Keep messages on this computer
Tick **Keep messages for this account on this computer**. With it on, Thunderbird downloads and indexes your mail in the background, so search covers message bodies as well as subjects, and a train tunnel or a dropped Wi-Fi connection no longer means an empty reading pane. The trade-off is disk space and the initial download, which is why the same screen lets you draw a boundary rather than hoarding everything.
### Sync only what you need
Click **Advanced** next to the folder list to choose which folders are kept offline. On a large, long-lived mailbox there is rarely a reason to hold every archive folder from years back on a laptop. A common, sensible pattern is to keep the Inbox, Sent and any folders you actually work in synchronised, and leave deep archives to be fetched on demand. Below that, **Synchronise the most recent** lets you cap the offline copy by age, for example the last 12 months, which keeps recent mail instant while older mail is pulled from the server only when opened.
### Leave the disk-space age limits alone unless you mean it
The **Disk Space** section offers to delete messages once they pass a chosen age or count. Because your mailbox is IMAP, these rules act on the server, not just the local copy, so a message removed here is gone from webmail and every other device too. This is a genuine footgun. Editor's pick: leave the automatic deletion options unticked. If you want to limit only what is downloaded rather than what is kept, the **Don't download messages larger than** option is the safe lever: it skips fetching oversized attachments to save space and bandwidth while leaving the originals untouched on the server.
## IMAP Folder Subscription: Show the Folders That Are Actually There
A Noiz mailbox can hold server-side folders that Thunderbird will not display until you subscribe to them. This is the single most common cause of the puzzle where a folder you can see in webmail, or a Sent or Junk folder your phone uses, simply does not appear in Thunderbird. Subscription is Thunderbird's way of asking which of the folders that exist on the server you want it to track.
Right-click the account name at the top of the folder pane and choose **Subscribe**. The dialog lists every folder the server holds; tick the ones you want visible and synchronised, then click **Subscribe** and **OK**. At minimum, subscribe to Inbox, Sent, Drafts, Trash and any Junk or Spam folder the server maintains, plus any folders you filed mail into elsewhere. If a folder you expect is missing from the list entirely, it does not yet exist on the server; create it and it will appear here to be subscribed. Getting subscription right is what makes the folder view in Thunderbird match webmail instead of quietly hiding mail.
## Special Folders: Point Sent, Drafts and Junk at the Server
This step is short but high-value, and it is where multi-device setups most often go wrong. By default Thunderbird can be told to keep Sent mail, Drafts and Junk in its own local folders rather than in the matching folders on the server. When that happens, a message you send from Thunderbird never shows up in the Sent folder on your phone or in webmail, because it was filed locally and never uploaded.
Open **Account Settings > Copies & Folders** and, for each of Sent, Drafts and any templates or archives, choose **Other** and select the corresponding folder *under your account on the server* rather than under Local Folders. Do the same for the Junk folder under **Junk Settings**. Once every special folder points at the server, all your devices share one consistent view of what was sent, what is still a draft, and what was marked as spam.
## Junk and Spam Controls: A Second Layer, Not the First
Most spam is filtered on the Noiz mail servers before it ever reaches your device, so Thunderbird's junk filter is a personal second layer rather than your main defence. It is worth configuring precisely because of that: tuned well it quietly learns your habits, and tuned badly it either buries good mail or does nothing.
### Enable the adaptive filter and protect your contacts
Under **Account Settings > Junk Settings**, tick **Enable adaptive junk mail controls for this account**. The word adaptive is the point: the filter learns from you. Every time you mark a message as junk, or mark a wrongly flagged one as not junk, it gets better at telling the difference for your particular mail. To stop it ever misjudging people you know, tick **Do not automatically mark mail as junk if the sender is in** and select your address book. Mail from saved contacts is then never treated as spam, which removes the most annoying kind of false positive.
### Choose what happens to junk, carefully
Decide what Thunderbird does with a message once it decides the message is junk. Moving junk to the Junk folder keeps the inbox clean, and pairing that with **Mark as read** stops the folder generating unread badges. Editor's pick: move junk to the Junk folder but review that folder for a week or two before you trust it, because the adaptive filter needs training time and you do not want a real invoice sitting unseen among the spam. Avoid any option that deletes junk automatically until you are confident the filter has settled.
Because your Noiz mailbox already carries out server-side spam scoring, there is a sensible division of labour: let the server catch the bulk, and let Thunderbird's adaptive filter mop up the personal edge cases it learns from your clicks. If you want a single shared verdict across every device, doing your junk marking against the server Junk folder (which you subscribed to above) means a message you flag on one device is filed as junk everywhere.
## Message Display: Threading On, Receipts Off
Two display choices repay the effort of setting them early because they shape every day you use the program.
### Turn on threading
Threading groups a message with its replies into a single collapsible conversation instead of scattering them down the list by arrival time. On a busy mailbox this is the difference between following a discussion at a glance and hunting for the latest reply. Turn it on from the menu bar under **View > Sort by > Threaded**, or click the small column header above the message list to switch between threaded and unthreaded. It is set per folder, so apply it to the folders where conversations pile up; a low-traffic folder is often clearer left unthreaded.
### Stop sending read receipts automatically
A return receipt (often called a read receipt) is a request from the sender to be told the moment you open their message. Left on the wrong setting, Thunderbird will silently confirm to any sender that you have read their mail, which is a small but real privacy leak and a gift to spammers probing whether an address is live. Open **โฐ > Settings > General**, find the **Return Receipts** options, and under **When I receive a request for a return receipt** choose **Never send a return receipt**, or **Ask me** if you would rather decide case by case. While you are there, leave **When sending messages, always request a return receipt** unticked so you are not demanding the same of everyone you write to. Editor's pick: never send automatically, and request one only for the rare message where confirmation genuinely matters.
## Composition Defaults: Format and Quoting
How your replies look and where your text lands are governed by a few options under **Account Settings > Composition & Addressing**, with program-wide defaults under **โฐ > Settings > Composition**.
### HTML or plain text
**Compose messages in HTML format** controls whether you can use bold, colours, links and inline images, or send unformatted text. For most business and personal mail, HTML is the reasonable default and is what recipients expect. Plain text has its place: mailing lists, developer and technical correspondence, and anyone who prefers it will thank you, because plain text is smaller, never breaks layout, and cannot hide anything. There is no universally correct answer, so pick the one that matches who you write to. A practical middle path is to leave HTML on and hold **Shift** as you click Write or Reply to compose a one-off plain-text message when the occasion calls for it.
### Quoting and where your reply starts
Keep **Automatically quote the original message when replying** ticked so the thread's context travels with your answer. The setting just below it, **then, start my reply**, decides whether your new text appears **above the quote** (top posting, which most people and most email culture now expect) or **below the quote** (bottom posting, still preferred on some mailing lists). Editor's pick: start above the quote for everyday mail, and switch to below if a particular list or workplace convention calls for it. Setting this once means every reply is laid out the way your correspondents expect without you rearranging text by hand.
## Disk Space and Compacting: Reclaim the Space Deleted Mail Leaves Behind
Deleting a message in an IMAP folder does not immediately free the space it occupied. Thunderbird marks the message hidden and only truly removes it when the folder is compacted, so a heavily used mailbox can accumulate a surprising amount of dead weight, and a folder that is never compacted can grow large and slow. Compacting is the housekeeping that clears it out.
Open **โฐ > Settings > General** and find the **Disk Space** section. Leave **Compact folders when it will save over [N] MB in total** ticked so Thunderbird tidies up on its own; a threshold in the region of 20 MB is a fine starting point. If constant prompts annoy you, you can turn off the confirmation so compacting happens quietly. The two related options, **Clean up ("Expunge") Inbox on Exit** and **Empty Trash on Exit**, permanently clear out deleted and trashed mail when you close Thunderbird; enable them if you like a clean slate, but understand they discard that mail for good rather than leaving it recoverable. You can always compact by hand at any time by right-clicking a folder and choosing **Compact**.
## Notifications: Enough to Notice, Not Enough to Interrupt
Fresh out of the box Thunderbird can pop an alert, play a sound and light up its icon for every single message, which becomes noise the moment your mailbox is busy. Tuning notifications early is what keeps email a tool you check rather than a stream that checks you. Open **โฐ > Settings > General** and find the incoming-mail notification options. Editor's pick: keep a single quiet signal, such as the on-screen alert or the tray icon, and turn the notification sound off so a run of newsletters at 6am does not wake the house. If your work depends on catching certain mail instantly, a more precise approach is to leave general alerts off and use a message filter to notify you only for senders that matter, which keeps the interruption for the messages that earn it.
## Troubleshooting
- **Symptom**: a folder shows in webmail or on your phone but not in Thunderbird. It is not subscribed. Right-click the account, choose **Subscribe**, tick the missing folder and click OK.
- **Symptom**: messages you send from Thunderbird never appear in Sent on your other devices. The Sent folder is pointing at Local Folders. Under **Copies & Folders**, set Sent to the server folder under your account, and do the same for Drafts and Junk.
- **Symptom**: your mailbox size on the server keeps climbing even after you delete mail. Deleted messages are still hidden in the folders awaiting compaction. Right-click a folder and choose **Compact**, and confirm automatic compacting is enabled under Settings > General > Disk Space.
- **Symptom**: legitimate mail keeps landing in Junk. The adaptive filter needs training and a contacts exception. Mark each wrongly flagged message as **Not Junk**, and under Junk Settings tick the option not to mark mail as junk from senders in your address book.
- **Symptom**: mail is slow to open, or you see nothing when offline. Offline storage is off. Under **Synchronisation & Storage**, tick **Keep messages for this account on this computer**, then let the initial download finish.
- **Symptom**: Thunderbird's automatic setup filled in the wrong servers, or could not find any. Autoconfig often cannot discover the settings for a custom domain, so enter them by hand: incoming IMAP `mail.yourdomain.com` port `993` SSL/TLS, outgoing SMTP `mail.yourdomain.com` port `465` SSL/TLS, user name the full email address, normal password. The full walkthrough is in [How to Add an Email Account in Mozilla Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/).
Work through these once and Thunderbird settles into a mailbox that stays in step with your other devices, keeps recent mail instant and searchable, throws away only what you tell it to, and interrupts you only when it should. If a setting behaves differently on your version, or your Noiz mail is not connecting the way it should, open a support ticket with the Noiz support team and include your domain, your Thunderbird version, and whether the account is IMAP or POP, and the team will help you get it right.
# Why Is My Email Not Working? An Email Troubleshooting Guide
Source: https://docs.noiz.ie/email/why-is-my-email-not-working-an-email-troubleshooting-guide/
When your email stops working, the fastest way back to a working inbox is not to change settings at random but to narrow the problem down until only one cause is left. This guide is that method: a plain-language decision tree for the email faults people hit most often on a Noiz mailbox, whether you send and receive through a desktop program such as Outlook or Thunderbird, a phone, or Noiz webmail. It is written for anyone with a mailbox on a Noiz hosting plan (a mailbox is also called an email account), and it is the hub that the more specific Noiz email guides branch off from.
Work through it in order. Start with the settings reference and the single sign-in test in the next two sections, because that test alone tells you whether the fault is on your device or with the mailbox itself, and that answer decides everything that follows. Then jump to the section that matches your symptom: cannot send, cannot receive, password rejected, connection timing out, mail going to spam, mailbox full, or it worked yesterday and not today.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable) and the Roundcube webmail it ships. This guide is written for Noiz hosting and is kept current against Plesk. It complements, and does not replace, the official Plesk documentation linked below. Panel labels and app screens shift slightly between updates, so where a screen differs from the wording here, the setting names, ports and values still apply.
### Official Documentation Reference
- [Plesk Obsidian Customer's Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/): the official reference for managing your mailbox, forwarding, autoresponders and spam filtering from the Plesk panel that Noiz runs.
- [Outlook help and learning (Microsoft)](https://support.microsoft.com/en-us/outlook): Microsoft's own troubleshooting for the Outlook desktop and mobile apps, useful for app-side faults this guide traces to your client.
- [RFC 8314: TLS for Email Submission and Access](https://www.rfc-editor.org/rfc/rfc8314): the internet standard behind the encrypted ports Noiz uses (465 for sending, 993 for IMAP, 995 for POP), and why the old unencrypted ports are obsolete.
## Prerequisites
- A mailbox that already exists on your Noiz plan. If you have not created it yet, do that first: see [How to create an email address in Plesk](/plesk/how-to-create-an-email-address-in-plesk/). Nothing below can connect to a mailbox that has not been set up.
- The full email address and its current password. The username for Noiz mail is always the whole address, for example `you@yourdomain.com`, never just the part before the `@`.
- Access to whichever app or device is failing, so you can check its settings, and if possible a second way in (webmail, or a phone on mobile data) to compare against.
## Know Your Noiz Mail Settings
Almost every email fault comes down to one of these values being wrong somewhere. Keep this table in front of you while you troubleshoot. Wherever you see `yourdomain.com`, replace it with your own domain: it is an example placeholder, not a real server.
| Setting | Incoming (IMAP, recommended) | Outgoing (SMTP) |
| --- | --- | --- |
| Server hostname | `mail.yourdomain.com` | `mail.yourdomain.com` |
| Port | `993` | `465` |
| Connection security | SSL/TLS | SSL/TLS |
| Authentication | Normal password | Normal password (required) |
| Username | Full email address, e.g. `you@yourdomain.com` | Full email address, e.g. `you@yourdomain.com` |
If you use POP instead of IMAP, the only change is the incoming port: `995` with SSL/TLS on the same hostname. The outgoing settings never change. Two rules catch most people out:
- The username is the **whole address**. A username of just `you` will fail to authenticate every time.
- Noiz mail is encrypted throughout. Use the SSL/TLS ports (993, 465, 995) only. The old cleartext ports (143, 110, 25, and 587 without TLS) are not used, and pointing an app at them is a common reason sending or receiving silently fails.
## Start Here: The One Test That Halves the Problem
Before changing a single setting, sign in to Noiz webmail. Noiz webmail talks to your mailbox directly on the server, using none of your device's app settings or your local network's mail path, so it is the cleanest possible test of whether the mailbox itself is healthy. See [How to access email from Plesk webmail](/plesk/how-to-access-email-from-plesk-webmail/) for the sign-in address, then read the result:
- **Webmail signs in and mail sends and receives normally.** Your mailbox, password and the Noiz mail server are all fine. The fault is on the device or app you were using, or on the network it was connected to. Head to the symptom section below and focus on that device's settings, not the mailbox.
- **Webmail rejects your password, or you cannot get in at all.** The fault is with the account or the server, and no amount of changing settings inside Outlook or your phone will fix it. The likely causes are a wrong or changed password, a full mailbox, or a suspended service. Go straight to the password, mailbox-full, or suddenly-stopped sections.
This one test tells you which half of the problem to work on, and it stops the most common mistake in email troubleshooting: rebuilding an app account over and over when the real issue is on the server, or resetting a healthy password when the real issue is one app setting.

## You Cannot Send Mail (but Receiving Works)
When mail arrives but will not leave, the problem is nearly always the outgoing (SMTP) side. Check these in order.
- **Outgoing port and security.** The SMTP server must be `mail.yourdomain.com` on port `465` with SSL/TLS. An app set to port 587, 25, or "no encryption" is the single most common cause. Correct it to 465 and SSL/TLS.
- **Outgoing authentication is switched off.** Many apps have a separate tick box such as "My outgoing server requires authentication" or "Use username and password". Noiz requires it. If it is off, or set to "same as incoming" but the incoming login itself is wrong, sending is refused. Turn authentication on and enter your full email address and password.
- **The username is not the full address.** The outgoing username must also be `you@yourdomain.com` in full. Apps often leave the outgoing username blank or shortened even when incoming works.
- **Your network is blocking the mail port.** Some office, school, hotel and public Wi-Fi networks, and a few home routers, block outbound mail ports to curb spam. The tell-tale sign is that sending fails only on one network. Test by sending from the same app over mobile data or a different connection; if it works there, the block is the network, not your mailbox.
- **Security software in the way.** A local antivirus or firewall that scans email, or a VPN, can intercept the outgoing connection. Temporarily disable email scanning or the VPN to test, then re-enable it and add an exception if that was the cause.
If you are unsure your app is configured correctly, re-check it against the Noiz settings using the guide for your program: [Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/) or [iPhone and iPad](/email/how-to-set-up-email-on-iphone-or-ipad/). Microsoft's [Outlook help](https://support.microsoft.com/en-us/outlook) covers the equivalent screens in Outlook.
## You Cannot Receive Mail (but Sending Works)
If you can send but nothing new arrives, work down this list before assuming mail is lost.
- **Check the Junk or Spam folder first.** Filtered mail is not missing mail. Look in Junk both in your app and in webmail, since a message flagged on the server may never reach your app's inbox.
- **Confirm the incoming settings.** Incoming should be `mail.yourdomain.com`, port `993` (IMAP) or `995` (POP), SSL/TLS, full-address username. A POP account set to "remove from server after download" on one device will pull mail down so your other devices and webmail never see it.
- **Is the mailbox full?** A mailbox at its size limit stops accepting new mail and the sender gets a quota bounce. See the mailbox-full section below.
- **A filter or forwarder is diverting mail.** A rule set up earlier, or a forwarding address, can move or redirect incoming messages before you see them. Review any mail rules and forwarders on the mailbox.
- **Ask the sender to check for a bounce.** If one specific person's mail never arrives, ask them whether they received an automated failure notice. The wording of that bounce (unknown user, mailbox full, message rejected) names the exact cause and is worth quoting to Noiz support.
- **Recently moved the domain to Noiz?** If your domain's mail was only just pointed to Noiz, allow DNS time to take effect. Until it does, incoming mail can still be delivered to the old host.
## Your Password Is Rejected, or You Are Asked for It Again and Again
A password that keeps being refused, or a login box that reappears every few minutes, usually means one of the following.
- **The username is not the full email address.** This causes more "wrong password" errors than an actually wrong password. Set the username to `you@yourdomain.com` in full, for both incoming and outgoing.
- **The password really is wrong, or was changed.** Confirm it by signing in to webmail (the test above). If webmail also refuses it, the password is the problem: reset it in the Plesk panel where the mailbox lives, after you [log in to Plesk](/plesk/how-to-log-in-to-plesk/), then update every device with the new password. A single device still holding the old password can trigger repeated prompts and, on some servers, temporary lockouts that affect your other devices too.
- **An older app is negotiating an outdated login method.** Some long-standing desktop clients try an obsolete authentication mechanism and fail even with the correct password. In the account's security settings, set the authentication method to normal or plain password over SSL/TLS (not "encrypted password", "secure password authentication" or a challenge-response option). The encryption comes from the SSL/TLS connection, so a plain-password login is both correct and safe here.
- **A typo you cannot see.** A trailing space, a swapped character, or Caps Lock will all read as a wrong password. Re-type it rather than relying on a saved value, and re-tick "remember password" once it works.
## The Connection Times Out or the Server Cannot Be Found
If your app hangs, reports a timeout, or says it cannot find the server, the issue is reaching the mail server rather than logging in to it.
- **The hostname is misspelled.** It must be exactly `mail.yourdomain.com` with your own domain, no extra spaces. A "server not found" error often traces to a single wrong character.
- **Your network is blocking the mail ports.** As with sending, some networks block the mail ports outright, which shows as a timeout on both incoming and outgoing. Test the same account over mobile data or another connection; success there points at the original network.
- **DNS has not caught up.** If the domain recently moved to Noiz, `mail.yourdomain.com` may not yet resolve everywhere. This clears as DNS takes effect. Webmail is a useful check in the meantime, as it does not depend on your device resolving the mail hostname.
- **A VPN, proxy or security suite is intercepting the connection.** Turn these off briefly to test. If the connection then succeeds, add an exception for your mail app rather than leaving the protection off.
## Your Mail Is Landing in Spam
There are two very different versions of this, and the fix depends on the direction.
- **Mail you send is landing in other people's spam or junk.** This is a deliverability matter, decided by your domain's sending reputation and its authentication records (SPF, DKIM and DMARC), not by any setting in your app. Ask a recipient to mark one of your messages as "not spam" and to add your address to their contacts, which helps immediately. For the underlying records, deliverability is configured at the domain level on Noiz hosting; if outgoing mail is consistently filtered, raise it with Noiz support so the domain's authentication can be reviewed.
- **Legitimate mail you receive is going to your own Junk folder.** Mark the message as "not spam" and add the sender to your contacts or safe list. Doing this in webmail as well as in your app teaches the filter on the server, not just on one device.
- **You are receiving a flood of spam, or your address seems to be sending spam.** That is a different problem with its own guide. See [How to determine the source of spam and reduce it](/email/how-to-determine-the-source-of-spam-and-reduce-it/), which covers finding where unwanted mail is coming from and cutting it down.
## Your Mailbox Is Full
Every mailbox has a size limit. When it is reached, new mail stops arriving, senders receive a "mailbox full" or "over quota" bounce, and some apps also refuse to send because they cannot save a copy to the Sent folder. The mailbox is not broken; it simply has no room.
To free space, sign in to [Noiz webmail](/plesk/how-to-access-email-from-plesk-webmail/) or your IMAP app and:
- Delete large, old messages, sorting by size to find the biggest first. Messages with attachments are usually the heaviest.
- Empty the Trash or Deleted folder and the Junk folder afterwards. On most setups, mail sitting in Trash still counts towards the limit until it is purged.
- Remember to clear the Sent folder too; years of sent attachments add up.
You can see how much space a mailbox is using, and its limit, in the mail settings for that address after you [log in to Plesk](/plesk/how-to-log-in-to-plesk/). If you genuinely need more room than the current limit allows, contact Noiz support to have the mailbox quota raised on your plan.

## It Was Working, Then Suddenly Stopped
When email worked fine and then stopped without you touching it, something changed. Finding the change is faster than checking every setting, so ask what is new since it last worked.
- **A password was changed on one device but not the others.** If you or a colleague reset the mailbox password, every device needs the new one. The devices still holding the old password will fail and can cause repeated prompts across all of them. Update them all, or see the password section above.
- **Mail security was tightened.** When a mail platform moves to encryption-only connections, older apps still set to a cleartext port or an outdated login method stop working overnight, even though nothing looked wrong before. The fix is to bring the app in line with the Noiz settings: SSL/TLS on ports 993 and 465, normal password, and the full email address as the username.
- **The domain or its DNS changed.** Moving nameservers, changing MX records, or transferring the domain can interrupt mail until the change takes effect. If the domain was recently touched, that is the first thing to reconcile.
- **An app updated itself.** A phone or desktop update can reset an account's ports or security back to a default that does not match Noiz. Re-check the settings against the table above.
- **The mailbox filled up.** Mail that "just stopped arriving" is often a mailbox that quietly reached its limit. Check the mailbox-full section.
Once you have identified the change, the fix is usually to undo it or to reconcile the app to the current Noiz settings. Re-running your client's setup guide ([Thunderbird](/email/how-to-add-an-email-account-in-mozilla-thunderbird/), [iPhone and iPad](/email/how-to-set-up-email-on-iphone-or-ipad/)) from scratch is often quicker than hunting for the one changed field.
## When to Contact Noiz Support
If you have run the webmail test and worked through the matching section and email still will not behave, open a support ticket. The team can resolve it far faster when the ticket includes:
- The full email address affected.
- Whether the problem is sending, receiving, or both.
- Whether Noiz webmail works for that mailbox (the single most useful thing to state, from the test above).
- The app and device, for example Outlook on Windows 11, or Mail on an iPhone.
- The exact error message, copied word for word or as a screenshot.
- When it last worked and what changed around then, if anything.
- Whether it fails on every network or only one.
On Noiz managed plans the support team can check the mailbox, its quota and the mail server from the inside and tell you the precise value to correct, which is usually the quickest route once the on-device checks above are done.
# Why Outlook Mailboxes Over 50 GB May Cause Corruption Issues
Source: https://docs.noiz.ie/email/why-outlook-mailboxes-over-50-gb-may-cause-corruption-issues/
Very large Microsoft Outlook mailboxes can cause slow performance, sync failures and even data-file corruption. This is not a fault of your email host. It is a limitation of the Outlook desktop client itself, and it follows the mailbox wherever it lives. Move the same account between shared hosting, a dedicated server or a cloud mail service and the problem returns if the mailbox stays excessively large. This guide explains why the 50 GB threshold matters, what happens beyond it, and how to keep your Outlook data files healthy on Noiz hosting.
**Last reviewed:** 27 July 2026, against current Microsoft Outlook desktop (Microsoft 365 Apps, and Outlook 2021, 2019 and 2016). This guide is written for Noiz hosting and explains a behaviour of the Outlook client. It complements, and does not replace, the official Microsoft documentation linked below.
### Official Documentation Reference
- [Turn on Cached Exchange Mode](https://support.microsoft.com/en-us/office/turn-on-cached-exchange-mode-7885af08-9a60-4ec3-850a-e221c1ed0c1c) (Microsoft Support): controls how much mail Outlook keeps in the local cache.
- [Outlook help & learning](https://support.microsoft.com/en-us/outlook) (Microsoft Support): general reference for data files, archiving and account setup.
## Understanding Outlook data files
Outlook keeps a local copy of your mailbox in a data file on your computer, either an **OST** (offline cache, used by IMAP and cached accounts) or a **PST** (personal storage). Modern Outlook applies a default configured limit of **50 GB** per file. That limit is a Microsoft policy value rather than a hard technical ceiling, and it can be raised through the registry. Raising it lets the file grow larger, but it does not make Outlook stable at that size.
In practice, stability drops well before the file reaches 50 GB. Once a mailbox grows beyond roughly **20 to 30 GB**, most users start to see problems. At 70 GB or more they become routine:
- Slow performance, freezing and long start-up times in Outlook
- Sync errors, duplicated items or missing mail
- Corrupted OST or PST files that require a rebuild
- Very long repair times, or a full re-download of the mailbox from the server
The larger the single data file, the longer every operation on it takes and the greater the chance that an interrupted write, an antivirus lock or a full disk leaves the file in a damaged state.
## Why this is a client software issue, not a hosting issue
The corruption happens inside the Outlook data file on your computer, not on the mail server. Whether your mailbox is hosted on shared hosting, a dedicated server or a cloud service such as Microsoft 365, Outlook still has to hold and index the whole cache locally, and a single oversized file is where the fragility lives.
Noiz mailboxes are standard IMAP and POP accounts, not Microsoft Exchange or Microsoft 365. That has a reassuring consequence: the OST that Outlook builds is only a local cache of what is already on the server. If that local file corrupts, you rebuild it and re-sync; the authoritative copy on the Noiz mail server is stored as individual message files and is unaffected by damage to your local Outlook cache. The risk you are managing here is on the Outlook side, so the fixes below are almost all things you do in Outlook or in your day-to-day mail housekeeping.
## Options to reduce problems
- **Limit the cached data.** Set Outlook to keep only the last 12 to 24 months of mail offline instead of the entire mailbox. In an account using Cached Exchange Mode this is the "Mail to keep offline" slider; on an IMAP account, remove very old folders from the sync set. This is the single most effective change for most people.
- **Archive older mail.** Move old messages into an Archive mailbox or a dated archive folder so they leave your active data file. Archiving on the server side keeps the active mailbox lean without deleting anything.
- **Use online (non-cached) mode where suitable.** Outlook can connect without building a full local file, which removes the corruption risk entirely, but every action then depends on a fast, stable internet connection. This suits office environments more than mobile users.
- **Export to local archive files.** Export older messages to separate PST archive files kept outside your active profile, so the working mailbox stays small. Store those archives somewhere backed up, because a local-only PST is not on the server.
## Alternative email clients
Other mail clients handle large mailboxes differently. Mozilla Thunderbird, for example, can store each folder with the Maildir option, keeping every message as a separate file. That structure means one damaged message cannot take down the whole mailbox the way a single corrupted OST or PST can. No desktop client performs perfectly with an enormous mailbox, but Thunderbird generally copes better than Outlook once you are past 50 GB. Webmail is another option for occasional access to old archives, since it reads mail straight from the server and keeps nothing large on your device.
## Best practice recommendations
- Keep your active Outlook mailbox under 20 to 30 GB for reliable performance.
- Archive older messages routinely instead of letting the Inbox and Sent Items grow without limit.
- Do not rely on raising the 50 GB registry limit as a fix; it postpones the symptoms rather than removing them.
- Use webmail or an alternative client for long-term archive access.
- Make sure any local-only archive files are covered by a backup.
Managing mailbox size is essential to a fast, reliable email experience. If your mailbox is already over 50 GB, archive and trim it now, before corruption forces an emergency rebuild. If you would like a hand, the Noiz support team can advise on server-side archiving and mailbox housekeeping for your account.
# Why Some Email Apps Stop Working After a Mail Security Upgrade
Source: https://docs.noiz.ie/email/why-some-email-apps-stop-working-after-a-mail-security-upgrade/
From time to time you may notice that an email program which previously worked suddenly starts reporting connection errors or refusing to log in. This is frustrating, but it is rarely a server fault. In most cases the problem is outdated or unsupported software on your device that can no longer meet modern security requirements. This guide explains what changed, why some older apps stop connecting, and exactly what you need to do to get email working again.
**Last reviewed:** 27 July 2026. This guide reflects the current Noiz mail security requirements (encrypted connections using TLS 1.2 or higher, authenticated submission only) and is kept current as email clients and operating systems reach end of support. It complements, and does not replace, the vendor documentation linked below.
### Official Documentation Reference
- [Microsoft: Windows 10 end of support](https://www.microsoft.com/en-za/windows/end-of-support)
- [Microsoft Lifecycle: Outlook 2016 support dates](https://learn.microsoft.com/en-us/lifecycle/products/outlook-2016)
- [Mozilla Thunderbird: system requirements](https://www.thunderbird.net/en-US/thunderbird/system-requirements/)
## What changed on the server side
Noiz has tightened mail security controls to keep the platform aligned with PCI DSS and South Africa's POPIA requirements. In particular:
- Plain-text authentication and unauthenticated relaying over port 25 have been disabled. Port 25 is now used only for server-to-server delivery, not for sending mail from your own apps.
- Only encrypted connections are accepted for IMAP, POP3 and SMTP, and the connection must negotiate **TLS 1.2 or higher**. The older TLS 1.0 and 1.1 protocols, and the long-obsolete SSL protocols, are refused.
- Mail services are aligned with current [secure mail authentication practice and regulatory compliance](https://www.noiz.co.za/announcements/9/Important-change-Secure-mail-authentication.html).
These changes keep your mailboxes secure and compliant. The side effect is that older software which only speaks insecure protocols can no longer connect. This is deliberate, and re-enabling the old protocols is not an option.
## Why older email apps stop working
An email client has to support modern encryption to connect to a secure server. Apps and operating systems that no longer receive updates are stuck with outdated cryptography, so they fail the moment the server insists on TLS 1.2 or higher. Common culprits:
- **Windows 10:** Microsoft ended mainstream support for [Windows 10 on 14 October 2025](https://www.microsoft.com/en-za/windows/end-of-support). It no longer receives free security updates, and its built-in mail components will fall further behind modern security standards over time. Windows 7 and 8.1 are even further out of date and will not connect at all.
- **Outlook 2013 and 2016:** These editions were released long before today's security expectations and are no longer fully supported. They frequently fail to negotiate TLS 1.2 correctly, which shows up as repeated password prompts or a flat connection failure even when the password is correct.
- **Old phones and tablets:** The stock mail app on an ageing Android or iOS device can hit the same wall. If a phone can no longer install operating-system updates, its mail app may not support the required encryption.
- **Thunderbird as a reliable alternative:** On a supported operating system, [Mozilla Thunderbird](https://www.thunderbird.net/en-US/thunderbird/system-requirements/) is a strong choice. It is free, open source, actively maintained, and fully supports modern security protocols.
## How to confirm the server is not at fault
Before spending time troubleshooting a device, it helps to know the server side is healthy. The Noiz mail servers are kept up to date and compliant:
- All mail traffic must use TLS 1.2 or higher; no insecure plain-text logins are permitted.
- Certificates are issued by Let's Encrypt and pass standard verification checks.
- Current, well-maintained clients connect to the same mailbox without any special configuration.
The practical test is simple: if a modern client (for example Thunderbird on an up-to-date computer, or the mail app on a current phone) can log in to the same account, the mailbox and server are fine and the fault is the older software.
## The correct secure settings to use
When you set up or repair an account, use encrypted settings throughout. These are the standard secure values for Noiz mailboxes:
- **Incoming, IMAP:** port `993`, connection security **SSL/TLS**.
- **Incoming, POP3:** port `995`, connection security **SSL/TLS**.
- **Outgoing, SMTP:** port `465` with **SSL/TLS**, or port `587` with **STARTTLS**. Do not use port 25 for sending from your app.
- **Authentication:** required for outgoing mail, using your full email address as the username and your normal password. The password travels inside the encrypted connection, so "normal password" is the correct setting to choose.
Replace the incoming and outgoing server names with the mail host shown in your Noiz control panel for the mailbox (this is usually `mail.yourdomain.com`, where `yourdomain.com` is your own domain).
## What you need to do
To keep using your email securely:
- Make sure your operating system is still supported and fully updated: Windows 11, macOS with current updates, or a maintained Linux distribution. If you are still on Windows 10 or older, plan an upgrade.
- Upgrade your email client to a supported version. Thunderbird is recommended where you are free to choose.
- If you use Outlook, run a currently supported edition (Microsoft 365, or Outlook 2021 or later) and install its updates.
- Remove and re-add the account using the encrypted settings above if it still fails after updating. A stale profile can hold on to old, insecure settings.
## Troubleshooting
- **Symptom: repeated password prompts even though the password is correct.** The client is failing the TLS negotiation, not the login. Confirm the ports and connection security match the secure settings above, and update or replace the client.
- **Symptom: "cannot connect to the server" or "the connection to the server failed".** Usually an outdated client that cannot negotiate TLS 1.2. Test the same account in a modern client to confirm, then update the failing software.
- **Symptom: mail receives but will not send.** The outgoing server is still set to port 25 or has no authentication. Switch to port 465 (SSL/TLS) or 587 (STARTTLS) with authentication enabled.
- **Symptom: an Outlook error such as 0x800CCC1A referencing SSL.** The Outlook edition cannot complete a modern secure handshake. Update Outlook or move to a supported client.
## Summary
Security cannot be relaxed by re-enabling outdated protocols; these controls protect both your data and the Noiz infrastructure. If an email app has stopped working after the mail security upgrade, it is almost always because that app or the device it runs on no longer meets today's encryption requirements. The fix is to update the software, correct the account to encrypted settings, or move to a supported client such as Thunderbird.
If you have updated your software and applied the secure settings above and email still will not connect, the Noiz support team can check the account and confirm the server side from their end. Open a ticket from your client area with the exact error message, the app and version you are using, and the operating system on the device.
# Why and How to Switch to Thunderbird
Source: https://docs.noiz.ie/email/why-and-how-to-switch-to-thunderbird/
Mozilla Thunderbird is a free, open-source email client known for reliability, privacy, and strong performance with large IMAP mailboxes. This guide explains why many people (especially anyone carrying a very large mailbox) switch to Thunderbird, how it compares with other popular clients, and gives you modular migration paths so you can either set up a clean IMAP account or import existing mailbox data safely. It works with your Noiz mailbox over standard IMAP and SMTP, so nothing about your Noiz hosting has to change.
**Last reviewed:** 27 July 2026, against Thunderbird **140 ESR** (Extended Support Release; the monthly channel is on version 153 at time of writing). This guide is written for Noiz hosting and is kept current against Thunderbird. It complements, and does not replace, the official Thunderbird documentation linked below.
### Official Documentation Reference
- [Thunderbird Help (support.mozilla.org)](https://support.mozilla.org/en-US/products/thunderbird): the authoritative support knowledge base.
- [Manual account configuration](https://support.mozilla.org/en-US/kb/manual-account-configuration): for when auto-detect does not fill in your server settings.
- [OpenPGP in Thunderbird: how-to and FAQ](https://support.mozilla.org/en-US/kb/openpgp-thunderbird-howto-and-faq): the definitive guide to built-in encryption.
- [ImportExportTools NG add-on](https://addons.thunderbird.net/en-US/thunderbird/addon/importexporttools-ng/): the standard tool for importing and exporting MBOX and EML.
## Prerequisites
- Your full email address and mailbox password (from your Noiz welcome email or your hosting control panel).
- A desktop running Windows, macOS, or Linux with permission to install software.
- If you are migrating, a copy of your existing data (PST, MBOX, or EML files) and, ideally, a backup before you start.
## Why Choose Thunderbird
- **Open source and free:** no licensing costs, and it is actively maintained by MZLA Technologies and a global community.
- **Cross-platform:** the same interface and features on Windows, macOS, and Linux, so switching machines does not mean relearning your email client.
- **Large mailbox resilience:** an optional "file per message" (Maildir) storage mode reduces the risk of one giant mailbox file becoming corrupted, which is exactly the failure mode that bites heavy mail users.
- **Built-in PGP encryption:** native OpenPGP support lets you create or import keys and send and receive encrypted and signed email without any third-party add-on.
- **Customisable:** a wide range of add-ons and interface tweaks to match how you actually work.
- **Vendor-neutral:** it speaks standards-based IMAP and SMTP, so it works with your Noiz mailbox and any other standards-compliant mail server.
## Client Comparison: Thunderbird vs Other Popular Email Apps
All comparisons below reflect the current stable releases of each client at time of review. Feature sets move quickly, so treat the table as a snapshot rather than a permanent ruling.
| Capability | Thunderbird | Outlook (Microsoft 365/Desktop) | Apple Mail (macOS) | eM Client (Win/macOS) | Mailbird (Windows) | Mailspring (Win/macOS/Linux) |
| --- | --- | --- | --- | --- | --- | --- |
| **Cost** | Free | Paid (licence or Microsoft 365) | Included with macOS | Free for personal use; paid Pro | Paid | Free tier + paid |
| **Platforms** | Win / macOS / Linux | Win / macOS | macOS only | Win / macOS | Windows only | Win / macOS / Linux |
| **Mailbox size handling** | Maildir (file per message) optional; robust with large IMAP stores | Single OST/PST files; can become unstable above roughly 20 GB to 30 GB of local cache | File-per-message (.emlx) store; generally fine, can grow large | Database-backed store; good performance | Database-backed store; good performance | Database-backed store; good performance |
| **Built-in PGP** | Yes (OpenPGP) | No (requires add-ons or enterprise features) | No (use GPGMail or plugins) | Yes (built-in PGP) | No (rely on external tools) | No (rely on external tools) |
| **Exchange/EWS first-class** | Native Exchange (EWS) email support added in recent versions (140 ESR); still maturing, calendar and contacts limited | Yes (native) | Limited (best with iCloud/Gmail/IMAP) | Yes (EWS support) | No | No |
| **Customisation & add-ons** | Extensive | Limited | Limited | Moderate | Moderate | Moderate |
| **Privacy posture** | Open source, vendor-neutral | Microsoft ecosystem integration/telemetry | Apple ecosystem integration | Proprietary | Proprietary | Proprietary (open-core) |
**Note on Exchange:** Thunderbird's native Exchange support is a genuine step forward, but at 140 ESR it focuses on email. If you depend on Exchange calendars, shared contacts, or shared mailboxes, test carefully before you commit, or keep a second client for those specific features.
## Choose Your Path: Clean IMAP Setup vs Migration
Pick one of the options below based on your goals and current client.
### Option A: Clean IMAP Setup (Fastest, Least Risk)
This is the right choice for most people. Because IMAP keeps your mail on the Noiz server, a fresh Thunderbird install simply syncs everything down. Nothing is at risk of being lost locally.
1. **Install Thunderbird:** download the latest version for your operating system from the official Thunderbird website.
2. **Add your account:** enter your name, full email address, and password. Thunderbird will try to auto-detect your IMAP and SMTP settings. Choose SSL/TLS where offered.
- If auto-detect does not find your Noiz settings, click **Configure manually** and enter them by hand. The usual pattern is incoming **IMAP** on port `993` with SSL/TLS, outgoing **SMTP** on port `465` (SSL/TLS) or `587` (STARTTLS), with your **username set to your full email address**. Use the exact hostname shown in your Noiz welcome email or control panel (commonly `mail.yourdomain.com`, which you replace with your own domain).
3. **(Optional) enable Maildir for large mailboxes:**
- If the option is visible under account or server settings, choose **File per message (Maildir)**.
- If it is not visible, open **Settings โ General โ Config Editor**, search for `store`, and set the default message store to Maildir for new accounts, then create the account. Maildir support in Thunderbird is still considered experimental, so use it deliberately rather than as a default.
4. **Let it sync:** Thunderbird downloads headers first, then message bodies as you read them. For very large accounts, leave the app open so the initial sync can finish.
5. **Organise:** create yearly archive folders (for example **Archive/2024**, **Archive/2025**) and move old mail out of Inbox and Sent to keep your active folders lean.
### Option B: Migrate Existing Data into Thunderbird (Modular)
Use the sub-option that matches your current client and data format. You can combine methods, for example importing old archives while also adding a live IMAP account for current mail.
#### B1. Outlook Data (PST) to Thunderbird
- **Recommended (no third-party tools):** add the same mailbox as IMAP in both Outlook and Thunderbird. In Outlook, drag folders from the local PST into the IMAP account so they upload to the server, and Thunderbird will sync them down. This keeps server-side copies but depends on your mailbox quota and bandwidth.
- **Direct PST conversion:** convert the PST to MBOX using a converter (for example `readpst` on Linux, or a reputable commercial tool), then import the resulting MBOX files (see B4).
#### B2. Apple Mail (MBOX) to Thunderbird
1. In Apple Mail, use **Mailbox โ Export Mailbox** to produce one MBOX file per folder.
2. In Thunderbird, import those MBOX files (see B4).
#### B3. EML Files to Thunderbird
- Create or open a target folder in Thunderbird, then drag and drop the EML files from Finder or File Explorer straight into that folder. For large batches, use the ImportExportTools NG add-on instead.
#### B4. Importing MBOX into Thunderbird
Thunderbird's built-in importer handles profiles, address books, and settings from other apps, but it does not import arbitrary MBOX files on its own. For MBOX, install the free **ImportExportTools NG** add-on, which is the standard tool for this job.
1. Install **ImportExportTools NG** from the Thunderbird add-ons site (linked above).
2. Right-click the destination folder (or **Local Folders**) and choose **ImportExportTools NG โ Import mbox file**.
3. Select the exported MBOX file (or a whole directory of them) and confirm.
4. Verify the messages appear in the chosen folder. You can then move or copy them into your IMAP account if you want them on the server.
#### B5. Contacts and Calendars
- **Contacts:** export as vCard (.vcf) or CSV from your old client. In Thunderbird, open the **Address Book**, then use its menu to **Import** the file.
- **Calendars:** export .ics files from your old client. In Thunderbird, use **Events and Tasks โ Import** to bring them in, or connect directly to a CalDAV or Google calendar for live sync.
## Set Up PGP Encryption in Thunderbird
Thunderbird's OpenPGP support is built in, so there is nothing extra to install for end-to-end encryption.
1. Open **Account Settings โ End-To-End Encryption**.
2. Choose **Add Key**, then either **Create a new key** (recommended if you do not already have one) or **Import an existing key** (if you already use PGP).
3. Share your public key with contacts, for example by attaching it to a message or publishing it where appropriate. Keep your private key secure and backed up, because losing it means losing access to your encrypted mail.
4. When composing, use the **Encryption** options to **Encrypt** and/or **Digitally Sign** the message as needed.
## Performance and Reliability Tips
- **Keep active folders lean:** move older mail into yearly archives. Very large single folders (Inbox and Sent especially) slow down every email client, not just Thunderbird.
- **Use IMAP server-side folders:** this keeps your mail consistent across every device and makes server-side backups straightforward.
- **Consider Maildir for huge mailboxes:** file-per-message storage reduces the chance that a single corrupted file takes out a whole folder.
- **Back up your profile:** periodically back up the Thunderbird profile folder, especially before large imports or restructuring.
## Troubleshooting Common Migration Issues
- **Quota errors during IMAP copy:** clear space or ask Noiz support about your mailbox quota, and upload in batches by year rather than all at once.
- **Missing subfolders after import:** confirm each exported folder produced its own MBOX file, then re-import the ones that are missing.
- **Incorrect message dates:** some EML and MBOX exports lose the original timestamps, so test a small batch first before committing a full archive.
- **Large imports freeze:** break the import into smaller folders (by year or quarter) and give Thunderbird time to index each one.
- **Auto-detect fails to find your settings:** use **Configure manually** with the IMAP and SMTP details from your Noiz welcome email, as described in Option A.
## Summary
Thunderbird gives you robust performance with large mailboxes, native PGP encryption, and the freedom to run on any major desktop platform, all while speaking the same standards-based IMAP and SMTP your Noiz mailbox already uses. Choose a clean IMAP setup for speed and simplicity, or follow the relevant migration module (PST, MBOX, or EML) to bring your historic mail across safely.
If you would rather not handle the migration yourself, or you hit a quota or connection issue you cannot clear, Noiz support can help you confirm your mailbox settings and plan the move. Open a ticket from your Noiz client area and the team will point you in the right direction.
# Winmail.dat Attachments: Cause, Impact and Fixes (Microsoft TNEF)
Source: https://docs.noiz.ie/email/winmaildat-attachments-cause-impact-and-fixes-microsoft-tnef/
**Summary:** If your recipients see a single `winmail.dat` file instead of normal attachments, the message was sent in Microsoft's proprietary **TNEF** format by **Outlook** or **Exchange**. This is **not** a problem with the Noiz mail servers or any standards-compliant MTA. The fix must be applied on the **sender's Microsoft side** (Outlook or Exchange settings or policy). If you are the sender, or are helping the sender, apply the changes below; if the changes do not resolve it, contact **Microsoft Support** or the sender's **IT provider**.
**Last reviewed:** 27 July 2026, against Microsoft **Exchange Online** and current **classic Outlook for Windows**. This guide is written for Noiz hosting and is kept current against Microsoft's TNEF and remote-domain behaviour. It complements, and does not replace, the official Microsoft documentation linked below.
### Official Documentation Reference
- [Remote domains in Exchange Online](https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/remote-domains/remote-domains) (message format and RTF/TNEF behaviour)
- [Manage remote domains in Exchange Online](https://learn.microsoft.com/en-us/exchange/mail-flow-best-practices/remote-domains/manage-remote-domains) (admin centre and PowerShell steps)
- [Set-RemoteDomain](https://learn.microsoft.com/en-us/powershell/module/exchangepowershell/set-remotedomain) (the `TNEFEnabled` parameter)
## What is winmail.dat?
`winmail.dat` appears when Microsoft Outlook or Exchange encapsulates rich text formatting and attachments using **Transport Neutral Encapsulation Format (TNEF)**. Most non-Microsoft mail clients (Apple Mail, Gmail, Thunderbird, webmail, many mobiles) cannot interpret TNEF, so they display a single opaque file named *winmail.dat* instead of the intended attachments.
## Is this a server or MTA issue?
No. Standards-compliant MTAs (Postfix, Exim, Sendmail and others) *relay* what they receive and do not generate or convert TNEF. If Outlook or Exchange emits TNEF, the message leaves the Microsoft environment already incompatible with many recipients. There is nothing a downstream server can change without risking message corruption or breaking the message's DKIM signature.
## Why it can happen even when Outlook says "HTML"
Outlook's "Compose in HTML" setting does not guarantee that the final wire format is MIME or HTML. TNEF can still be forced by:
- Outlook or Exchange **contact records** flagged to send using Rich Text Format (RTF).
- Exchange **Remote Domain** policies that allow or force RTF/TNEF.
- **Transport rules (mail flow rules)**, shared mailboxes, or cached address properties overriding user preferences.
- Legacy compatibility modes or add-ins that trigger RTF/TNEF on certain messages.
**Good to know:** TNEF is a behaviour of **classic Outlook for Windows** (the Win32 desktop app). The **new Outlook for Windows** and **Outlook on the web** do not send RTF/TNEF, so if a sender can reproduce the problem, it is almost always coming from the classic desktop client, a contact flag, or a tenant-level Remote Domain policy.
## Who is affected
- Recipients using non-Microsoft clients (Apple Mail, Gmail web, Thunderbird, most mobile apps).
- Mixed environments where only some recipients use Microsoft 365 or Outlook.
## How to confirm it is TNEF
1. View the **original message source** of an affected email at the recipient end.
2. Look for MIME parts with content types like `application/ms-tnef`, or a part named `winmail.dat`.
3. If either is present, the message was sent using TNEF upstream, on the Microsoft side.
## Definitive fixes (on the sender's Microsoft side)
### Classic Outlook for Windows (per user)
1. Go to **File โ Options โ Mail**.
2. Under **Compose messages**, set *Compose messages in this format* to **HTML** (or **Plain Text**).
3. Under **Message format**, set *When sending messages in Rich Text format to Internet recipients* to **Convert to HTML format** (or Plain Text).
4. Open the **contact properties** for any frequently emailed recipient (in Contacts, or from the recipient's card) and make sure the email address is **not** set to *Send using Outlook Rich Text Format*.
5. **Clear the cached recipient entry.** The auto-complete (nickname) cache can retain the old RTF flag even after you fix the contact. Delete the recipient from the auto-complete list (highlight it in the address suggestions and press **Delete**) and re-add them, then send a fresh test message.
### Microsoft 365 / Exchange Online (tenant-wide)
Run in Exchange Online PowerShell as an administrator:
```
Set-RemoteDomain Default -TNEFEnabled $false
Get-RemoteDomain | Format-Table Name,DomainName,TNEFEnabled
```
Setting `TNEFEnabled` to `$false` is the equivalent of **Never** use Rich Text Format for that remote domain. To target a single partner domain instead of everything, create or edit a remote domain for it:
```
Set-RemoteDomain "partnerdomain.com" -TNEFEnabled $false
```
You can also do this in the **Exchange admin centre**: **Mail flow โ Remote domains**, open **Default** (or the partner domain), and under the message format options set **Rich Text Format (RTF)** to **Never**. Then review your **mail flow rules (transport rules)** to make sure none force RTF/TNEF, and verify any **third-party connectors** are not rewriting content types.
### Exchange Server (on-premises)
1. In the **Exchange admin centre**, go to **Mail flow โ Remote domains**, open **Default**, and set **Rich Text Format (RTF)** to **Never**.
2. Or run the equivalent in the Exchange Management Shell:
```
Set-RemoteDomain Default -TNEFEnabled $false
```
Audit transport rules and any address policies that could re-enable RTF/TNEF.
### Group Policy or registry enforcement (optional, older fleets)
For managed desktop fleets, you can enforce TNEF off via policy or the registry. The example below covers Office 2016 through Microsoft 365 Apps (all use branch `16.0`):
```
[HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Preferences]
"DisableTNEF"=dword:00000001
```
## What Noiz can and cannot do
- **Noiz can** confirm the presence of TNEF in received messages, validate DKIM and DMARC alignment, and show that the message arrived already encoded as TNEF from the Microsoft environment.
- **Noiz cannot** convert or strip TNEF safely at the mail server without risking damage to the message or attachments, or breaking the sender's signature. The correct, standards-compliant fix is to stop TNEF at the source, in Outlook or Exchange.
## Next steps for senders
1. Apply the **Outlook** or **Exchange** changes above.
2. Retest by sending a fresh message with a simple attachment (for example a PDF) to an external, non-Microsoft mailbox.
3. If TNEF continues, **contact Microsoft Support or your IT provider** to audit Remote Domain policies, transport rules, address book and contact flags, and connectors that may still be forcing TNEF.
## Troubleshooting
**Symptom: one recipient keeps getting winmail.dat after the fix.** The recipient's address is almost certainly still cached with the RTF flag in the sender's auto-complete list. Delete it from the suggestions and re-add the contact, then send a fresh test.
**Symptom: only some external recipients are affected.** The default Remote Domain is likely set to *Follow user settings* for RTF. Set it to **Never** (`-TNEFEnabled $false`) so it no longer depends on each user's Outlook configuration.
**Symptom: the sender uses the new Outlook or webmail and still sees the problem.** The new clients do not emit TNEF, so the RTF/TNEF is being applied by a tenant policy, a contact flag, or a transport rule. Focus the investigation on Exchange, not the desktop client.
## FAQ
### Can Noiz fix existing winmail.dat messages?
No. Noiz can confirm the cause, but the only correct resolution is to stop TNEF at the sender. Some third-party tools can extract the content from a `winmail.dat` file, but that is a workaround, not a fix.
### Why do some recipients see the attachments fine?
Recipients using Microsoft Outlook or Exchange can parse TNEF correctly, which masks the issue. Non-Microsoft clients typically cannot.
### Can enabling or disabling TLS or filters on the Noiz server help?
No. TLS and standard content filters do not convert Microsoft's TNEF to MIME. Attempting to rewrite the content on the server side risks corruption and signature failures.
## Need a hand?
If you receive winmail.dat files on a Noiz mailbox and need help confirming the cause before you go back to the sender, contact Noiz support with a copy of an affected message (including full headers) and Noiz will verify whether it arrived as TNEF and confirm that the fix belongs on the sender's Microsoft side.
# How to Delete a Database Table in phpMyAdmin
Source: https://docs.noiz.ie/databases/how-to-delete-a-database-table-in-phpmyadmin/
**phpMyAdmin** is the web-based manager for MySQL and MariaDB databases that ships with every Noiz hosting control panel. This guide shows you how to delete a single table out of a database using it, which is the usual way to clear out a table left behind by an uninstalled plugin, a failed import, or an application you no longer run.
Deleting a table in database terms is called **dropping** it. A drop removes the table's rows, its columns, its indexes and the table itself in one action. There is no undo, no confirmation beyond the single dialogue box, and no recycle bin. The only way back is a backup, so take one before you start.
**Last reviewed:** 27 July 2026, against phpMyAdmin **5.2.3** (latest stable, released 8 October 2025). This guide is written for Noiz hosting and is kept current against phpMyAdmin. It complements, and does not replace, the official phpMyAdmin documentation linked below.
### Official Documentation Reference
- [phpMyAdmin User Guide (docs.phpmyadmin.net)](https://docs.phpmyadmin.net/en/latest/user.html)
- [phpMyAdmin: Import and Export (how to take and restore the backup)](https://docs.phpmyadmin.net/en/latest/import_export.html)
- [MySQL Reference Manual: DROP TABLE statement](https://dev.mysql.com/doc/refman/8.4/en/drop-table.html)
- [MySQL Reference Manual: TRUNCATE TABLE statement](https://dev.mysql.com/doc/refman/8.4/en/truncate-table.html)
- [MariaDB Knowledge Base: DROP TABLE](https://mariadb.com/kb/en/drop-table/)
## Prerequisites
- Access to your hosting control panel (your Noiz welcome email contains the login details).
- The name of the database the table sits in. For WordPress this is the `DB_NAME` value in `wp-config.php`.
- A current backup, or a few minutes to take one in step 2 below.
- Certainty that nothing still reads from the table. If you are not certain, rename it instead of dropping it. That option is covered at the end of this guide.
## Step 1: Open phpMyAdmin
phpMyAdmin is reached from your control panel, so you are already authenticated and do not need to enter database credentials separately. Depending on which Noiz platform your account sits on, the route differs slightly, but the destination is the same application:
- **Plesk**: open **Databases**, find the database in the list, then click **phpMyAdmin** next to it.
- **DirectAdmin**: open **Account Manager** or **Databases**, then click the **phpMyAdmin** link.
- **ISPConfig**: open **Sites**, then **Database**, and use the phpMyAdmin link on the database entry.
- **Any other panel**: look for a **Databases** section, then the **phpMyAdmin** entry inside it.
The screenshots below were taken on an older panel build, but every step from the moment phpMyAdmin opens is identical on all of them.

## Step 2: Back Up the Database First
A dropped table cannot be recovered from within phpMyAdmin, so the export you take now is the entire safety net for this job. Select the database in the left sidebar, click the **Export** tab at the top, leave the export method on **Quick** with the format set to **SQL**, and click **Export**. The `.sql` file downloads to your computer.
If you only want the one table, open the table first and then use its own **Export** tab. That produces a much smaller file and is enough to put the table back exactly as it was.
Keep the file until the site or application has been tested and is behaving normally. Restoring it later is a matter of using the **Import** tab on the same database.
## Step 3: Expand the Database in the Navigation Tree
The left sidebar lists every database your account can reach. Click the expand arrow beside the database name (or the name itself) to open it and reveal its tables.

If more than one database is listed, pick carefully. A single hosting account often holds databases for several sites, plus leftovers from old installs, and table names repeat across them. For WordPress, the correct database is the value of `DB_NAME` in that site's `wp-config.php` file, which you can open in File Manager.
## Step 4: Select the Table You Want to Delete
Click the table name in the sidebar, or the table row in the main panel, to open it. The worked example below uses the WordPress table `wp_links`.

Two things to check before going further. First, `wp_` is only the default WordPress table prefix, and many installs use a custom one, so your table may be named something like `xk4_links` instead. The prefix in use is the `$table_prefix` value in `wp-config.php`. Second, confirm the row count and glance at the **Browse** tab. If a table you assumed was abandoned is full of recent rows, something is still writing to it.
## Step 5: Open the Operations Tab
With the table open, click **Operations** in the row of tabs across the top. This tab holds the table-level actions: rename, move, copy, change storage engine, and the delete options.

## Step 6: Click Delete the Table (DROP)
Scroll down to the **Delete data or table** panel near the bottom of the page. It offers two options, and the difference between them matters:
- **Empty the table (TRUNCATE)** deletes every row but keeps the table, its columns and its structure. The application can carry on writing to it.
- **Delete the table (DROP)** removes the table completely. Nothing is left behind.
Click **Delete the table (DROP)**, then confirm in the dialogue box that appears. phpMyAdmin runs the statement and reports success, and the table disappears from the sidebar.
**Warning:** the whole table is removed. Restoring it is impossible without a backup, and phpMyAdmin has no undo for this action. Make sure you have completed step 2 before you confirm.
## Deleting Several Tables at Once
If you are clearing out a group of tables, for example everything a removed plugin left behind, you do not need to repeat the steps above for each one. Click the database name in the sidebar so the full table list is showing, tick the checkbox beside each table you want gone, then choose **Drop** from the **With selected** menu underneath the list. phpMyAdmin shows the full list of tables it is about to drop, which is the moment to read it carefully, then confirms.
## Drop, Empty, or Rename: Choosing the Right One
Dropping is the most destructive of the three and often not what is actually needed:
- **Drop** when the table belongs to software you have removed and will not reinstall.
- **Empty (TRUNCATE)** when the application still uses the table but the contents are junk, such as a bloated log, session or transient table. The application keeps working because the table still exists.
- **Rename** when you are fairly sure the table is unused but want a way back. On the same **Operations** tab, use **Rename table to** and give it a name like `zz_old_wp_links`. The application stops finding it, exactly as if it were deleted, but every row is still there if something breaks. Drop it a fortnight later once nothing has complained.
## Gotchas Worth Knowing
- **Do not drop an application's core tables.** Dropping something like `wp_options`, `wp_posts` or `wp_users` takes the site down immediately. Only remove tables you can positively identify as belonging to software that is no longer installed.
- **`wp_links` is a WordPress core table, not plugin debris.** It backs the old Links Manager, hidden by default since WordPress 3.5. Dropping it is usually harmless on a modern site, but WordPress or a plugin may recreate it, and any plugin that re-enables the Links Manager will error without it. It is used here as the example because it is one of the few core tables that is genuinely safe to remove.
- **Foreign keys can block the drop.** If another table references this one through a foreign key constraint, InnoDB refuses the statement and returns an error. Remove the dependent constraint first, or drop the tables in the correct order, rather than forcing it.
- **Dropping a table does not always shrink your disk usage straight away.** With the usual per-table file layout the space is returned when the table file is removed, but on shared tablespaces the freed space is reused internally rather than handed back to the filesystem.
- **Orphaned tables are not always safe to delete.** A prefix you do not recognise may belong to a second application sharing the same database, which is common on older installs where a forum or a shop was set up alongside the main site.
- **Case matters.** On Linux servers, table names are case sensitive. `wp_Links` and `wp_links` are different tables.
## Troubleshooting
**Symptom**: The **Operations** tab is missing or the delete options are greyed out. The database user phpMyAdmin is connecting as does not hold the `DROP` privilege on that database. Grant the user full privileges on the database in your control panel, then reload phpMyAdmin.
**Symptom**: "Cannot delete or update a parent row: a foreign key constraint fails" or error `#1217`. Another table depends on this one. Find the referencing table, drop or alter its constraint, then retry.
**Symptom**: The table is gone but the site now shows a database error. Import the `.sql` file you exported in step 2 using the **Import** tab on the same database. Importing a single-table export recreates just that table and leaves the rest untouched.
**Symptom**: The table reappears after you delete it. The application recreated it, which means it is still in active use. Do not keep dropping it. Uninstall or disable the software that owns the table first.
**Symptom**: You cannot see the database you expected in the sidebar. The database belongs to a different hosting account or user, or the application connects to a database you did not know about. Confirm the name in the application's configuration file rather than guessing from the list.
## Related Guides
- [How to Export a Database in phpMyAdmin](/databases/how-to-export-a-database-in-phpmyadmin/)
- [How to Import a Database in phpMyAdmin](/databases/how-to-import-a-database-in-phpmyadmin/)
- [How to Edit a Database Table in phpMyAdmin](/databases/how-to-edit-a-database-table-in-phpmyadmin/)
## Need a hand?
Dropping the wrong table is one of the quickest ways to take a working site offline. If you are on a managed Noiz plan and would rather have the table identified and removed for you, or you need a database restored from backup, contact the Noiz support team through the client area and the team will assist.
# How to Edit a Database Table in phpMyAdmin
Source: https://docs.noiz.ie/databases/how-to-edit-a-database-table-in-phpmyadmin/
**phpMyAdmin** is the web-based manager for MySQL and MariaDB databases that ships with every Noiz hosting control panel. It lets you open a database table, find a single row, and change one stored value directly, which is the quickest way to fix an application that will not let you change that value from its own admin area. This guide shows you how to edit a table row safely, using the WordPress `wp_options` table as the worked example.
Editing a database by hand is a power tool. There is no undo button and no confirmation prompt on a value change, so the backup step below is not optional.
**Last reviewed:** 27 July 2026, against phpMyAdmin **5.2.3** (latest stable, released 8 October 2025). This guide is written for Noiz hosting and is kept current against phpMyAdmin. It complements, and does not replace, the official phpMyAdmin documentation linked below.
### Official Documentation Reference
- [phpMyAdmin User Guide (docs.phpmyadmin.net)](https://docs.phpmyadmin.net/en/latest/user.html)
- [phpMyAdmin: Import and Export (backing up before you edit)](https://docs.phpmyadmin.net/en/latest/import_export.html)
- [WordPress Options API and the options table](https://developer.wordpress.org/apis/options/)
- [WordPress: Changing The Site URL](https://wordpress.org/documentation/article/changing-the-site-url/)
## Prerequisites
- Access to your hosting control panel (your Noiz welcome email contains the login details).
- The name of the database the application actually uses. For WordPress this is the `DB_NAME` value in `wp-config.php`.
- A current backup, or a few minutes to take one in step 2 below.
## Step 1: Open phpMyAdmin
phpMyAdmin is reached from your control panel, so you are already authenticated and do not need to enter database credentials separately. Depending on which Noiz platform your account sits on, the route differs slightly, but the destination is the same application:
- **Plesk**: open **Databases**, find the database in the list, then click **phpMyAdmin** next to it.
- **DirectAdmin**: open **Account Manager** or **Databases**, then click the **phpMyAdmin** link.
- **ISPConfig**: open **Sites**, then **Database**, and use the phpMyAdmin link on the database entry.
- **Any other panel**: look for a **Databases** section, then the **phpMyAdmin** entry inside it.
The screenshots below were taken on an older panel build, but every step from the moment phpMyAdmin opens is identical on all of them.

## Step 2: Back Up the Database First
Before changing anything, take a copy you can restore from. In phpMyAdmin, select the database in the left sidebar, click the **Export** tab at the top, leave the export method on **Quick** with the format set to **SQL**, and click **Export**. The `.sql` file downloads to your computer.
Keep that file until you have confirmed the site still works. Restoring it later is a matter of using the **Import** tab on the same database.
## Step 3: Expand the Database in the Navigation Tree
The left sidebar lists every database your account can reach. Click the arrow beside the database name (or the name itself) to expand it and reveal its tables.

If more than one database is listed, pick carefully. A single hosting account often holds databases for several sites, plus leftovers from old installs. For WordPress, the correct one is the value of `DB_NAME` in the site's `wp-config.php` file, which you can open in File Manager.
## Step 4: Select the Table You Want to Edit
Click the table name in the sidebar, or click the table row in the main panel, to open it on the **Browse** tab.
For the WordPress example, the table holding site-wide settings is `wp_options`. Note the underscore. Note also that `wp_` is only the default table prefix. Many installs use a custom prefix for security, so your table may be named something like `xk4_options` instead. The prefix in use is the `$table_prefix` value in `wp-config.php`.

## Step 5: Find the Correct Row and Click Edit
The **Browse** tab shows the first 25 rows, with **Edit**, **Copy** and **Delete** links at the start of each row.

Do not rely on row position. Row order is not guaranteed and the row you want may be on a later page. Instead, use the **Search** tab to target the row precisely: put the column name and value you are looking for into the search form and run it. For WordPress, searching the `option_name` column for `blogname` returns the single row that holds the site title. Then click **Edit** on that result.
## Step 6: Change the Value and Click Go
phpMyAdmin opens the row in an editable form, one field per column. Change only the field you came for, leave the primary key column alone, then click **Go** at the bottom of the form to write the change.

phpMyAdmin confirms with a green message and shows the `UPDATE` statement it ran. Reload the site in a new browser tab to confirm the change took effect.
## Why This Is Useful
Editing the value directly bypasses the application's own admin area entirely, which matters when that admin area is the thing that is broken. Common cases include a theme or plugin that renders the WordPress dashboard unusable, a site URL that was changed to the wrong address and now locks you out, or a setting that refuses to save because of a caching or permissions fault. In each of those, the value in the table is the real source of truth, and changing it there is the fastest route back to a working site.
## Gotchas Worth Knowing
- **Serialised data breaks if you edit it by hand.** Values that begin with something like `a:3:{s:5:...}` are PHP serialised arrays, and the numbers are character counts. Change the text without changing the count and the application will silently discard the whole option. Never search-and-replace inside serialised values by hand. Use a tool built for it, or change the setting through the application.
- **Site URL changes need both rows.** In WordPress, `siteurl` and `home` both live in the options table. Change one and not the other and you get redirect loops or a half-broken site.
- **No Edit link means no primary key.** If a table has no primary or unique key, phpMyAdmin cannot identify a single row and hides the inline edit links. You will need a targeted `UPDATE` statement on the **SQL** tab instead, with a `WHERE` clause narrow enough to hit one row.
- **Caching can hide your change.** If a page or object cache is active, the old value may keep being served. Clear the application cache, and any CDN cache, before concluding the edit did not work.
- **The autoload column matters in WordPress.** Leave it as you found it. Flipping it changes whether the option loads on every page request, which affects performance rather than correctness, but there is no reason to touch it while changing a value.
- **Editing while the site is live is a race.** On a busy site the application may overwrite your change moments later. For anything beyond a one-off fix, put the site into maintenance mode first.
## Troubleshooting
**Symptom**: The change saves in phpMyAdmin but the site shows the old value. Clear the application, object and CDN caches, then reload with a hard refresh. If the value reverts in the database itself, a plugin or configuration file is rewriting it. For WordPress, check whether `WP_HOME` or `WP_SITEURL` are hard-coded in `wp-config.php`, which overrides the database.
**Symptom**: You get "#1062 Duplicate entry" when saving. You have edited a column covered by a unique index and the new value already exists in another row. Pick a different value, or find and resolve the existing row first.
**Symptom**: The site went blank or started redirecting after your edit. Restore the `.sql` file you exported in step 2 using the **Import** tab, then work out what the correct value should have been before trying again.
**Symptom**: You cannot see the database you expected in the sidebar. The database belongs to a different hosting account or user, or the application is connecting to a database you did not know about. Confirm the name in the application's configuration file rather than guessing from the list.
## Need a hand?
Direct database edits are one of the easier ways to break a working site. If you are on a managed Noiz plan and would rather have the change made for you, or you need a database restored from backup, contact the Noiz support team through the client area and the team will assist.
# How to Export a Database in phpMyAdmin
Source: https://docs.noiz.ie/databases/how-to-export-a-database-in-phpmyadmin/
Exporting a database in **phpMyAdmin** produces a single downloadable `.sql` file containing the SQL statements needed to rebuild that database: the table structures and, by default, all of the data inside them. It is the quickest way to take a portable copy of a site's database before an upgrade, when migrating a site to another host, or when a developer asks you for "a copy of the database".
This guide covers exporting an entire database, which is what most people need, and also shows you how to export a single table when that is all you want. The steps are the same whichever hosting control panel your Noiz account uses, because phpMyAdmin itself is the same tool in each one.
**Last reviewed:** 27 July 2026, against phpMyAdmin **5.2.3** (latest stable). This guide is written for Noiz hosting and is kept current against phpMyAdmin. It complements, and does not replace, the official phpMyAdmin documentation linked below.
### Official Documentation Reference
- [phpMyAdmin: Import and export](https://docs.phpmyadmin.net/en/latest/import_export.html)
- [phpMyAdmin: Frequently asked questions (export and import limits)](https://docs.phpmyadmin.net/en/latest/faq.html)
- [MySQL Reference Manual: mysqldump](https://dev.mysql.com/doc/refman/8.4/en/mysqldump.html)
## Prerequisites
- An active Noiz hosting account with at least one MySQL or MariaDB database.
- Your hosting control panel login details, or a direct phpMyAdmin login for the database user.
- Somewhere on your computer with enough free space for the dump file. A database dump is plain text and compresses well, but an uncompressed dump of a busy site can be several hundred megabytes.
## Opening phpMyAdmin
1. Log in to your hosting control panel from the Noiz client area.
2. In the **Databases** section, click **phpMyAdmin**. Some panels place the link beside each individual database in the database list rather than as a separate icon. 
Opening phpMyAdmin from the control panel signs you in automatically, so no separate database password is needed. If you reach phpMyAdmin through a direct URL instead, log in with the database username and password from your site's configuration file, for example `wp-config.php` for WordPress or `configuration.php` for Joomla.
## Exporting the Whole Database
1. In the navigation tree on the left, click the database you want to export. Selecting the correct database first is the step that matters most: if you run an export while phpMyAdmin is still on the server home page, you will get a dump of every database you can see, which is usually not what you want. 
2. With the database selected, click the **Export** tab along the top of the page. 
3. Leave **Export method** set to **Quick** and **Format** set to **SQL**. Quick exports every table with structure and data using sensible defaults, which is exactly what a backup or a migration needs.
4. Click **Export**. On older phpMyAdmin releases this button is labelled **Go**.
The browser downloads a file named after the database, such as `yourdatabase.sql`. Large databases take a while, and nothing appears to happen until the download begins, so give it time before clicking again. Clicking a second time starts a second export and doubles the load on the server.
## Useful Custom Export Options
Choose **Custom** instead of Quick when you need any of the following. Everything else can be left at its default.
- **Compression**: set this to **gzipped** or **zipped**. A compressed dump is typically five to ten times smaller, downloads far faster, and is much less likely to time out. This is the single most useful option on the page.
- **Structure and data**: switch to **Structure only** to get an empty copy of the schema, or **Data only** when the tables already exist on the destination.
- **Add DROP TABLE / VIEW / PROCEDURE / FUNCTION / EVENT statement**: tick this if the dump will be imported over an existing copy of the same database. Without it, the import fails with "table already exists" errors. With it, the import destroys the existing tables before recreating them, so only use it when that is what you intend.
- **Character set of the file**: leave this as `utf8`. Changing it is the usual cause of accented characters, currency symbols and emoji turning into mojibake after a restore.
- **Database system or older MySQL server**: set this if you are importing into an older or different database server. It adjusts the syntax the dump uses so the target server accepts it.
## Exporting a Single Table
To export one table rather than the whole database, click the database in the left navigation tree, then click the table itself so that its name appears in the breadcrumb at the top of the page. Now click **Export** and continue as above. The export applies to whatever is currently selected, so always check the breadcrumb before clicking Export.
You can also select several tables at once: from the database's **Structure** tab, tick the tables you want, choose **Export** from the **With selected** dropdown at the bottom of the list, and continue from the Export page.
## Checking the Export Worked
A truncated dump looks perfectly normal until the day you try to restore it, so it is worth thirty seconds of checking:
- The file size should be plausible. A few kilobytes for a site with years of content means the export failed part way through.
- Open the file in a plain text editor (not a word processor) and scroll to the end. A complete dump finishes with a comment line beginning `-- Dump completed on`. If the file simply stops in the middle of an INSERT statement, the export timed out.
- The top of the file should list the expected tables in the `CREATE TABLE` statements.
Keep in mind that a database dump is not a complete backup of a website. Your files, uploads, themes and configuration live on the filesystem, not in the database. A restorable backup needs both.
## Troubleshooting
**The download stops early or the file is incomplete**: the export exceeded the PHP execution time or memory limit before it finished. Run the export again with **Custom** selected and **Compression** set to **gzipped**, which reduces both the time and the amount of data sent to the browser. If it still fails, the database is too large for a browser-based export and should be dumped over SSH instead.
**Nothing downloads at all**: check that a browser extension or pop-up blocker is not suppressing the download, and confirm you clicked **Export** on the database rather than on the server home page. Retry in a private browsing window to rule out extensions.
**The dump is far bigger than expected**: you probably exported from the server home page, which includes every database on the account. Select the specific database in the left navigation tree and export again.
**You cannot see the database you expect**: phpMyAdmin only shows databases the logged-in database user has been granted access to. Check the user is assigned to that database in your control panel's database section, with the privileges it needs.
**The import into another server fails on a view or trigger**: dumps record a `DEFINER` clause naming the database user that created the object. If that user does not exist on the destination server, the import errors. Edit the dump to remove the `DEFINER=...` clauses, or recreate the user on the destination first.
## When phpMyAdmin Is the Wrong Tool
Browser-based exports run inside PHP and are bound by its time and memory limits, so they become unreliable somewhere in the region of a few hundred megabytes. For databases beyond that size, dump them over SSH with `mysqldump`, which streams straight to disk and has no browser in the way:
```
mysqldump -u yourdbuser -p yourdatabase | gzip > yourdatabase.sql.gz
```
Replace `yourdbuser` and `yourdatabase` with your own values. You will be prompted for the database password. Never place the password directly on the command line, because it is then visible to other users of the server through the process list.
If your plan does not include SSH access, or the export keeps timing out, open a ticket from your Noiz client area. Noiz support can take the dump server-side and place the file where you can collect it.
# How to Import a Database in phpMyAdmin
Source: https://docs.noiz.ie/databases/how-to-import-a-database-in-phpmyadmin/
**phpMyAdmin** is the web-based MySQL and MariaDB manager included with your Noiz hosting account. Importing a database means running an `.sql` dump file against an existing database so that its tables and data are recreated on the server. This is how you restore a backup, move a site from another host, or push a copy of a development database up to live.
This guide applies to any Noiz hosting plan that gives you phpMyAdmin. You open it from your hosting control panel (Plesk on the South African platform, DirectAdmin on the Irish platform), or from the database section of whichever panel your plan provides. The phpMyAdmin steps themselves are identical in every panel.
**Last reviewed:** 27 July 2026, against phpMyAdmin **5.2.3** (latest stable, released October 2025). This guide is written for Noiz hosting and is kept current against phpMyAdmin. It complements, and does not replace, the official phpMyAdmin documentation linked below.
### Official Documentation Reference
- [phpMyAdmin: Import and export](https://docs.phpmyadmin.net/en/latest/import_export.html)
- [phpMyAdmin FAQ: I cannot upload big dump files (memory, HTTP or timeout problems)](https://docs.phpmyadmin.net/en/latest/faq.html#i-cannot-upload-big-dump-files-memory-http-or-timeout-problems)
- [MySQL Reference Manual: mysqldump](https://dev.mysql.com/doc/refman/8.4/en/mysqldump.html) (how dump files are produced)
## Prerequisites
- The `.sql` dump file you want to import, saved on your computer. A compressed dump (`.sql.gz`, `.sql.zip`, `.sql.bz2`) works too and does not need unpacking first.
- A database already created on the server to import into. phpMyAdmin imports *into* a database; it does not normally create one for you. Create the database in your hosting control panel first if it does not exist yet.
- The exact name of that database. On shared hosting the panel usually prefixes database names with your account name, so a database you called `shop` may actually be `example_shop` on the server.
## Before You Import: Read This First
An import is not a preview. It executes every statement in the file against the database you have selected, and there is no undo button.
- **Export the target database first.** Even if you believe it is empty, take a dump before you import. It costs thirty seconds and it is the only thing that will save you if the wrong database was selected.
- **Import into an empty database wherever possible.** Most dumps produced by `mysqldump` include `DROP TABLE IF EXISTS` statements, so they replace tables cleanly. Dumps that only contain `INSERT` statements do not, and running one on top of existing data produces duplicate key errors or silently doubles up rows.
- **Check which database is selected before you click Import.** phpMyAdmin shows the target in the page heading, for example `Importing into the database "example_wordpress"`. If that heading says **Server: localhost** instead of naming a database, no database is selected and the import will fail or land in the wrong place.
## Import the SQL File
**1.** Log in to your hosting control panel and open **phpMyAdmin** from the databases area.

**2.** In the navigation tree in the left sidebar, click the database you want to import into. Ignore `information_schema` and any other system databases; those belong to the server, not to your account.

**3.** Click the **Import** tab in the menu bar across the top of the page.

**4.** In the **File to import:** section, find **Browse your computer:** and click the file chooser button (your browser labels it **Browse** or **Choose File**), then pick the `.sql` file from your computer. The maximum accepted file size is printed next to the button, for example `(Max: 500MiB)`. You can also drag the file onto the page instead of using the file picker.

**5.** Leave **Character set of the file** at `utf-8` unless you know the dump was created in another encoding. Getting this wrong is one of the few import mistakes that is genuinely hard to reverse, because it corrupts accented and non-Latin characters as they are written.
**6.** Leave the remaining defaults alone for a standard restore, then scroll to the bottom and click the **Import** button.
**7.** Wait for the page to finish. Large files can take several minutes, and closing the tab or clicking away mid-import leaves the database half populated.
A green banner confirms the import finished, along with the number of queries executed and the file name.

Confirm the result rather than trusting the banner alone: the table list in the left sidebar should now show the expected tables, and clicking a couple of them should show real rows.
**A note on the screenshots:** these were captured on an earlier phpMyAdmin release. The page layout and the option names are unchanged, but the submit button at the bottom of the Import tab is now labelled **Import** rather than **Go**.
## The Import Options Explained
You can ignore all of these for a routine restore, but they are the settings that rescue a failing import.
- **Partial import โ Allow the interruption of an import...** Ticked by default. It lets phpMyAdmin stop just before the PHP time limit is reached and resume from where it stopped when you resubmit. Useful for large files, but it breaks transactions, so an interrupted import can leave the database in a partial state until you finish it.
- **Skip this number of queries (for SQL) starting from the first one.** Used with the option above. If an import times out, phpMyAdmin tells you the position it reached; enter that number here and resubmit the same file to carry on instead of starting from scratch.
- **Other options โ Enable foreign key checks.** Ticked by default. Untick it when a dump creates tables in an order that references tables which do not exist yet, which is the usual cause of `Cannot add or update a child row` and `errno: 150` errors.
- **Format.** Leave on **SQL** for a database dump. The other formats (CSV, XML, OpenDocument Spreadsheet) are for loading tabular data into an existing table, not for restoring a whole database.
- **Format-specific options โ SQL compatibility mode.** Leave on `NONE`. It only matters when the dump came from a much older MySQL version and the import fails on syntax the current server no longer accepts.
## When the File Is Larger Than the Upload Limit
This is the single most common reason an import will not start. If your `.sql` file is bigger than the maximum shown next to **Browse your computer:**, the upload either fails immediately or the page returns blank after a long wait.
1. **Compress the dump.** phpMyAdmin decompresses the file on the server, so a zipped or gzipped dump only has to fit through the upload limit in its compressed form. SQL text compresses extremely well, often to a tenth of its size. The file name must end in the format followed by the compression, for example `backup.sql.zip` or `backup.sql.gz`. Renaming a `.zip` to `.sql` does not work and produces a syntax error.
2. **Split the dump.** If the compressed file is still too large, split it into several smaller `.sql` files and import them in order. Keep the table creation statements with the data that belongs to them.
3. **Ask Noiz to import it server side.** For very large databases the practical answer is to import from the command line, which has no upload limit and no web timeout. Upload the dump to your account by FTP or SFTP and open a support ticket telling Noiz the file path and the target database name.
## Troubleshooting
- **"No data was received to import. Either no file name was submitted, or the file size exceeded the maximum size permitted by your PHP configuration."** The file is over the upload limit, or the upload was cut off in transit. Compress the dump and try again, or use one of the other options above.
- **"#1044 Access denied for user" or "#1007 Can't create database".** The dump contains `CREATE DATABASE` and `USE` statements from the server it came from. Your hosting account is not permitted to create databases from SQL, and the old database name almost certainly does not match your new one. Open the dump in a plain text editor, delete those two lines from the top, and import again.
- **"#1062 Duplicate entry ... for key 'PRIMARY'".** You are importing into a database that already holds this data. Empty the database first (or create a fresh one) and repeat the import.
- **"The user specified as a definer does not exist".** The dump contains views, triggers or stored routines carrying a `DEFINER` clause naming a user from the original server. Edit the dump and remove each ``DEFINER=`someuser`@`localhost``` clause, then import again.
- **"Fatal error: Maximum execution time of ... seconds exceeded" or the page stops part way.** The import ran out of time. Note the position phpMyAdmin reports, enter it in **Skip this number of queries**, and resubmit the same file to continue.
- **Accented characters appear as `รยฉ`, `รขโฌโข` or question marks after the import.** The character set was wrong. Do not try to correct the text by hand. Drop the tables, set **Character set of the file** to match how the dump was actually created (usually `utf-8`, occasionally `latin1` for older dumps) and import the original file again.
- **The import succeeded but the site still shows an error.** The database is only half the job. Check that your application's configuration file points at the correct database name, database user and password on this server. For WordPress that is `wp-config.php`; a restored database with the old credentials still in the config file produces "Error establishing a database connection".
- **A restored WordPress site loads the old domain.** The site and home URLs are stored in the database. Change them with a search and replace tool that understands PHP serialised data, because a plain find and replace corrupts serialised option values and breaks widgets and theme settings.
If the import will not complete, or the database is too large to push through the browser, contact the Noiz support team and Noiz can run the import on the server for you. Please note that if you are not on a managed plan, migration and recovery work of this kind may be billable.
# How to Import and Export a Database with phpMyAdmin
Source: https://docs.noiz.ie/databases/how-to-import-and-export-a-database-with-phpmyadmin/
This guide shows you how to copy a MySQL database out to a file and how to load one back in again, using phpMyAdmin, the browser-based database tool that Noiz provides with every hosting account. Copying a database out is called an **export** (you will also hear it called a "dump" or a "backup"); loading one in is called an **import** (sometimes a "restore"). You will do this when you back up a site before making changes, when you move a site to or from Noiz, or when a developer hands you a `.sql` file to load. phpMyAdmin works the same way whether your account is on Plesk, cPanel, DirectAdmin or ISPConfig, so this article is panel-agnostic: the screens described below look identical no matter which control panel got you there. The one part that differs between accounts is the size limit on imported files, and that has a section of its own with the ways around it.
**Last reviewed:** 27 July 2026, against phpMyAdmin **5.2** (latest stable series). This guide is written for Noiz hosting and is kept current against phpMyAdmin. It complements, and does not replace, the official phpMyAdmin and MySQL documentation linked below. Different control panels bundle slightly different phpMyAdmin builds, so a checkbox may sit in a marginally different place than described, but the terms and the workflow are stable across the 5.x line.
### Official Documentation Reference
- [Import and export (phpMyAdmin Documentation)](https://docs.phpmyadmin.net/en/latest/import_export.html): the reference for the Export and Import tabs, the Quick and Custom export methods, and the supported file and compression formats.
- [Configuration (phpMyAdmin Documentation)](https://docs.phpmyadmin.net/en/latest/config.html): covers the `UploadDir` setting and the options that govern the maximum size of an uploaded import.
- [MySQL server has gone away (MySQL Reference Manual)](https://dev.mysql.com/doc/refman/8.0/en/gone-away.html): the authoritative explanation of the "gone away" error and its link to `max_allowed_packet`, which large imports commonly trip over.
- [mysqldump (MySQL Reference Manual)](https://dev.mysql.com/doc/refman/8.0/en/mysqldump.html): the command-line tool to use instead of phpMyAdmin when a database is too large to move through a browser.
## Prerequisites
- You can open phpMyAdmin for your account. On ISPConfig you reach it from the **Databases** list after you [log in to the ISPConfig control panel](/ispconfig/how-to-log-in-to-the-ispconfig-control-panel/); on Plesk it is under **Databases**, and on DirectAdmin under **MySQL Management**. Whichever panel you use, the phpMyAdmin screens from that point on are the same.
- You know a database **username and password** that can access the database in question. This is the database login, not your control panel login; the two are separate.
- For an **import**, the destination database must already exist. If you are setting up a new site, create the empty database first by following [How to Create a Database and Database User in ISPConfig](/ispconfig/how-to-create-a-database-and-database-user-in-ispconfig/), then import into it. phpMyAdmin will not create the database for you unless the file you are loading contains its own `CREATE DATABASE` statement, which most exports do not.
## Exporting a Database
An export reads your live database and writes every table structure and every row into a single text file of SQL statements. That file is a complete, portable snapshot: kept somewhere safe it is a backup, and handed to another server it becomes the source for a migration.
1. In the left-hand navigation panel of phpMyAdmin, click the **name of the database** you want to export. Do not skip this: the tabs at the top behave differently depending on whether a database is selected. With a database selected, the tabs act on that database; with nothing selected, they act on the whole server.
2. Click the **Export** tab at the top.
### Quick export for a straightforward backup
Leave **Export method** on **Quick - display only the minimal options**, and leave **Format** on **SQL**. SQL is the format to use for anything you intend to load back into MySQL later; the other formats such as CSV and JSON are for handing data to spreadsheets or other programs, not for restoring a database. Click **Export** (labelled **Go** in some builds) and your browser downloads a `.sql` file named after the database. For a small or medium site this is all you need.
### Custom export for tables, compression and options
Choose **Custom - display all possible options** when you need more control. The extra options that matter most are:
- **Selecting tables.** The **Tables** box lists every table with all of them selected by default. Use **Unselect all** and then tick only the tables you want to export a part of the database, which is handy for copying a single large table or for leaving out bulky cache and log tables you do not need to keep.
- **Compression.** Under the output options, set **Compression** to **gzipped**. This produces a `.sql.gz` file that is typically five to ten times smaller than the plain `.sql`, because SQL text compresses very well. A gzipped export downloads faster, stores smaller, and, importantly, imports straight back into phpMyAdmin without you having to unzip it first. This is the single most useful habit to adopt, because it is also what lets a larger database slip under the import size limit described later.
- **Structure and data.** Leave the object creation options at their defaults. A standard SQL dump includes an **Add DROP TABLE** option; when enabled, the file drops each existing table before recreating it, so re-importing over an existing database replaces it cleanly rather than colliding with tables that are already there. That is usually what you want for a restore, but be aware it will discard the current contents of any table it recreates.
Click **Export** to download the file. Keep the downloaded file somewhere reliable and note which database and which date it came from; a backup you cannot identify later is little better than no backup at all.
## Importing a Database
An import runs the statements in a `.sql` file against a database, recreating its tables and rows. phpMyAdmin reads plain `.sql` files and compressed `.sql.gz`, `.sql.zip` and `.sql.bz2` files directly, detecting the compression from the file extension, so a gzipped export can go straight back in with no unzipping.
### Select the destination database first
This is the step people most often get wrong, and it is worth slowing down for. In the left-hand panel, click the **name of the database you want to import into** before you touch the Import tab. If you open Import while sitting at the server level with no database chosen, and the file does not name a database of its own, phpMyAdmin has nowhere to put the tables and you get a **#1046 No database selected** error. Worse, if the file was exported with a hard-coded database name, an import at the wrong level can load the tables into a database you did not intend. Selecting the correct database first removes both problems.
1. With the destination database selected, click the **Import** tab.
2. Under **File to import**, click **Browse your computer** and choose your `.sql` or `.sql.gz` file. Note the maximum size shown in brackets next to the button, for example **(Max: 50MiB)**; your file must be smaller than this. The next section deals with what to do when it is not.
3. Check **Character set of the file**. Leave it on **utf-8** for any modern export. Only change it if you know the file was created from an older database in a different character set; getting this wrong is what produces garbled accented characters after an import, covered under Troubleshooting.
4. Leave the **Format** on **SQL**.
5. Click **Import**. On a large file the page may sit for a while as it works; wait for the green success message rather than reloading, which would start the import again.
Two options on the Import page are worth knowing about:
- **Enable foreign key checks** is ticked by default. If an import fails partway through with a foreign key error, unticking this box tells MySQL not to enforce the relationships between tables while the file loads, which lets tables come in regardless of the order they appear in the file. See the foreign key note under Troubleshooting.
- **Partial import** includes an option to let phpMyAdmin pause and resume if the import gets close to the server's PHP time limit, and a field to skip a number of queries from the start. The skip field is how you resume a large import that stopped partway, by telling it to continue past the statements that already ran.
## The Upload Size Limit and How to Work Around It
Every phpMyAdmin import is capped by a maximum file size, shown on the Import page as **(Max: ...)**. That figure is set by the web server's PHP configuration, not by phpMyAdmin itself, so it varies between Noiz servers and plans. When your file is larger than the limit, the upload is rejected before any data is loaded. You have four practical ways around it, in the order most people should try them:
- **Gzip the export.** The limit applies to the size of the file you upload, and phpMyAdmin unpacks a compressed file on the server side after it arrives. A `.sql.gz` is often a fraction of the size of the plain `.sql`, so re-exporting with **Compression: gzipped** (or gzipping the file you already have) is frequently enough on its own. Always try this first.
- **Split the export into smaller files.** Use the **Custom** export to save a few tables at a time into separate files, each under the limit, then import them one after another. Selecting the destination database first, as above, keeps every piece landing in the right place.
- **Use the command line over SSH.** For a genuinely large database this is the right tool, and it sidesteps the browser limit entirely. See the next section. SSH is available on VPS, dedicated and shell-user accounts; if your plan does not include shell access, use the last option.
- **Ask Noiz to load it server-side.** On a managed plan, the Noiz support team can import a large file directly on the server, past the browser limit, if you provide the file and name the destination database. This is the simplest route when the file is very large and you would rather not touch the command line.
## When to Use the Command Line Instead
phpMyAdmin is the right tool for small and medium databases, roughly up to a few tens of megabytes. Beyond that, browser and PHP time limits start to bite, a slow upload can be cut off partway, and a single oversized statement in the file can trigger the "gone away" error described below. For large databases the command line, over an SSH connection, is faster and far more reliable because it streams the data straight into MySQL with none of the browser in the way. SSH access comes with VPS, dedicated and shell-user accounts.
To **export** a database to a file, and to a compressed file:
```
mysqldump -u dbuser -p dbname > backup.sql
mysqldump -u dbuser -p dbname | gzip > backup.sql.gz
```
To **import** a file into an existing database, from a plain dump and from a gzipped one:
```
mysql -u dbuser -p dbname < backup.sql
zcat backup.sql.gz | mysql -u dbuser -p dbname
```
Replace `dbuser` and `dbname` with your own values; the `-p` flag makes each command prompt for the database password so it never appears in your shell history. On an ISPConfig shared account, remember that both the database name and the user carry your account prefix, so the real values look like `c1dbname` and `c1dbuser`. If a command asks for a host, the database runs on the same server as your site, so the host is `localhost`. As with an import in phpMyAdmin, the destination database must already exist before you load into it.
## Getting Character Set and Foreign Keys Right
Two things quietly cause most "the import worked but the data looks wrong" complaints, and both are easy to head off.
**Character set.** A database stores text in a particular character set, and the export records which one. If you import a file using a different character set from the one it was written in, accented and non-English characters come out mangled, so `cafรฉ` becomes `cafรยฉ`. Modern sites are UTF-8, and leaving **Character set of the file** on **utf-8** is correct almost every time. The exception is an export taken from an older database that used `latin1`; for those, match the setting to the original. The safe rule is to keep the export and the import on the same character set from end to end.
**Foreign keys.** Many databases define relationships between tables, where rows in one table point at rows in another. A full export made by phpMyAdmin or `mysqldump` handles this for you by switching the checks off at the top of the file and back on at the end, so a complete restore loads cleanly. The trouble appears when you import only part of a database, or load tables in the wrong order, and a row points at another row that has not been created yet. That produces a **Cannot add or update a child row** error. Unticking **Enable foreign key checks** on the Import page lets the tables load regardless of order, after which the relationships line up once every table is present.
## Troubleshooting
- **Symptom**: the import fails with **MySQL server has gone away**. A single statement in the file was too large for the server to accept in one piece, most often a row containing a large block of data such as an image stored in the database. The controlling limit is `max_allowed_packet`. The dependable fix is to import over SSH and raise the limit for that one command, for example `mysql --max_allowed_packet=256M -u dbuser -p dbname < backup.sql`. On a shared plan where you cannot change server settings, ask the Noiz support team to load the file for you. This error is one of the clearest signs that a database has outgrown browser-based import.
- **Symptom**: the file is bigger than the **(Max: ...)** figure and will not upload. Gzip the export so the uploaded file is smaller, split it into several smaller files, import over SSH, or ask Noiz to load it server-side, as set out in the size-limit section above.
- **Symptom**: **#1046 No database selected**. You started the import without choosing a database. Click the destination database in the left-hand panel first, then reopen the Import tab and try again.
- **Symptom**: accented or non-English characters appear garbled after the import, such as `รยฉ` in place of `รฉ`. The character set chosen for the import did not match the one the file was written in. Re-import the same file with **Character set of the file** set to match the original database, which for older data is often `latin1` rather than `utf-8`.
- **Symptom**: **Cannot add or update a child row: a foreign key constraint fails**. Tables are loading in an order that breaks the links between them, which happens with partial imports. Untick **Enable foreign key checks** on the Import page and import again.
- **Symptom**: a large import stops partway with a timeout and only some tables arrive. The server's PHP time limit was reached before the file finished. Import a gzipped copy to move less data over the wire, use the **Partial import** skip field to resume past the statements that already ran, or switch to the command line, which has no such time limit.
- **Symptom**: phpMyAdmin rejects the database username and password. Use a database user with access to the database, not your control panel login; the two are different. On ISPConfig the database user includes your account prefix, for example `c1dbuser` rather than `dbuser`.
If an export or import will not go through, or a database is simply too large to move comfortably through a browser, open a support ticket with the Noiz support team. Tell them the database name, whether you are exporting or importing, and the exact error message, and attach the file if you have one. On a managed plan the team can run the transfer directly on the server for you. Never include a database password in a ticket.
# How to Optimize a Database in phpMyAdmin
Source: https://docs.noiz.ie/databases/how-to-optimize-a-database-in-phpmyadmin/
Optimizing a database rebuilds its tables so that the space left behind by deleted and updated rows is reclaimed and the index statistics are refreshed. In phpMyAdmin this is a few clicks on the **Structure** page of a database, and it runs the same `OPTIMIZE TABLE` statement you would issue from the MySQL command line. You may also see it described as defragmenting a database, clearing overhead, or repairing table bloat; they all refer to the same operation.
This guide applies to any Noiz hosting account that offers phpMyAdmin, whichever control panel your account uses. The phpMyAdmin screens themselves are identical; only the icon you click to launch it differs between panels.
**Last reviewed:** 27 July 2026, against phpMyAdmin **5.2.3** (latest stable). This guide is written for Noiz hosting and is kept current against phpMyAdmin. It complements, and does not replace, the official phpMyAdmin and MySQL/MariaDB documentation linked below.
### Official Documentation Reference
- [phpMyAdmin documentation (docs.phpmyadmin.net)](https://docs.phpmyadmin.net/en/latest/)
- [MySQL Reference Manual: OPTIMIZE TABLE (dev.mysql.com)](https://dev.mysql.com/doc/refman/8.4/en/optimize-table.html)
- [MariaDB Knowledge Base: OPTIMIZE TABLE (mariadb.com)](https://mariadb.com/kb/en/optimize-table/)
## Prerequisites
- Access to your hosting control panel (your Noiz welcome email contains the login details).
- A database on the account, and a database user with `SELECT` and `INSERT` privileges on the tables you want to optimize. The user created alongside the database normally has these already.
- A recent database backup. Optimizing rebuilds each table, so take a copy first if the site is live and busy.
## Optimize a database in phpMyAdmin
### 1. Open phpMyAdmin
Log in to your hosting control panel and, in the **Databases** section, click **phpMyAdmin**. Your panel signs you in automatically, so there is no separate phpMyAdmin password to remember.

### 2. Open the database you want to optimize
In the navigation panel on the left, click the expand arrow next to the database name (or click the database name itself) to open it. phpMyAdmin loads the **Structure** tab, listing every table in that database.
If the account holds several databases, check the name carefully before going further. Databases created through a control panel are usually prefixed with the account username, for example `youracct_wp001`, and the prefix is the quickest way to tell one site's database from another.

### 3. Select the tables and choose Optimize table
Scroll to the bottom of the table list and click **Check all**. In the **With selected:** drop-down immediately to the right of it, choose **Optimize table**. phpMyAdmin runs the statement straight away; there is no extra confirmation prompt.
You do not have to do the whole database. Ticking only the tables that show a figure in the **Overhead** column is often the better choice, because those are the only tables with space to reclaim. The summary row at the foot of the Structure page adds up the total overhead for the database, which is a useful before-and-after measure.

### 4. Read the results
phpMyAdmin returns a result row per table. A **status** of `OK` means the table was rebuilt successfully and the database is optimized.
On InnoDB tables, which is the default storage engine on current MySQL and MariaDB servers, you will also see a **note** reading `Table does not support optimize, doing recreate + analyze instead`. This is expected and is not an error. InnoDB maps `OPTIMIZE TABLE` to a table rebuild that reclaims free space in the clustered index and refreshes the index statistics, which is exactly what was wanted. As long as the status line says `OK`, the work was done.
## When optimizing actually helps
Optimizing is worth doing after a large clear-out, not on a schedule for its own sake. Typical triggers are deleting thousands of post revisions, spam comments, expired transients, old orders, log rows, or session records. Deleting rows marks the space as reusable inside the table file but does not hand it back to the operating system; the rebuild is what actually returns it.
Two points are worth knowing before you expect a large drop in disk usage:
- **Delete first, then optimize.** Optimizing a table that still contains all its data will not shrink it. Clear the unwanted rows, then run the optimize pass.
- **Space is returned to the filesystem only when each table has its own data file.** Modern MySQL and MariaDB installations enable `innodb_file_per_table` by default, which is the case on Noiz shared hosting, so a rebuild does release the space back to the account's disk quota.
Routine daily or weekly optimizing is unnecessary and, on a large database, counterproductive: each pass rewrites the entire table. Once after a significant purge is the sensible cadence.
## Troubleshooting
**The page times out or the browser gives up on a large table**: the statement continues running on the database server even though the browser connection has dropped. Wait a few minutes, reload the Structure page and check whether the overhead figure has fallen, rather than firing the optimize off a second time. For very large tables, optimize them one at a time instead of using **Check all**.
**The result says the storage engine does not support optimize**: some engines, such as MEMORY, have no rebuild operation. There is nothing to fix and nothing to reclaim on those tables.
**An access denied or privileges error appears**: the database user you are connected as is missing `SELECT` or `INSERT` on that table. Reassign the user to the database with full privileges in your control panel's database section, then try again.
**Disk usage did not drop afterwards**: check that the rows were genuinely deleted, and check whether the space is being used by something else in the account entirely, such as backups, mailboxes, or an error log, rather than by the database.
**The site is slow and optimizing made no difference**: table overhead is rarely the real cause of a slow site. Missing indexes, an unbounded query, an overloaded plugin, or an oversized options or postmeta table are far more common. Optimizing tidies storage; it does not rewrite a slow query.
## Need a hand?
If you are on a managed Noiz plan and would rather Noiz optimize a database, investigate why one is growing, or look at slow queries behind a sluggish site, contact the Noiz support team through the client area and the team will assist.
# How to Repair a Database in phpMyAdmin
Source: https://docs.noiz.ie/databases/how-to-repair-a-database-in-phpmyadmin/
**phpMyAdmin** is the web-based manager for MySQL and MariaDB databases that ships with every Noiz hosting control panel. Its **Repair table** operation rebuilds a table's index and data files after they have been left in an inconsistent state, which is the standard fix for a site throwing errors such as "Table is marked as crashed and should be repaired". This guide shows you how to run it, and just as importantly, how to tell whether it will do anything at all for your database.
The single most useful thing to know before you start: **Repair table only works on MyISAM tables** (and the rarely used ARCHIVE and CSV engines). Modern databases almost always use InnoDB, and InnoDB does not support this operation. Running Repair on an InnoDB table is harmless but pointless, and it will simply report that the storage engine does not support repair. The section below on identifying your storage engine tells you which situation you are in before you spend time on it.
**Last reviewed:** 27 July 2026, against phpMyAdmin **5.2.3** (latest stable, released 8 October 2025), MySQL **8.4 LTS** and MariaDB **11.4 LTS**. This guide is written for Noiz hosting and is kept current against phpMyAdmin. It complements, and does not replace, the official phpMyAdmin and MySQL documentation linked below.
### Official Documentation Reference
- [phpMyAdmin User Guide (docs.phpmyadmin.net)](https://docs.phpmyadmin.net/en/latest/user.html)
- [MySQL 8.4 Reference: REPAIR TABLE statement](https://dev.mysql.com/doc/refman/8.4/en/repair-table.html)
- [MySQL 8.4 Reference: CHECK TABLE statement](https://dev.mysql.com/doc/refman/8.4/en/check-table.html)
- [MariaDB Knowledge Base: REPAIR TABLE](https://mariadb.com/kb/en/repair-table/)
- [MySQL 8.4 Reference: Forcing InnoDB Recovery (for genuinely corrupt InnoDB data)](https://dev.mysql.com/doc/refman/8.4/en/forcing-innodb-recovery.html)
## Prerequisites
- Access to your hosting control panel (your Noiz welcome email contains the login details).
- The name of the database the application actually uses. For WordPress this is the `DB_NAME` value in `wp-config.php`.
- A current backup, or a few minutes to take one in step 2 below. A repair rebuilds files in place, and in a small number of cases it discards rows it cannot recover.
## Step 1: Open phpMyAdmin
phpMyAdmin is reached from your control panel, so you are already authenticated and do not need to enter database credentials separately. Depending on which Noiz platform your account sits on, the route differs slightly, but the destination is the same application:
- **Plesk**: open **Databases**, find the database in the list, then click **phpMyAdmin** next to it.
- **DirectAdmin**: open **Account Manager** or **Databases**, then click the **phpMyAdmin** link.
- **ISPConfig**: open **Sites**, then **Database**, and use the phpMyAdmin link on the database entry.
- **Any other panel**: look for a **Databases** section, then the **phpMyAdmin** entry inside it.
The screenshots below were taken on an older panel build, but every step from the moment phpMyAdmin opens is identical on all of them.

## Step 2: Back Up the Database First
A repair is a rebuild, not an undo. If the table is badly damaged, the rebuild can drop the rows it cannot make sense of, and there is no way to get them back afterwards.
In phpMyAdmin, select the database in the left sidebar, click the **Export** tab at the top, leave the export method on **Quick** with the format set to **SQL**, and click **Export**. The `.sql` file downloads to your computer. Keep it until you have confirmed the site is working again.
If the table is so damaged that the export itself fails, stop and contact the Noiz support team rather than repairing blind. A server-side copy of the raw database files taken before any repair gives you far more options than a failed export does.
## Step 3: Expand the Database in the Navigation Tree
The left sidebar lists every database your account can reach. Click the arrow beside the database name (or the name itself) to expand it and reveal its tables.

If more than one database is listed, pick carefully. A single hosting account often holds databases for several sites, plus leftovers from old installs. For WordPress, the correct one is the value of `DB_NAME` in the site's `wp-config.php` file, which you can open in File Manager.
## Step 4: Check Which Storage Engine the Tables Use
With the database selected, the main panel lists every table with its row count, **Type** (the storage engine), collation and size. Look at the **Type** column before you do anything else:
- **MyISAM**, **ARCHIVE** or **CSV**: Repair table applies, and the rest of this guide is what you want.
- **InnoDB**: Repair table does not apply. Skip to the InnoDB section below.
Mixed databases are common on older sites, particularly ones that have been migrated between hosts over the years. You may find a handful of legacy MyISAM tables sitting alongside InnoDB ones in the same database.
If you want to confirm damage rather than assume it, select the tables and choose **Check table** from the same drop-down used in step 5. A healthy table returns `OK`. A damaged one returns a message such as `Table is marked as crashed`, which tells you a repair is genuinely warranted rather than a guess.
## Step 5: Select the Tables and Run Repair
Scroll to the bottom of the table list and click **Check All** to select every table, or tick only the specific tables you want if you have already identified them. Then open the **With selected:** drop-down beneath the list and choose **Repair table**.

phpMyAdmin runs the operation immediately, with no confirmation prompt, and returns a results grid listing every table it touched.
## Step 6: Read the Results
Each row in the results grid shows the table name, the operation, a message type and the message itself:
- **status / OK**: the table is fine, either because it was never damaged or because the repair succeeded.
- **note / The storage engine for the table doesn't support repair**: an InnoDB (or similar) table. This is expected and is not an error. See the next section.
- **warning** followed by a row count: the repair completed but discarded rows it could not recover. Compare the count against your backup to see what was lost.
- **error**: the repair could not complete. Note the exact wording and move to the troubleshooting section.
Reload the affected site afterwards. An `OK` from a repair means the table structure is now consistent, which is not quite the same as the application working again, so verify the actual symptom has gone.
## If Your Tables Are InnoDB
InnoDB has been the default engine since MySQL 5.5, so unless the database is genuinely old or was created by an application that insists on MyISAM, this is what you will be looking at. InnoDB has no equivalent of the MyISAM repair, and it does not need one in normal operation, because it keeps a write-ahead log and replays it automatically the next time the database service starts. A power cut or an unclean shutdown is repaired without anyone asking it to.
Three practical points follow from that:
- **Running Repair table on InnoDB does nothing and harms nothing.** You get a note back, and the table is untouched. There is no need to avoid it out of caution.
- **What you probably want is `OPTIMIZE TABLE`.** If your actual complaint is a bloated or slow table rather than a crashed one, the **Optimize table** option in the same drop-down rebuilds the table and reclaims space. On InnoDB, phpMyAdmin maps it to a rebuild that achieves the same result.
- **Genuine InnoDB corruption is a server-level job.** Recovering it involves the `innodb_force_recovery` setting in the server configuration, which cannot be reached from phpMyAdmin and is not available to hosting accounts. If you are seeing InnoDB corruption errors in your site logs, raise a ticket with the Noiz support team and include the exact error text.
## When a Repair Is and Is Not the Answer
Repair fixes damage to the table's own files. It cannot fix problems that live in the data itself.
**A repair is the right tool when** you see errors naming a specific table, such as "Table './dbname/wp\_options' is marked as crashed and should be repaired", "Incorrect key file for table", or "Can't open file: 'wp\_posts.MYI'". These follow an unclean shutdown, a disk that filled up, or a process killed mid-write.
**A repair will not help when** the site is slow, a plugin is misbehaving, a login fails, content has been deleted, or the database connection is refused outright. Those are application, permission or configuration problems. Repeatedly repairing a healthy table in the hope that something changes only costs you time.
If the same table keeps crashing after being repaired, treat that as a signal rather than a nuisance. Recurring MyISAM corruption usually points to the disk filling up, the database service being killed under memory pressure, or a table large enough to be running into MyISAM's limits. In every one of those cases the durable fix is converting the table to InnoDB, which tolerates unclean shutdowns by design.
## Converting a Repeatedly Crashing Table to InnoDB
If a MyISAM table crashes more than once, converting it is usually the better answer than repairing it again. Take an export first, then open the **SQL** tab and run:
```
ALTER TABLE wp_options ENGINE=InnoDB;
```
Replace `wp_options` with your own table name. Convert one table at a time and test the site in between. A small number of older applications rely on MyISAM behaviour such as full-text search on legacy MySQL versions, so check the application's requirements before converting everything in the database.
## Troubleshooting
**Symptom**: The result says "The storage engine for the table doesn't support repair". The table is InnoDB. This is not a failure. See the InnoDB section above.
**Symptom**: The repair returns an error mentioning a temporary file or disk space. The repair needs room to build a new copy of the table alongside the original, so a table close to your disk quota cannot be repaired until you free space. Clear old backups, logs and cache directories, then try again.
**Symptom**: The repair reports "Table is in use" or appears to hang. Another process is writing to the table. Put the site into maintenance mode, or stop whatever cron job or import is running, then retry.
**Symptom**: The repair reports lost rows. Open your export from step 2, find the rows that are missing, and reinsert only those. Reimporting the entire file over a repaired table risks bringing the damage back with it.
**Symptom**: The page times out on a large table. Repairs on multi-gigabyte tables can outlast the web request. Run it on one table at a time rather than using **Check All**, and if it still times out, raise a ticket so the operation can be run directly on the server without a browser timeout in the way.
**Symptom**: The site still shows a database error after a successful repair. The error is coming from something other than table damage. Check the exact error text in the site's log: a connection error points at credentials or the database service, whereas a missing table or column points at an incomplete update or migration.
## Related Guides
- [How to Export a Database in phpMyAdmin](/databases/how-to-export-a-database-in-phpmyadmin/)
- [How to Import a Database in phpMyAdmin](/databases/how-to-import-a-database-in-phpmyadmin/)
- [How to Edit a Database Table in phpMyAdmin](/databases/how-to-edit-a-database-table-in-phpmyadmin/)
## Need a hand?
A crashed database table on a live site is stressful, and the wrong move at that point can turn a recoverable problem into a restore. If you are on a managed Noiz plan, or you are unsure whether repairing is safe with the data you have, contact the Noiz support team through the client area with the exact error text and the database name, and the team will take it from there.
# How to Check If a Domain Name Is Available
Source: https://docs.noiz.ie/domains-dns/how-to-check-if-a-domain-name-is-available/
This guide shows you how to find out whether the domain name you want is free to register, how to make sense of the result the search gives back, and what your options are when the name you had your heart set on turns out to be taken. It is written for anyone about to start a website or a business online, from a first-time registrant looking for a `.co.za` address to someone comparing a handful of extensions for a brand. Along the way it explains a few terms you will meet: a domain that is free to register is **available**; one that someone already owns is **taken** or **registered**; a **premium** domain is available but priced above the standard rate by the registry; and a **WHOIS** (or, in its modern form, **RDAP**) record is the public registration record you can read on a taken domain to see who holds it and when it expires. The most useful skill this article teaches, and the one you will not find in a registrar's checkout flow, is how to read that record so you can judge whether a taken name might soon become free.
**Last reviewed:** 27 July 2026. Domain availability is decided by the registries that run each extension: ICANN-accredited registries for global names such as `.com`, `.org` and `.net`, and the ZA Registry Consortium (ZARC) for South Africa's `.co.za`, `.org.za`, `.net.za` and `.web.za`. This guide is written for Noiz hosting and is kept current against those registries' published policies and the Noiz client area. It complements, and does not replace, the official references linked below. Registry lifecycle timings, pricing tiers and the WHOIS-to-RDAP transition can change over time; where a figure could shift it is flagged as approximate so you can confirm the current value before you rely on it.
### Official Documentation Reference
- [ICANN Lookup](https://lookup.icann.org/): the authoritative public tool for the registration data of global (gTLD) domains such as `.com`, `.org` and `.net`. It returns RDAP data, the successor to classic WHOIS, and is the neutral place to confirm a taken domain's dates and status.
- [EPP Status Codes (ICANN)](https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en): explains the status codes you see on a registration record, such as `clientTransferProhibited`, `redemptionPeriod` and `pendingDelete`, which are the clearest signal of whether a taken domain is about to be released.
- [IANA Root Zone Database](https://www.iana.org/domains/root/db): the definitive list of every top-level domain in existence, useful when you are weighing up an alternative extension and want to know it is real and delegated.
- [ZA Registry Consortium (ZARC)](https://zarc.web.za/): the registry operator for South Africa's second-level domains including `.co.za`. Its lookup and policies are the authority for availability, expiry and lifecycle of `.co.za` names, which the global ICANN tools do not cover.
## Prerequisites
- You have one or more candidate names in mind. If you are still deciding what to call your site, work that out first with [How to Choose a Domain Name](/domains-dns/how-to-choose-the-right-domain-name-for-your-website/), then come back here to check whether your shortlist is free.
- You can reach the Noiz website domain search, or you can sign in to the Noiz client area. Checking availability needs neither an account nor payment; you only need an account when you decide to register.
- You understand that availability is a live, moving thing. A name that is free this minute can be registered by someone else a minute later, because domains are first come, first served. Checking a name does not reserve it; only completing registration does.
## What "Available" Actually Means
A domain name is a single, globally unique label. No two people can hold `yourdomain.com` at the same time, so at any given moment a name is in exactly one of a few states. Knowing them makes the search result far easier to read.
| Result | What it means | Can you register it? |
| --- | --- | --- |
| **Available** | Nobody currently holds this exact name on this extension. | Yes, at the standard price, if you act before anyone else. |
| **Taken** (registered) | Someone already owns it. It has an active registration record. | Not directly. See the options for a taken name below. |
| **Premium** | Available to register, but the registry has classed it as high value (often a short or common word) and set a higher price. | Yes, but usually at a premium registration price and sometimes a premium renewal price too. |
| **Reserved or restricted** | The registry or authority holds the name back, or the extension requires you to meet a condition (for example a local presence) to register it. | Only if you meet the extension's rules, if at all. |
One point trips people up more than any other: availability is checked per extension, not per word. `yourbrand.co.za` being taken tells you nothing about whether `yourbrand.com`, `yourbrand.africa` or `yourbrand.shop` is free. Each extension is its own namespace with its own registry, so a search always answers "is this exact name on this exact extension free", and no more.
## Checking Availability with the Noiz Domain Search
The quickest way to check a name is the domain search on the Noiz website. It queries the relevant registry live and comes back in seconds.
1. Go to the domain search on the Noiz website and type the name you want. You can type it with or without the extension. Entering just `yourbrand` lets the search check several extensions at once, while entering `yourbrand.co.za` checks that one exact name.
2. Start the search. The tool asks the registry whether the name is registered and reports back.
3. Read the result for your exact name, then glance down at the suggestions and the other extensions it offers, which are covered in the next section.
You can run exactly the same search from inside the Noiz client area, under **Domains** and then **Register a New Domain**. The client-area search is the one to use when you have already decided to buy, because an available result there leads straight into the registration flow described later in this guide. The two searches query the same registries and return the same answer; the only difference is that the client-area version is wired up to your cart.
## Reading the Results
A domain search gives you more than a yes or no. Learning to read the whole result saves you a second search and often hands you a better name than the one you started with.
### Available
An available result means the exact name is free right now and shows you the registration price, usually per year. This is the moment to act if you are sure, because nothing is holding the name for you. If you are comparing options, note that the price shown is the registration price; check the renewal price too, since some extensions and especially premium names renew at a different rate to the first year.
### Taken
A taken result means the name is already registered to someone. The search will not let you add it to your cart. This is not the end of the road: the sections below cover switching extension, picking from the suggestions, and reading the domain's record to see when it expires and whether it is likely to be released.
### Premium
A premium result is available but carries a higher, registry-set price because the name is short, memorable or a dictionary word. There is nothing wrong with a premium domain; the name is real and yours to register if the price suits you. Just read the figures carefully, because a premium name sometimes has both a premium first-year price and a premium annual renewal, so the cost is ongoing rather than a one-off.
### Suggestions and other extensions
When your first choice is taken or premium, the search offers two kinds of alternative. It lists the **same name on other extensions** that are free, for example offering `yourbrand.africa` or `yourbrand.net` when `yourbrand.com` is gone, and it lists **suggested variations** that combine your word with related terms or a different structure. Treat these as a starting point rather than a final answer. A good alternative extension often reads better for a local audience anyway: for a South African business, `.co.za` signals a local presence that a global `.com` does not.
## What to Do When the Name Is Taken
Most memorable names on the older extensions are already registered, so a taken result is common and rarely a dead end. Work through these options in order.
### Try a different extension
The fastest fix is to keep your name and change the ending. The number of available extensions is large and still growing, from country codes like `.co.za` to newer general-purpose ones like `.shop`, `.online` or `.africa`. If you are unsure what an extension is or which suits you, [What Is a TLD](/domains-dns/what-is-a-tld-top-level-domain/) explains the different kinds and how to choose between them, and the IANA Root Zone Database linked above lists every real extension. For a South African audience, `.co.za` is the natural and most-searched choice, and it is frequently free even when the matching `.com` is taken.
### Adjust the name itself
A small change can free up a name without losing its meaning. Add a short, relevant word (your city, your sector, or a word like `get` or `go`), or drop a hyphen or filler word. Keep it easy to say aloud and to type, and avoid hyphens and numbers where you can, since they cause confusion when a name is spoken or dictated over the phone.
### Check when it expires, and whether it might be released
Before you give up on a taken name, look at its registration record. Every registered domain has a public record you can read, and it tells you the expiry date and the domain's current status. If the name is a year or more from expiry and locked in the normal way, it is not going anywhere soon. If it is close to expiry or already showing a status like `redemptionPeriod` or `pendingDelete`, it may be on its way to being released. Reading that record is the subject of the next two sections, and it is the single most useful thing you can do before deciding whether a taken name is worth pursuing.
### Consider a backorder
If a taken name is close to being released, a **backorder** is a service that queues an attempt to register it the instant it becomes available again. A backorder is not a guarantee. If more than one party wants the same dropping name, it can go to whoever the process favours or to an auction, and many expiring names are simply renewed by their owner and never drop at all. Treat a backorder as a bet on a name that looks likely to expire, not as a reservation. If you want to pursue a specific taken domain that is near its expiry date, contact the Noiz support team to talk through what is possible for that extension.
### Approach the current owner
For a name that is registered and staying registered, the only remaining route is to ask the owner whether they will sell. The registration record often shows enough to make contact, though as explained below much of the personal detail is now hidden for privacy. This is a longer and less certain path, and a name held by an active owner can be expensive or simply not for sale, so weigh it against a good alternative extension before spending time on it.
## Reading a WHOIS or RDAP Record on a Taken Domain
This is the part that turns a flat "taken" into useful information. Every registered domain publishes a registration record. The older protocol behind it is called **WHOIS**; it is being retired in favour of **RDAP** (Registration Data Access Protocol), which returns the same core facts in a cleaner, standardised form. You may still see the word WHOIS used loosely for any such lookup. For global extensions like `.com`, look a name up with [ICANN Lookup](https://lookup.icann.org/). For `.co.za` and the other `.za` second-level names, use the ZARC lookup, because the global ICANN tools do not hold South African registry data.
A typical record for a global domain, with the personal contact fields redacted as they now are by default, looks like this (the values are an example; the domain here is shown hosted on Noiz):
```
Domain Name: YOURDOMAIN.COM
Registry Expiry Date: 2027-06-02T13:45:07Z
Creation Date: 2014-06-02T13:45:07Z
Updated Date: 2026-03-14T09:20:11Z
Registrar: Example Registrar (Pty) Ltd
Domain Status: clientTransferProhibited
Name Server: NS1.NOIZ.CO.ZA
Name Server: NS2.NOIZ.CO.ZA
Registrant Organization: REDACTED FOR PRIVACY
Registrant State/Province: Western Cape
Registrant Country: ZA
Registrant Email: Please query the RDDS service of the registrar of record
DNSSEC: unsigned
```
Read it field by field and it tells a clear story:
- **Registry Expiry Date** is the field that matters most when you are eyeing a taken name. It is the date the current registration lapses unless the owner renews. A date years away means the name is settled; a date within the next month or two, combined with the right status, is what makes a name worth watching.
- **Creation Date** tells you how long the name has been registered. A name held continuously for a decade is far less likely to be dropped than one registered recently.
- **Updated Date** is when the record last changed, for example at a renewal or a nameserver change. A very recent update near an expiry date often means the owner just renewed, so the name is not about to drop.
- **Registrar** is the company through which the domain is registered. It is not the owner, and it is not where the site is hosted.
- **Domain Status** is the set of EPP status codes on the name, explained in the table below. This is your clearest read on whether a name is locked, expiring or being released.
- **Name Server** lines show which DNS servers answer for the domain. Seeing `NS1.NOIZ.CO.ZA` and `NS2.NOIZ.CO.ZA` here would tell you the domain uses Noiz nameservers, which is how a domain registered anywhere is pointed at hosting on Noiz.
- **Registrant fields** are the owner's details. Since data-protection rules took effect, the personal parts (name, email, phone) on most global domains are redacted and replaced with a privacy message or a relay address, while non-personal fields such as country and sometimes province still appear. The absence of a name is normal and does not mean the domain is unregistered.
### The status codes that tell you a name might free up
The status codes are the difference between guessing and knowing. Most are routine locks that simply mean the domain is registered and protected. A few tell you the name is in the process of expiring. These are the ones worth recognising:
| Status you may see | What it tells you | Bearing on availability |
| --- | --- | --- |
| `ok` or `active` | The normal, healthy state of a registered domain. | Registered and not expiring. Not becoming free. |
| `clientTransferProhibited`, `clientUpdateProhibited`, `clientDeleteProhibited` | Standard registrar locks that protect the name from unauthorised changes. | These are a sign of a normal, cared-for registration, not of a name about to drop. |
| `autoRenewPeriod` | The name recently passed its expiry date and was auto-renewed; the owner can still cancel within a short grace window. | Just expired on paper, but almost always kept. Do not count on it dropping. |
| `redemptionPeriod` | The registration was deleted and is in a recovery window where only the former owner can restore it, usually for an extra fee. | On its way out, but the owner can still pull it back. Not yet available. |
| `pendingDelete` | The recovery window has closed and the name is queued for release. | The strongest signal a name is about to become available. It typically drops within a few days. |
The [ICANN EPP status codes reference](https://www.icann.org/resources/pages/epp-status-codes-2014-06-16-en) lists the full set and their exact meanings. For `.co.za` the underlying idea is the same, though the exact status names and the length of each window are set by ZARC and can differ from the global gTLD pattern, so confirm current `.co.za` timings on the ZARC site rather than assuming the figures above.
## The Life of a Domain, and When a Taken Name Becomes Free
A taken name does not flip to available the moment it expires. It moves through a lifecycle, and knowing the shape of it tells you how long you might wait, and when. The stages below are the general pattern for global (gTLD) domains; the windows are approximate and set by each registry, and `.co.za` follows its own ZARC-defined version of the same idea.
1. **Registered.** The name is held and renewing normally. Nothing happens here for you.
2. **Expiry and grace.** After the expiry date the owner usually still has a grace period, often up to around 45 days for global domains, to renew at the normal price. Most expired names are renewed in this window and never go further.
3. **Redemption period.** If still not renewed, the name enters a redemption window, commonly about 30 days, where only the former owner can recover it, and only by paying a redemption fee. It is not available to you during this time. This is the `redemptionPeriod` status.
4. **Pending delete.** When redemption ends without recovery, the name sits in a short pending-delete window, often around 5 days, from which it cannot be saved. This is the `pendingDelete` status.
5. **Released.** At the end of pending delete the name is released and becomes available to register again, usually first come, first served, though some sought-after names are picked up instantly by a backorder or sent to auction.
The practical takeaway: a name showing an expiry date next week is not free next week; realistically it is two to three months from release even in the best case, and only if the owner lets every stage lapse. If you see `pendingDelete`, release is close. Anything earlier is a wait, and a bet that the owner keeps letting it slide.
## Registering the Domain Through the Noiz Client Area
Once your search shows a name available, registering it is a short flow in the client area. This is a high-level walk-through; the detailed billing and payment steps are covered separately, and the aim here is to show you the shape of it and the two or three choices that matter.
1. **Search and add.** From the Noiz website or the client area under **Domains** and **Register a New Domain**, search your name and add the available result to your cart. Premium names can be added the same way, at the premium price shown.
2. **Choose the term.** Pick how many years to register for. Some extensions allow multiple years up front, which spares you an early renewal and, on `.co.za`, is worth doing for a name you intend to keep.
3. **Set the nameservers.** If you are hosting the site with Noiz, point the domain at the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za`. This is what links the name to your hosting so your website and email work. If you are not ready to decide, you can accept the default and change the nameservers later.
4. **Enter the registrant details.** Provide accurate contact details for the registrant. For global domains these must be genuine; false registration data can put the domain at risk of suspension. Where the extension offers WHOIS privacy or ID protection, you can enable it here to keep your personal contact details out of the public record while still meeting the accuracy requirement.
5. **Review and check out.** Confirm the name, term and price, then complete checkout in the client area. Payment methods are handled in the billing section of the client area.
One step catches new registrants out: for most global domains you must **verify the registrant email address** after you register. Noiz sends a verification link to the registrant email, and if it is not confirmed within the required window (15 days for gTLDs under the current rules), the domain can be suspended even though you paid for it. Watch for that email, click the link, and your registration is complete. A `.co.za` registration does not use the same email verification step, so this one applies mainly to `.com`, `.org`, `.net` and other global names.
## Troubleshooting
- **Symptom: the search says a name is taken, but the website for it does not load.** A registered domain with no live website is completely normal. Many names are held for a brand, parked, or simply registered and unused. The absence of a working site does not make the name available; only the registration record and its status tell you that. Look the name up as described above rather than judging by whether a page loads.
- **Symptom: a name showed as available, and now it will not add to the cart.** Availability is live and names are first come, first served. Someone may have registered it in the minutes between your searches, or it may be a premium name that needs a different step. Re-run the search to see the current state, and if you have found the perfect name, register it promptly rather than sleeping on it.
- **Symptom: the registration record shows no owner name or email.** This is expected. Personal registrant details on most global domains are redacted for privacy, leaving only non-personal fields and, often, a relay address or a message pointing you to the registrar. It does not mean the domain is free or abandoned.
- **Symptom: a premium price looks far higher than a normal domain.** The name has been classed as premium by the registry, not by Noiz. Check whether the premium applies only to the first year or to renewals as well, and if the ongoing cost does not suit you, a standard-priced alternative extension or a slight variation of the name will serve you better.
- **Symptom: an ICANN lookup returns nothing for a `.co.za` name.** The global ICANN tools only cover ICANN-managed extensions such as `.com`. For `.co.za` and other `.za` names, use the ZARC lookup instead, which is the registry that actually holds those records.
## Noiz Support
If you have found a name you want and are not sure whether an alternative extension or a slight variation would serve you better, or you are trying to judge whether a taken name is genuinely worth waiting for, the Noiz support team can help you read the registration record and weigh up the options before you commit. If you want to pursue a specific taken domain that is close to expiry, or you would like a backorder placed on a name that looks likely to drop, open a ticket with your candidate names and Noiz will tell you what is realistic for that extension. When your name is available and you are ready, the Noiz client area takes you from search to registered in a few minutes, and the team is on hand if any part of the registration or verification does not go through cleanly.
# How to Choose the Right Domain Name for Your Website
Source: https://docs.noiz.ie/domains-dns/how-to-choose-the-right-domain-name-for-your-website/
Your domain name is the one part of your website you are most likely to keep for years, print on business cards, read out over the phone, and never be able to change without cost and disruption. This guide helps you choose a domain name you will not regret: one that is memorable, easy to say and spell, legally safe, and right for your audience. It is written for anyone about to register a domain through Noiz, whether you are a South African business weighing `.co.za` against `.com`, a personal brand, or an international project. You will finish with a clear shortlist and a decision checklist you can act on.
A domain name is made of two parts you can choose and one you cannot. In `yourbusiness.co.za`, the **top-level domain** (the `.co.za` ending) is chosen from a fixed public list, the **second-level label** (`yourbusiness`) is the name you invent, and anything before it, such as `www` or `shop`, is a subdomain you can add later for free. This article is about getting the second-level label and the top-level domain right, because those are the two decisions you commit to at registration.
**Last reviewed:** 27 July 2026. The list of available top-level domains, South African `.za` registration rules, and naming conventions all change over time, so this guide is kept current against the authoritative registries and standards bodies listed below. It gives Noiz-specific guidance and complements, and does not replace, those sources.
### Official Documentation Reference
- [IANA Root Zone Database](https://www.iana.org/domains/root/db): the authoritative, complete list of every top-level domain in existence, both generic (`.com`, `.shop`) and country-code (`.za`, `.uk`). Use it to confirm a TLD is real before you plan around it.
- [.ZA Domain Name Authority (ZADNA)](https://www.zadna.org.za): the statutory regulator of South Africa's `.za` namespace, and the definitive source on the second-level domains such as `.co.za`, `.org.za` and `.net.za` and the rules that govern them.
- [CIPC Trade Marks (South Africa)](https://www.cipc.co.za/?page_id=3752): the Companies and Intellectual Property Commission runs the South African trade marks register and a free basic online search, which you should use before you commit to a brandable name.
- [WIPO Domain Name Dispute Resolution](https://www.wipo.int/amc/en/domains/): the global authority on cybersquatting disputes and the UDRP process, worth understanding so you never register a name that someone else has the legal right to take from you.
## Before You Start
- A rough idea of what the site is for and who it is for, because the right name for a local shop is not the right name for a global software product.
- A few candidate names in mind, or at least a direction: a brand name you have invented, your own or your company's existing name, or a description of what you do.
- A way to write down a shortlist. You will test several names against the criteria below and keep the survivors, rather than falling in love with the first idea.
## What Makes a Domain Name Work
Before comparing specific names, know what you are aiming for. A strong domain name shares a short list of qualities, and every good name below is really just these qualities applied.
### Short and memorable
Shorter names are easier to remember, quicker to type, and less prone to mistakes. There is no hard rule, but aim to keep the second-level label under about 15 characters and, ideally, to two or three syllables. A name someone can recall a day after hearing it once is worth far more than a clever name they have to look up.
### Easy to say and easy to spell
Apply the **radio test**: say the full domain out loud, as if reading it to someone over the phone, and ask whether they could type it correctly without you spelling it. If a name forces you to say "that's spelled with a Z, no hyphen, two Ls", it will cost you visitors every day. Avoid words people spell in more than one way, invented spellings that drop or swap letters, and anything that sounds like a different word when spoken.
### Brandable rather than generic
A brandable name is distinctive enough to own and to grow into. Made-up or unexpected words (think of the well-known invented brand names) are memorable and easy to protect, whereas a bag of generic keywords blends in with every competitor. A distinctive name also gives you a far better chance of registering matching trademarks and social handles, which a generic phrase rarely allows.
## Keywords Versus a Brand Name
A common instinct is to stuff the domain with the words people search for, on the theory that `bestcheapplumberjohannesburg.co.za` will rank higher. This is one of the most persistent myths in choosing a domain, and it is worth dispelling clearly.
Search engines long ago stopped treating a keyword in the domain as a meaningful ranking signal on its own. An exact-match keyword domain gives you no reliable SEO advantage today, and the long, awkward names it produces are hard to remember, hard to say, and look untrustworthy. Rankings are earned by good content, a fast and secure site, and genuine links, not by the letters in your domain.
That does not make a descriptive word useless. A single, natural keyword paired with a brandable element can be an excellent compromise, for example `brightpaints.co.za` rather than either a bare brand no one understands or a keyword salad. The rule of thumb: choose a name a customer would happily say out loud and recommend to a friend, and let your content do the ranking. If you are building something you hope to grow and sell one day, a brand name is almost always the stronger long-term asset.
## Characters and Patterns to Avoid
Some choices quietly cost you traffic and credibility for the entire life of the domain. Avoid them from the start.
- **Hyphens.** A hyphenated name (`your-business.co.za`) is hard to convey verbally, since you must remember to say "hyphen", and it is easy to lose visitors to whoever owns the un-hyphenated version. Hyphenated domains also carry a lingering association with low-quality sites. If the plain version of your name is taken, that is usually a signal to choose a different name, not to bolt a hyphen onto it.
- **Numbers.** Numbers create the same spoken ambiguity: is it `4` or `four`, `2` or `to` or `too`? Every time you say the domain aloud you will have to clarify, and every visitor who guesses wrong lands on someone else's site.
- **Doubled or ambiguous letters.** Names where two words collide into a repeated letter, or that rely on letters easily confused when spoken, invite typos. Say the name aloud and listen for where a listener would stumble.
- **Homophones and near-misses.** If your name sounds exactly like a common word or an existing brand, people will type the other spelling. This is worth avoiding even when the domain is technically available.
The underlying principle is simple: a domain name spends most of its life being spoken, remembered, and typed from memory. Anything that survives being read aloud once, and typed correctly from that alone, is a good name.
## Steer Clear of Trademark Trouble
Registering a domain that contains someone else's brand or trademark is one of the few naming mistakes that can end with you losing the domain entirely, sometimes after you have already invested in it. This is not a minor risk, and it is easy to check for.
Under the Uniform Domain-Name Dispute-Resolution Policy (UDRP), and its South African equivalent for `.za` domains, a trademark holder can file a complaint and have a domain transferred away from you if it is confusingly similar to their mark, you have no legitimate interest in it, and it was registered in bad faith. Availability at the registrar is not permission: a name can be free to register and still be legally off-limits.
Protect yourself before you commit:
- Search the South African trade marks register through the [CIPC](https://www.cipc.co.za/?page_id=3752) free basic search for any name you intend to build a brand on.
- Do a plain web and search-engine check for an existing company already using the name, especially in your industry or region.
- If you plan to trade internationally, widen the check, and read the [WIPO](https://www.wipo.int/amc/en/domains/) material on how these disputes are decided.
Choosing a distinctive, invented, or clearly personal name is the simplest way to sidestep this whole category of risk, since a name no one else uses cannot infringe anyone.
## Choosing the Right Ending: TLD, .co.za and .com
The top-level domain is the ending of your name, and there are now well over a thousand of them in the [IANA Root Zone Database](https://www.iana.org/domains/root/db). For most people the real decision is narrower than that long list suggests.
### .co.za for South African businesses
South Africa's country namespace is managed by the [.ZA Domain Name Authority](https://www.zadna.org.za), and `.co.za` is its commercial second-level domain, the everyday home of South African business online. If your customers are in South Africa, `.co.za` is often the strongest choice for three practical reasons:
- **It signals local presence.** South African visitors recognise `.co.za` instantly as a local business, which builds trust for a shop, service, or brand serving the domestic market.
- **The name is more likely to be free.** Because the `.co.za` space is smaller than the global `.com` space, the exact name you want is far more often still available.
- **It is the local standard.** Customers, suppliers, and search engines all treat `.co.za` as the natural fit for a South African organisation.
The `.za` namespace also offers other second-level domains for specific purposes, such as `.org.za` for non-profit and community organisations and `.net.za` for network-related entities. For a normal business or personal brand, `.co.za` is the one to reach for.
### .com for global reach
`.com` remains the most recognised ending in the world and the default many people type by habit. Choose it when your audience is international rather than specifically South African, when you are building a product or brand with global ambitions, or when you simply want the most universally familiar address. The trade-off is competition: the name you want in `.com` is much more likely to be taken already.
### Registering both
These are not mutually exclusive. Many South African businesses register both `.co.za` and `.com`, point one at the site and redirect the other to it, and in doing so protect the brand and catch visitors who guess the wrong ending. If your budget allows and both are free, securing the matching pair is a sound defensive move, and you can add close misspellings later if the name is easy to get wrong.
### New and specialist endings
Beyond `.co.za` and `.com` there are many newer generic endings, some genuinely useful. A continental option such as `.africa` can suit a pan-African brand, and category endings like `.shop`, `.co` or `.io` can work well when the ending reads as part of the name. Treat these with a little caution: some are less familiar to everyday visitors, a few carry higher renewal costs, and an ending that is trendy today may date. Pick a specialist TLD because it genuinely fits your name and audience, not merely because your first choice was taken in `.com`.
## Check the Name Everywhere, Not Just the Domain
A domain rarely stands alone. Before you commit, confirm the same name is available where you will actually use it, so your website, social profiles, and email all line up.
- **Social handles.** Check the exact name on every platform you expect to use, so your handles can match your domain. A consistent name across your site and your profiles is far easier for customers to find and remember, and it is much cheaper to secure a free handle now than to compromise later.
- **Both leading TLDs.** Even if you only register one to start, check whether the `.co.za` and `.com` versions are free, since a name that is available in both is a stronger, more defensible brand.
- **Obvious misspellings.** If your name has a likely typo, glance at whether that variant is free too, in case you want it later.
If the name is taken on the platforms that matter most to you, that is a strong reason to revisit your shortlist now, while changing course is still free.
## Future-Proof the Choice
You are choosing a name for years, so give it room to grow.
- **Do not over-narrow.** Baking a single product, a suburb, or a current year into the name (`capetownvintagevinyl2020.co.za`) locks you in. If you add products, move, or simply want the name to stay current, an over-specific domain becomes a liability. A broader, brandable name travels with you.
- **Leave room to expand.** If you might add a shop, a blog, or regional sections later, remember you can create subdomains (`shop.yourbusiness.co.za`) and folders under one good domain at no extra cost, so you do not need a separate clever domain for every idea.
- **Avoid dated fashions.** Deliberate misspellings and of-the-moment trends can look tired within a few years. A clean, real-word or well-invented name ages far better.
- **Think about how it looks written together.** Read the label with no spaces and check it does not accidentally form an unintended word across the boundary between two joined words. This is a classic, avoidable embarrassment.
## The Domain Name Decision Checklist
Run each shortlisted name through this checklist. A name that clears every point is one you can register with confidence. If it fails an item, either fix it or drop the name and move to the next candidate.
- **Say it aloud.** Could someone type it correctly from hearing it once, with no spelling out? (The radio test.)
- **Length.** Is the second-level label short, ideally under about 15 characters and a few syllables?
- **Spelling.** Is there only one obvious way to spell it, with no ambiguous or invented spellings?
- **No hyphens or numbers.** Is the name free of hyphens and digits?
- **Reads cleanly joined up.** With the spaces removed, does it avoid any unintended word or awkward letter collision?
- **Brandable.** Is it distinctive enough to own, rather than a generic string of keywords?
- **Trademark clear.** Have you checked the CIPC trade marks register and searched the web, and found no conflicting brand?
- **Right ending.** Does the TLD fit your audience: `.co.za` for a South African focus, `.com` for global reach, and both secured where practical?
- **Handles available.** Is the matching name free on the social platforms you will use?
- **Future-proof.** Is it free of a year, a single product, or a location you might outgrow?
- **Available to register.** Confirm the exact domain is genuinely free, as a final step, before you fall in love with it.
## Registering Your Chosen Name With Noiz
Once a name clears the checklist, register it while it is still free, since good domains are taken every day. You can search for and register your chosen domain directly through the domain search on the Noiz website, or from within the Noiz client area, which is also where you will manage renewals so the name never lapses by accident.
When you register a domain with Noiz to use with Noiz hosting, point it at the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za` so it resolves to your hosting. Set this on any domain you plan to host with Noiz; a separate guide in this section covers pointing a domain to Noiz step by step.
## Still Deciding? Ask Noiz
Choosing a domain name is a decision you live with for a long time, so it is worth getting right the first time. If you are torn between two names, unsure whether `.co.za` or `.com` is the better fit for your audience, or want to check a name is sensible before you commit, the Noiz support team is happy to talk it through. Open a support ticket with your shortlist and a line about who your site is for, and Noiz can give you a straight, practical opinion, then help you register the winner and connect it to your hosting.
# How to Find the IP Address of a Website or Domain
Source: https://docs.noiz.ie/domains-dns/how-to-find-the-ip-address-of-a-website-or-domain/
This guide shows you how to find the IP address that a website or domain **resolves to**: the numeric address, such as `203.0.113.10`, that a name like `yourdomain.com` points at behind the scenes. Turning a name into an address is called a **DNS lookup** (you will also hear it called "resolving" a domain, or a "name resolution"), and every browser does it silently every time you open a page. You will want to do it yourself when you are confirming that a domain points at the right server, adding a server address to a firewall or allow-list, checking a change you made to your DNS, or working through a support ticket. There are two ways to do it: a browser-based lookup tool that needs nothing installed, and the command-line tools built into every operating system. Both are covered below, along with the one thing that surprises people most often: the address a lookup gives you is not always the real address of the server your site sits on. When a content delivery network (CDN) or reverse proxy sits in front of a domain, the lookup returns the CDN's address and hides the true origin by design. That gotcha, and how to read the output well enough to spot it, is what this article adds on top of the raw commands.
**Last reviewed:** 27 July 2026. This guide covers the standard DNS lookup tools built into Windows, macOS and Linux, namely `ping`, `nslookup`, `dig` and `host`, which are long-established and stable across versions. It is written for Noiz hosting and is kept current against the DNS standards and the tools' own documentation. It complements, and does not replace, the official documentation linked below. The example IP addresses used throughout (`203.0.113.10` and `2001:db8::10`) are reserved documentation addresses, not real servers, so replace them and `yourdomain.com` with your own values.
### Official Documentation Reference
- [RFC 1035: Domain Names, Implementation and Specification](https://www.rfc-editor.org/rfc/rfc1035): the foundational DNS standard that defines the `A` record (the IPv4 address of a name) and the structure of the query and answer you see in a lookup.
- [RFC 3596: DNS Extensions to Support IP Version 6](https://www.rfc-editor.org/rfc/rfc3596): defines the `AAAA` record, which is how an IPv6 address is published for a name.
- [nslookup (Microsoft Learn)](https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/nslookup): the reference for the `nslookup` command that ships with Windows, including its interactive mode, the `-type=` option, and how to query a specific DNS server.
- [dig and host manual pages (ISC BIND documentation)](https://bind9.readthedocs.io/en/latest/manpages.html): the authoritative reference for `dig` and `host`, including the meaning of every section in `dig` output and the flags such as `+short`.
## Prerequisites
- The domain name you want to look up, for example `yourdomain.com`. You do not need to own it; a lookup reads public DNS.
- For the command-line methods, access to a terminal: **Command Prompt** or **PowerShell** on Windows, and **Terminal** on macOS or Linux. No administrator rights are needed for a plain lookup.
- A working internet connection. A lookup asks a DNS resolver a question over the network, so an offline machine cannot resolve a name it has not already cached.
## The Quick Way: Online Lookup Tools
If you only need the answer once, or you are on a phone or a locked-down work machine where you cannot open a terminal, a browser-based DNS lookup is the fastest route. You type the domain into a web form and it shows the `A` record (IPv4) and, if one exists, the `AAAA` record (IPv6). Public DNS providers run such pages; the query page at [dns.google](https://dns.google/), run by Google Public DNS, is one authoritative example, and a web search for "DNS lookup" returns several more.
One thing worth understanding about these tools: the lookup runs on the tool's own servers, not on your machine, so the answer is what a public resolver somewhere on the internet sees. That is usually the same as what you would see, but it means an online tool bypasses your local network's own DNS and any cached answer on your computer. That difference becomes useful later when a stale local cache is the problem.
## Looking Up an IP on Windows
Windows ships with `ping` and `nslookup`, and modern Windows also has the PowerShell `Resolve-DnsName` cmdlet. It does not include `dig` or `host`. Open **Command Prompt** or **PowerShell** from the Start menu to use these.
### ping: the fastest look, as a side effect
`ping` exists to test whether a host answers, but to do that it first resolves the name, and it prints the address it found on the very first line:
```
ping yourdomain.com
```
The first line reads something like `Pinging yourdomain.com [203.0.113.10] with 32 bytes of data`. The address in the square brackets is your answer. This works even when the replies that follow all time out, because many servers deliberately ignore ping; the name was still resolved to get that address in the first place, so do not be put off by "Request timed out" lines underneath. By default Windows will usually return an IPv4 address here; add `-6` to ask for IPv6 (`ping -6 yourdomain.com`).
### nslookup: the purpose-built tool
```
nslookup yourdomain.com
```
The output first names the DNS server it asked (the **Server** and **Address** lines at the top, which is your configured resolver), then, under **Non-authoritative answer**, gives the **Name** and one or more **Addresses**. "Non-authoritative" simply means the answer came from a resolver's cache rather than from the domain's own nameservers, which is normal and not a problem. To ask specifically for the IPv6 address, set the type:
```
nslookup -type=AAAA yourdomain.com
```
To ask a particular DNS server instead of your default one, add its address as a second argument. This is how you check what a public resolver sees, sidestepping your own network's DNS:
```
nslookup yourdomain.com 1.1.1.1
```
### Resolve-DnsName: the tidy PowerShell option
In PowerShell, `Resolve-DnsName` presents the same information in clean columns of **Name**, **Type**, **TTL** and **IPAddress**, which many people find easier to read than nslookup:
```
Resolve-DnsName yourdomain.com
Resolve-DnsName yourdomain.com -Type AAAA
```
## Looking Up an IP on macOS and Linux
macOS includes `ping`, `nslookup`, `host` and `dig` out of the box. On Linux, `ping` is always present, but `dig` and `host` come from a DNS utilities package (named `dnsutils` or `bind-utils` depending on the system) that you may need to install first. Open **Terminal** to use them.
### host: the shortest command
`host` gives a one-line, plain-English answer and is the quickest to read:
```
host yourdomain.com
```
It replies with lines such as `yourdomain.com has address 203.0.113.10` and, if the domain publishes IPv6, `yourdomain.com has IPv6 address 2001:db8::10`. It will also list where mail is handled, which you can ignore when you only want the web address.
### dig: the tool that shows you everything
`dig` is the professional's tool because it shows the full DNS answer, not just the address. For a plain look at the IPv4 address:
```
dig yourdomain.com
```
By default this queries for the `A` record. To get only the address with none of the surrounding detail, add `+short`:
```
dig +short yourdomain.com
```
For the IPv6 address, ask for the `AAAA` record, and to query a specific resolver (here Cloudflare's public `1.1.1.1`, though Google's `8.8.8.8` works just as well) put its address after an `@`:
```
dig yourdomain.com AAAA
dig @1.1.1.1 yourdomain.com
```
The `ping` command works the same as on Windows: the first line reports the resolved address before any reply. Use `ping -6 yourdomain.com` (or `ping6` on older systems) for IPv6.
## IPv4 and IPv6: A Records and AAAA Records
A domain can point at two kinds of address, and a lookup can return either or both. Knowing which you are looking at saves a lot of confusion.
- An **A record** maps a name to an **IPv4** address: four numbers separated by dots, such as `203.0.113.10`. This is still the most common answer.
- An **AAAA record** (spoken as "quad-A") maps a name to an **IPv6** address: a longer address written in hexadecimal groups separated by colons, such as `2001:db8::10`. IPv6 is increasingly common but not universal.
Most tools show the IPv4 (`A`) answer by default, so if you specifically want the IPv6 answer you must ask for `AAAA`, as shown above. If a domain has no IPv6 address, an `AAAA` query returns no answer at all: that is expected and is not a fault, it simply means the domain has not published an IPv6 record. Equally, a domain can have several `A` records at once, in which case a lookup lists more than one address, which is normal for larger sites and is covered in the next sections.
## How to Read dig Output
A full `dig` response looks busy the first time you see it, but only one part is the answer and the rest is useful context. Here is a typical response, trimmed slightly, for `dig yourdomain.com`:
```
; <<>> DiG 9.x <<>> yourdomain.com
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 12345
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 1
;; QUESTION SECTION:
;yourdomain.com. IN A
;; ANSWER SECTION:
yourdomain.com. 300 IN A 203.0.113.10
;; Query time: 24 msec
;; SERVER: 1.1.1.1#53(1.1.1.1)
;; WHEN: Tue Jul 21 12:00:00 2026
;; MSG SIZE rcvd: 59
```
Read it top to bottom like this:
- The **HEADER** line carries the **status**. `NOERROR` means the query succeeded. `NXDOMAIN` means the name does not exist (a typo, an expired domain, or nameservers not yet set). `SERVFAIL` points at a problem on the resolver's side rather than with the domain.
- The **QUESTION SECTION** simply echoes what you asked: the name, class `IN`, and the record type `A`.
- The **ANSWER SECTION** is the payload, and this single line is what you came for. Reading it left to right: the name (`yourdomain.com.`), the **TTL** in seconds (`300`), the class (`IN`), the record type (`A`), and finally the value, `203.0.113.10`. In plain terms, this line says the domain resolves to that address.
- The **footer** tells you which resolver answered, on the **SERVER** line, so you know whose view of DNS you are seeing, along with how long the query took.
Two extra points make the output far more useful. First, if the **ANSWER SECTION** shows a `CNAME` line above the `A` line, the name is an **alias** that points at another hostname, and `dig` has followed the chain to the final address for you. This is extremely common when a domain uses a CDN or when you look up a `www` subdomain, and it is the first visible sign that something sits between the name and the real server. Second, the **TTL** matters whenever you have just changed where a domain points: it is the number of seconds a resolver is allowed to cache this answer, so after a change a lookup can keep showing the old address until the TTL counts down and expires. That is why lowering a record's TTL a day before a planned move, and querying a public resolver directly afterwards, gives you a truer picture during a migration.
## Why the IP You See May Not Be the Server's Real Address
This is the single most important thing to understand, and it is where a raw lookup can quietly mislead you. A DNS lookup returns whatever address the domain's DNS is configured to hand out. When a domain sits behind a **CDN or reverse proxy**, that address belongs to the CDN's edge network, not to the origin server where your site actually lives. Cloudflare is the most common example, shown in its dashboard as the "proxied" or orange-cloud state. This is not a mistake; it is the entire point of a proxy. It sits in front to cache content, speed up delivery and shield the origin, and to do that it publishes its own address and keeps the origin's address hidden.
On Noiz hosting this plays out simply. If your domain uses the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za` with nothing proxying in front, a lookup returns your actual Noiz server address. If you have put a CDN or proxy in front of the domain, a lookup returns the CDN's address instead, and your true Noiz origin stays out of sight even though the site is still served from Noiz. Both situations are correct; you just need to know which one you are looking at.
The confusion this causes almost always takes one of these shapes:
- **Allow-listing the wrong thing.** If you add the resolved address to a firewall or an allow-list expecting to reach the origin, you may have allow-listed the CDN's edge instead, and the rule will not do what you intended.
- **"Is my site on the right server?"** When a proxy is in front, the resolved address will not match your Noiz server's address. That looks alarming but is correct, and it is not evidence that the site is hosted somewhere else.
- **Migration puzzles.** After moving a site to Noiz, a lookup that still shows an unfamiliar address can mean either a cached answer whose TTL has not expired, or a proxy that was never repointed at the new origin. The two need different fixes, so it is worth telling them apart.
A few other, perfectly legitimate reasons a lookup can vary are worth knowing so they do not throw you:
- **Several addresses at once.** A domain may publish more than one `A` record, and a resolver hands them out in a rotating order (round-robin). Both addresses are valid.
- **A different answer depending on where you are.** Large networks use anycast or geographically aware DNS, so a lookup from South Africa and a lookup from Europe can return different addresses, and both are right for the person who asked.
- **Caching.** As covered under TTL, a recently changed record can still show its previous value until caches expire.
When you need to tell what you are actually looking at, check **who owns the address**. Running a WHOIS or IP-ownership lookup on the returned address names the organisation it belongs to: if it is a CDN edge, the owner will be that CDN (for example, a Cloudflare-owned range) rather than Noiz. Be aware that a CDN's address ranges change over time, so never hard-code them; check ownership at the moment you look. A reverse (PTR) lookup on the address and the record's TTL are further clues. If you are ever unsure what your account's real server address is, or whether a proxy sits in front of your domain, the Noiz support team can confirm it directly.
## Troubleshooting
- **Symptom**: the lookup returns **NXDOMAIN** or "Non-existent domain". The name is not in DNS. Check for a typo, confirm the domain has not expired, and if you have only just registered it or changed its nameservers, allow time for the change to take effect before it resolves everywhere.
- **Symptom**: the resolved address does not match your Noiz server's address. Most often a CDN or proxy sits in front of the domain, as explained above, or you are seeing a cached old answer. Query a public resolver directly, for example `dig @1.1.1.1 yourdomain.com` or `nslookup yourdomain.com 1.1.1.1`, to bypass a stale local cache, then check who owns the address that comes back.
- **Symptom**: `ping` times out but you still saw an address on the first line. Many servers block ping on purpose, so timed-out replies do not mean the site is down and do not mean the lookup failed. The address ping printed is still valid; use `dig`, `host` or `nslookup` to confirm it rather than relying on ping replies.
- **Symptom**: two tools, or two people, show different addresses for the same domain. This is usually round-robin records, geographically aware DNS, or caching, and all of them can be legitimate. Compare each result against the same known public resolver to get a common reference point.
- **Symptom**: an `AAAA` (IPv6) query returns nothing. The domain simply has no IPv6 record published, which is common and not a fault. The `A` (IPv4) record is what browsers will use.
- **Symptom**: on Windows there is no `dig` or `host` command. Those are not part of Windows. Use `nslookup` or PowerShell's `Resolve-DnsName` instead, or run `dig` from a Windows Subsystem for Linux shell if you have one.
- **Symptom**: you changed where the domain points but a lookup still shows the old address. This is TTL and caching. Wait out the record's TTL, flush your machine's DNS cache (`ipconfig /flushdns` on Windows), and query a public resolver directly to see the new value as it becomes available.
If a lookup is not returning what you expect, or you want to confirm the real server address behind a domain hosted with Noiz, open a support ticket with the Noiz support team. Tell them the exact domain, the address you are seeing, and which tool you used to get it. On a managed plan the team can confirm your account's server address, tell you whether a proxy sits in front of your domain, and help you read a confusing result so you know exactly where your domain points.
# How to Point Your Domain to Noiz Hosting
Source: https://docs.noiz.ie/domains-dns/how-to-point-your-domain-to-noiz-hosting/
This guide is for anyone who has bought Noiz hosting and now needs their domain name, the address people type into a browser, to actually load the website and receive the email that live on Noiz servers. It covers the two ways to connect a domain to hosting: handing the whole domain over to the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za` (the simple, recommended route), or leaving your nameservers where they are and pointing only individual records such as A and MX. It also explains, in plain terms, why the change is never instant and how to check for yourself when it has taken effect, so you are not left refreshing a page and guessing.
A word on terminology first, because two ideas get muddled constantly. Your **nameservers** are the servers that answer the question "who is in charge of this domain's records", and they are set at your **registrar**, the company you bought the domain from. Your **DNS records** (A, AAAA, CNAME, MX, TXT and so on) are the individual entries those nameservers hand out, and they say things like "the website is at this address" and "send mail to this server". Changing nameservers moves the whole job to a new set of servers at once. Changing records edits single entries at whichever nameservers are already in charge. This guide keeps the two clearly apart, because choosing the right one is most of the battle.
**Last reviewed:** 27 July 2026, against current DNS practice (RFC 1034/1035/2181) and the Noiz client area. This guide is written for Noiz hosting and is kept current as the Noiz client area and nameservers evolve. It complements, and does not replace, the standards and authority references linked below. Registrar control panels differ in layout and wording, so where a field name here does not match your registrar exactly, look for the equivalent; the action and its effect stay the same.
### Official Documentation Reference
- [RFC 1034: Domain Names, Concepts and Facilities](https://www.rfc-editor.org/rfc/rfc1034): the authoritative description of how the domain name system delegates authority to nameservers, which is exactly what you are changing when you point a domain.
- [RFC 1035: Domain Names, Implementation and Specification](https://www.rfc-editor.org/rfc/rfc1035): defines the record types you will meet (NS, A, MX, CNAME) and the TTL field that governs caching.
- [RFC 2181: Clarifications to the DNS Specification (Section 8, Time to Live)](https://www.rfc-editor.org/rfc/rfc2181): the precise rules for TTL, the value that decides how long the old answer lingers after you make a change.
- [IANA Root Zone Database](https://www.iana.org/domains/root/db): the list of every top-level domain and its registry, useful for understanding the chain that leads a visitor from `.co.za` or `.com` down to your nameservers.
- [ZADNA, the .za Domain Name Authority](https://www.zadna.org.za/): the statutory authority for South Africa's `.za` namespace, including `.co.za`, for registrant rights and the rules that govern local domains.
## Prerequisites
- You have an active hosting service with Noiz for the domain you are pointing. Pointing a domain at Noiz before the hosting exists gives visitors an error, because there is nothing yet for the nameservers to serve.
- You can sign in to the account at your current **registrar**, the company where the domain is registered, with enough access to change nameservers or edit DNS records. If someone else registered the domain on your behalf, they may hold this access.
- You know your domain name, written here as `yourdomain.com` throughout as an example to replace with your real domain.
- The domain is not locked in a way that blocks changes. A registrar transfer lock stops a domain moving to another registrar but does not usually stop nameserver or record edits; if changes are refused, check with your registrar.
## Two Ways to Point a Domain, and When to Use Each
There are two clean approaches, and picking the right one avoids most of the trouble people run into.
| Approach | What you change | Best when | Trade-off |
| --- | --- | --- | --- |
| **Delegate to Noiz nameservers** (recommended) | Set the domain's nameservers to `ns1.noiz.co.za` and `ns2.noiz.co.za` at your registrar. | You want website and email served by Noiz and you want to manage DNS from one place. | Any DNS records you kept only at the old nameservers stop being used, so they must be recreated on the Noiz side. |
| **Keep your nameservers, point only records** | Leave nameservers as they are; edit the A record (website) and MX records (mail) to aim at Noiz. | Another provider must stay in charge of DNS, for example a service that manages your zone for you, and you only want to move the website or the mail. | You manage records in two places and must set each record you want on Noiz by hand. |
For most people the first approach is simpler and less error-prone: you change two nameserver values once, and from then on every record for the domain is managed together on the Noiz side. Reach for the second approach only when something outside Noiz genuinely needs to remain the authority for your DNS.
## Nameservers and DNS Records, Explained
It helps to picture what actually happens when a visitor types `yourdomain.com`. Their computer does not know where your site is, so it asks a chain of servers. The top-level domain registry, for example the operator of `.co.za` or `.com`, does not store your website's address either. What it stores is a signpost: the names of your nameservers. This signpost is the **delegation**, and it is exactly what you set at your registrar.
Once the visitor's computer learns that `ns1.noiz.co.za` and `ns2.noiz.co.za` are in charge, it asks those nameservers for the specific record it needs: the **A record** for the website's address, the **MX records** for where mail should go, and so on. So nameservers are the "who is in charge" answer, and DNS records are the individual answers that server then gives. When you delegate to Noiz, you move the "who is in charge" job to Noiz, and all the records travel with it. When you edit a single record instead, you are changing one answer while the "who is in charge" part stays put.
## If Your Domain Is Registered with Noiz
If you registered the domain through the Noiz website domain search or added it in the Noiz client area at checkout, there is nothing to do here. Noiz sets the nameservers to `ns1.noiz.co.za` and `ns2.noiz.co.za` for you when the domain and hosting are set up together, so the domain is already pointed at your hosting. You can confirm this in the client area, and you can jump straight to [How to Verify the Change](#verify) below to see it for yourself. The manual steps that follow are for domains registered somewhere other than Noiz.
## Method 1: Point Your Nameservers to Noiz (Recommended)
This is the route to use unless you have a specific reason not to. You are telling the domain's registry to hand the whole job to Noiz.
### Step 1: Sign in at your current registrar
Log in to the account at the company where the domain is registered. Every registrar has a page for managing an individual domain, often labelled **Manage**, **DNS**, or **Nameservers**. Open the settings for `yourdomain.com`.
### Step 2: Find the nameserver setting
Look for a section named **Nameservers**, **Name Servers**, or sometimes **DNS**. Registrars usually offer a choice between the registrar's own default (often called "basic", "parked", or a default that uses the registrar's own nameservers) and a "custom" or "use your own nameservers" option. Choose the option that lets you enter your own nameservers.
### Step 3: Enter the Noiz nameservers
Replace whatever is there with the two Noiz nameservers, one in each field:
```
ns1.noiz.co.za
ns2.noiz.co.za
```
Enter them exactly, with no extra spaces and no trailing full stop unless your registrar's field already shows one. If the form provides more than two nameserver fields, leave the extras blank; two are all that is required. Do not enter an IP address in a nameserver field; nameservers are names, not numbers.
### Step 4: Save
Save or apply the change. The registrar sends the new delegation up to the domain's registry. The registry itself usually records the change within minutes, but the wider internet takes longer to notice, for the reasons explained under propagation below. From this point your website and email will move to Noiz as the change spreads.
**One caution before you switch.** Delegating to Noiz means the Noiz nameservers become the single source of truth for the domain. Any records that existed only at your old nameservers, for example a mail-related TXT record, a subdomain, or a record for a service unrelated to Noiz, will stop being used the moment the delegation moves. Before you switch, note down any such records so they can be recreated on the Noiz side. Your standard website and Noiz email records are set up for you as part of your hosting; it is the extra, non-Noiz records that are easy to forget.
## Method 2: Keep Your Nameservers and Point Only Records
Use this approach only when another provider must remain the authority for your domain's DNS, and you want to move just the website, just the email, or both, to Noiz without handing over the whole domain. Here you leave the nameservers untouched and edit individual records at whoever currently runs your DNS.
### Point the website (A record)
The website is moved by editing the **A record** for the domain (and usually for the `www` host) so that it holds the IP address of your Noiz hosting. To do that you first need that IP address; see [How to Find Your Server IP Address](/domains-dns/how-to-find-the-ip-address-of-a-website-or-domain/) for where to read it from your Noiz account. Set the A record for `yourdomain.com`, and the A record (or CNAME) for `www`, to that address at your current DNS provider.
### Point the email (MX records)
Email is moved by editing the **MX records** so they name the Noiz mail host for your service rather than your old provider. The exact mail host and priority for your account are shown with your Noiz hosting details; use those values rather than copying them from elsewhere, because mail host names differ between services. Remove or replace the old MX records so that mail is not split between two providers, which is a common cause of some messages arriving and others vanishing.
Because this approach leaves the "who is in charge" answer with your existing provider, only the records you edit change. Anything you do not touch keeps pointing wherever it did before, which is exactly why this method suits a partial move but adds ongoing work: every record you want on Noiz has to be set by hand, and future changes are made at your DNS provider, not on Noiz.
## Why the Change Takes Time (Propagation and TTL)
Whichever method you use, the change is not instant, and understanding why saves a lot of needless worry. The delay is not your registrar being slow, and it is not Noiz being slow. It is caching.
To keep the internet fast, DNS answers are cached. When a resolver anywhere in the world looks up your domain, it is told how long it may remember the answer before asking again. That lifetime is the **TTL** (time to live), a value attached to every record and measured in seconds. Until a cached answer's TTL runs out, that resolver keeps serving the old answer, even after you have made your change. What people call "propagation" is really nothing more than these old cached answers ageing out around the world and being refreshed with the new ones. Nothing is travelling anywhere; old copies are simply expiring at different times in different places.
This is why two people can see different results at the same moment: one is behind a resolver that has already refreshed, the other behind one still holding the old answer for a few more minutes or hours. It is normal, and it resolves itself. The widely used rule of thumb is to allow up to 24 to 48 hours for a change to be seen everywhere, though in practice most locations update far sooner, often within an hour or two.
Two nuances are worth knowing:
- **Nameserver changes (Method 1) can feel slower than record changes.** The lifetime of the delegation is set by the top-level domain's own settings, not by you, and for some extensions it is long. That is inherent to how the registry publishes delegations and is outside anyone's control, so patience is the only remedy here.
- **Record changes (Method 2) are under your control in advance.** If you know you are about to move an A or MX record, lower that record's TTL, for example to 300 seconds (five minutes), a day or two *before* the switch. Once the old, long TTL has expired everywhere, the actual change is picked up within the new short window. Raise the TTL back to a normal value afterwards. This trick only helps if you plan ahead, because you cannot shorten a TTL that resolvers have already cached.
## How to Verify the Change
Rather than guessing from a browser, which caches aggressively, check DNS directly. There are two easy ways.
### From the command line
On macOS or Linux, the `dig` command asks DNS the exact question you care about. To confirm the nameserver delegation (Method 1), run:
```
dig NS yourdomain.com +short
```
Once the change has reached the resolver you are using, the reply lists your Noiz nameservers:
```
ns1.noiz.co.za.
ns2.noiz.co.za.
```
To confirm where the website points (useful for Method 2, or to check the site after delegating), ask for the A record:
```
dig A yourdomain.com +short
```
And to confirm mail delivery, ask for the MX records:
```
dig MX yourdomain.com +short
```
On Windows, the equivalent is `nslookup`:
```
nslookup -type=ns yourdomain.com
```
### With an online propagation checker
Because your own computer only shows you the answer at one location, a global DNS propagation checker is the better tool for seeing the wider picture. These are free websites (search for the term "DNS propagation checker") that query DNS resolvers in many countries at once and show you, on a map or a list, which parts of the world already return the new answer and which still hold the old one. Choose the record type you changed (NS for a nameserver switch, A for the website, MX for mail), enter `yourdomain.com`, and watch the locations turn over to the new value. When they are all showing the Noiz nameservers or the correct records, the change is effectively complete.
## Troubleshooting
- **Symptom: hours have passed and the site still shows the old page or an error.** First confirm the nameservers actually changed at the registry, using `dig NS yourdomain.com +short` or a propagation checker set to NS. If it still lists the old nameservers everywhere, the change did not save at your registrar; go back and set the nameservers again. If the checker shows the Noiz nameservers in most locations but your own browser does not, it is your local or network cache; try a different device or connection, or clear your browser cache.
- **Symptom: the website works but email has stopped, or the reverse.** This usually means you moved one and not the other, or records are split between two providers. If you delegated to Noiz (Method 1), make sure any records that lived only at the old nameservers were recreated on the Noiz side. If you are using Method 2, check that the A record and the MX records both point where you intend, and that no leftover MX record still names the old mail provider.
- **Symptom: the registrar rejects the nameserver values.** Check for typos and stray spaces, that you entered names and not IP addresses, and that you filled the two nameserver fields rather than a "hostname registration" field, which is a different feature for registering your own custom nameservers. Enter `ns1.noiz.co.za` and `ns2.noiz.co.za` exactly.
- **Symptom: some visitors reach the new site and others do not.** This is normal propagation in progress: different resolvers are refreshing at different times as their cached answers expire. It settles on its own within the propagation window. A propagation checker will show the split clearly and confirm there is nothing to fix.
- **Symptom: you cannot find where to change nameservers at your registrar.** The setting sometimes hides under a "DNS" or "advanced" menu, and a few registrars require you to switch off a managed-DNS or parking option before the nameserver fields become editable. If it is genuinely absent, the domain may be managed through a reseller or a third party who holds that access.
## Managed Plans and Noiz Support
If you are on a Noiz managed plan, you do not have to make these changes yourself. Open a ticket with the Noiz support team, tell them the domain and where it is currently registered, and they will point it at your hosting and confirm when it is live. For domains registered with Noiz, the pointing is already handled as part of setting up your service.
If you are pointing a domain yourself and something does not behave as expected, Noiz support can help. When you open a ticket, include your domain name, whether you changed nameservers or individual records, what your registrar is (without sharing passwords), and what a check such as `dig NS yourdomain.com` currently returns. That lets the team see the same DNS you do and tell you quickly whether the change is still propagating or genuinely needs fixing.
# What Are PTR (Reverse DNS) Records and When You Need One
Source: https://docs.noiz.ie/domains-dns/what-are-ptr-reverse-dns-records-and-when-you-need-one/
This guide explains what a PTR record is, why reverse DNS matters far more for email than for websites, and who is actually able to set one. A PTR (pointer) record maps an IP address back to a hostname, so it is the mirror image of the A record that maps a hostname to an IP. You will see the same idea called reverse DNS, reverse lookup, rDNS or simply "the PTR", and they all describe the same thing: given an IP address, what name does it claim to be? This article is for Noiz clients who have run into a mail-delivery warning that mentions reverse DNS, who are setting up a mail server on a Noiz VPS or dedicated server, or who simply want to understand a record that, unusually, they cannot edit themselves. The short version is that on Noiz shared and managed hosting the PTR for your outbound mail is already handled for you, and you only need to act when you send mail directly from your own server's IP address.
**Last reviewed:** 27 July 2026. Reverse DNS is defined by long-standing internet standards that change very rarely, so the mechanics described here are stable. The mail-deliverability behaviour, however, reflects how receiving mail servers currently treat a sending IP address, and providers tend to tighten these checks over time rather than loosen them. This guide is written for Noiz hosting and complements, and does not replace, the standards and provider documentation linked below.
### Official Documentation Reference
- [RFC 1035 (Domain Names, Implementation and Specification)](https://www.rfc-editor.org/rfc/rfc1035): the core DNS standard that defines the PTR record type and the A record it reverses.
- [RFC 1912 (Common DNS Operational and Configuration Errors)](https://www.rfc-editor.org/rfc/rfc1912): explains why every IP that sends mail should have a matching reverse record, and the classic mistakes to avoid.
- [RFC 8499 (DNS Terminology)](https://www.rfc-editor.org/rfc/rfc8499): the authoritative glossary, including the definitions of forward and reverse lookups and forward-confirmed reverse DNS.
- [IANA .ARPA Zone Management](https://www.iana.org/domains/arpa): the registry for the `in-addr.arpa` and `ip6.arpa` zones where all reverse records ultimately live.
## Prerequisites
- A basic idea of what an A record does, that is, that it points a name at an IP address. Reverse DNS makes most sense once you picture it as that arrow turned around.
- The IP address you are asking about. To look up or confirm a PTR you need the exact IP, so if you are not sure of it, first [find the IP address of your domain or server](/domains-dns/how-to-find-the-ip-address-of-a-website-or-domain/).
- Access to a command line or an online reverse-lookup tool if you want to check a record yourself. This is optional, and the checks are shown further down.
## Forward DNS and Reverse DNS: Two Directions of the Same Question
Ordinary DNS answers the question "what is the IP address for this name?". You type `yourdomain.com`, DNS returns an IP address using an **A record** (or an **AAAA record** for IPv6), and your browser connects to it. This is called forward DNS because it runs from name to number.
Reverse DNS answers the opposite question: "what name belongs to this IP address?". Something is given an IP address such as `192.0.2.25` and wants to know which hostname that address claims to be. The answer is stored in a **PTR record**. A useful mental picture is a phone directory: the A record is the ordinary listing that turns a name into a number, and the PTR record is a reverse directory that turns a number back into a name.
Because they are separate records held in separate places, the two directions can disagree. An IP can have a perfectly good A record pointing to it while having no PTR at all, or a PTR that names some completely unrelated host. That mismatch is exactly what many mail servers are looking for, as explained below.
## Where PTR Records Live, and Why You Cannot Set Your Own
This is the single most important thing to understand about reverse DNS, and the point that catches most people out. A PTR record does **not** live in your domain's DNS zone. It is not something you add alongside your A, MX and TXT records. There is no field for it in a domain's DNS editor, whether that is your hosting control panel, the Noiz nameservers at `ns1.noiz.co.za` and `ns2.noiz.co.za`, or any third-party DNS host. You can have complete control of your domain's DNS and still be unable to touch your PTR.
The reason is that reverse records are organised by IP address, not by domain name, and they sit in a special reverse zone. IPv4 addresses map into the `in-addr.arpa` zone, with the octets written in reverse order, so the PTR for `192.0.2.25` is a record at `25.2.0.192.in-addr.arpa`. IPv6 addresses map into the `ip6.arpa` zone in a similar back-to-front fashion. Authority over these reverse zones follows the chain of ownership of the IP address itself, not the domain:
- IANA delegates each large block of the `in-addr.arpa` space to a Regional Internet Registry. Africa's registry is AFRINIC, and the other regions are served by ARIN, RIPE NCC, APNIC and LACNIC.
- The registry delegates the reverse zone for a block of addresses to the network that holds that block, typically a hosting provider or an internet service provider.
- That provider, as the holder of the IP block, is the only party that can create or change the PTR records for those addresses.
For addresses on Noiz infrastructure, Noiz holds the relevant block, so Noiz sets the PTR. Your domain registrar cannot do it, your DNS host cannot do it, and you cannot do it from any control panel, because none of them own the IP address. This is by design: it stops anyone from claiming that an IP they do not control belongs to their brand. It also means the correct route to a PTR change on a Noiz server is a request to Noiz, never a DNS edit on your side.
## Why PTR Records Matter for Email Deliverability
For a website, reverse DNS is almost irrelevant. A visitor's browser never checks the PTR of the server it is loading a page from, so a missing or odd PTR will not stop a site from working. Email is a different world entirely, and reverse DNS is one of the oldest and bluntest trust checks a receiving mail server performs.
When your server connects to another mail server to deliver a message, the receiving server sees the connecting IP address and, before it even looks at the message, it can ask reverse DNS what that IP claims to be. Two outcomes count heavily against you:
- **No PTR at all.** An IP that cannot even name itself looks like a home connection, a compromised machine or a throwaway spam source. Many receivers reject such connections outright, often with a message that mentions "no reverse DNS", "no PTR record" or "cannot resolve".
- **A generic or mismatched PTR.** A PTR that is plainly an automatically generated placeholder, or one that names a host with no connection to your mail, is treated as a weak signal. It may not cause an outright rejection, but it pushes your mail towards the spam folder or a slow, cautious acceptance.
The stronger test many receivers apply is **forward-confirmed reverse DNS**, sometimes shortened to FCrDNS. Here the receiver takes the PTR name your IP returns, then looks that name up in the forward direction, and expects it to resolve back to the very same IP. In other words, the reverse and forward records have to agree with each other. If your sending IP is `192.0.2.25`, its PTR should name something like `mail.yourdomain.com`, and `mail.yourdomain.com` should have an A record pointing back to `192.0.2.25`. When both halves line up, the receiver has good reason to believe the sender is a properly run mail server rather than a hijacked device.
It is worth being clear about the limits, because reverse DNS is often over-sold. A correct PTR is necessary for reliable delivery from your own IP, but it is not sufficient on its own. Modern deliverability still depends on the email-authentication records you publish in your own domain, chiefly SPF, DKIM and DMARC, together with a clean sending reputation. Think of the PTR as the doorman confirming your IP is who it says it is, while SPF, DKIM and DMARC prove the individual message is genuinely from your domain. You want all of them.
## When You Actually Need a PTR Record
Most Noiz clients never have to think about a PTR, because it is only relevant when mail leaves a machine directly from an IP address you are associated with. Use this as a quick guide.
- **Shared or managed Noiz hosting:** nothing for you to do. Outbound mail from shared and managed hosting is sent through Noiz mail infrastructure, and the PTR records for those sending addresses are already set correctly and forward-confirmed by Noiz. Your deliverability work is confined to your own domain's SPF, DKIM and DMARC records, not the PTR.
- **A Noiz VPS or dedicated server that sends its own mail:** this is the case that needs attention. When a message is sent straight from your server, the receiving side sees your server's IP, so that IP needs a PTR that matches the hostname your mail server introduces itself as. This is set by requesting it from Noiz, as described in the next section.
- **A server or VPS that only hosts a website and sends no mail from its own IP:** you can safely leave the default PTR in place. It is good practice for every live IP to have some valid PTR, and Noiz provides one, but you do not need a custom value if nothing is sending mail from that address.
- **Sending over IPv6:** if your mail server also connects over IPv6, that IPv6 address needs its own matching PTR in the `ip6.arpa` zone. Some receivers are stricter about IPv6 reverse DNS than IPv4, so an IPv6 address without a PTR is a common and easily missed cause of rejections.
## How PTR Is Handled on Noiz Hosting
Because only the holder of an IP block can edit its reverse zone, PTR on Noiz always works through Noiz rather than through your own panel. How much is automatic depends on your plan.
### Shared and Managed Plans
On shared and managed hosting the mail-sending IPs belong to Noiz mail infrastructure and are looked after for you. Their PTR records already point to legitimate Noiz mail hostnames, and those hostnames resolve back to the same IPs, so forward-confirmed reverse DNS passes without any action on your part. If a receiver ever complains about reverse DNS for mail you sent from shared hosting, that points to a different issue, so raise it with Noiz support rather than trying to change a PTR yourself.
### VPS and Dedicated Servers
On a VPS or dedicated server you are given one or more public IP addresses, and by default each carries a generic Noiz-provided PTR. That default is fine for a web-only server, but if you run a mail server you should request a PTR that matches your mail hostname. The steps are:
1. Decide on the hostname your mail server will announce itself as, for example `mail.yourdomain.com`. Replace `yourdomain.com` with your real domain; this is only an example value.
2. In your domain's DNS, create the forward record first: an A record for that hostname pointing to the server's IPv4 address, and, if you send over IPv6, an AAAA record pointing to the server's IPv6 address. You can set these yourself wherever your domain's DNS is hosted, including on the Noiz nameservers.
3. Open a ticket with Noiz support asking for the PTR (reverse DNS) on your server's IP address to be set to that same hostname. Give the exact IP address and the exact hostname, and mention the IPv6 address too if you send over IPv6.
4. Noiz sets the PTR in the reverse zone. Once it has propagated, the reverse and forward records agree, and forward-confirmed reverse DNS passes.
The order matters: set the forward A or AAAA record before or at the same time as requesting the PTR, so that the moment the PTR goes live the forward lookup already confirms it. A PTR pointing at a hostname that does not resolve back to the IP is only marginally better than no PTR at all.
## How to Check a PTR Record Yourself
You can inspect any IP's reverse DNS without special access, which is handy for confirming a change or diagnosing a rejection. The lookups below use the documentation address `192.0.2.25`; substitute the real IP you are checking.
On Linux or macOS, the `dig` tool does a reverse lookup with the `-x` flag:
```
dig -x 192.0.2.25 +short
```
A correctly configured address returns a hostname, such as `mail.yourdomain.com`. An empty result means there is no PTR for that IP.
On Windows, `nslookup` does the same job:
```
nslookup 192.0.2.25
```
If you do not have a command line to hand, any reputable online reverse-DNS or "reverse IP" lookup tool will show the same PTR value.
To confirm forward-confirmed reverse DNS, take the hostname the reverse lookup returned and look it up in the forward direction. It should resolve back to the IP you started with:
```
dig +short mail.yourdomain.com
```
When the reverse lookup gives you `mail.yourdomain.com` and the forward lookup of `mail.yourdomain.com` gives you back `192.0.2.25`, the two agree and your reverse DNS is set up the way mail servers want to see it.
## Troubleshooting
- **Symptom: mail is bounced with a message mentioning "no PTR record", "no reverse DNS" or "client host does not resolve".** The sending IP has no reverse record. If you are on shared or managed hosting this should not happen, so contact Noiz support. If you send from your own VPS or dedicated server, request a PTR for that IP from Noiz as described above, and make sure the matching forward A record exists.
- **Symptom: the PTR is set but mail is still treated as suspicious.** Check that forward-confirmed reverse DNS passes, that is, that the hostname in the PTR resolves back to the same IP. A PTR that names a hostname with no matching A record, or one pointing to a different IP, fails the check. Also remember that a correct PTR does not replace SPF, DKIM and DMARC; if those are missing or misaligned, mail can still be filtered.
- **Symptom: you tried to add a "PTR record" in your control panel or DNS editor and nothing changed.** That is expected. PTR records are not held in your domain's DNS zone and cannot be added there. The reverse record must be set by the holder of the IP block, which for a Noiz server means Noiz support.
- **Symptom: IPv4 mail is fine but mail sent over IPv6 is rejected.** The IPv6 address almost certainly lacks its own PTR in the `ip6.arpa` zone. Request a reverse record for the IPv6 address as well, and publish an AAAA record for the hostname so the forward and reverse agree.
- **Symptom: a reverse lookup still shows the old value after a change.** Reverse DNS is cached like any other DNS data, so a recent change can take time to appear everywhere. Allow for propagation, and re-check with a fresh lookup rather than relying on a cached result.
If your mail is being rejected for a reverse DNS reason, or you are standing up a mail server on a Noiz VPS or dedicated server and want the PTR set correctly, open a support ticket with the Noiz support team. Include the exact IP address, the hostname you want it to resolve to, and the text of any bounce message you received. On Noiz managed plans the support team can set the reverse record, confirm that the forward and reverse records agree, and check the wider picture of your mail authentication so that deliverability holds up beyond reverse DNS alone.
# What Is a TLD (Top-Level Domain)?
Source: https://docs.noiz.ie/domains-dns/what-is-a-tld-top-level-domain/
A top-level domain, or TLD, is the part of a web address that comes after the final dot: the `.com` in `yourbusiness.com`, or the `.za` in `yourbusiness.co.za`. It is the ending you choose when you register a domain, and it is one of the first real decisions you make when you put a business or project online. This guide explains what a TLD actually is, how it fits into the rest of a domain name, the main families you can pick from, who runs them behind the scenes, and, most usefully for a Noiz customer, how to choose the right one for what you are building.
You will hear TLDs called several other things, and they all mean the same object: the **domain extension**, the **domain ending**, or the **domain suffix**. When someone asks "should I go `.co.za` or `.com`?", they are asking which TLD to register. This article is written for anyone registering or searching for a domain through Noiz, whether you are a South African business leaning towards `.co.za` or reaching an international audience on `.com`, and no prior knowledge of the domain system is assumed.
**Last reviewed:** 27 July 2026, against the current IANA Root Zone Database and the ICANN generic top-level domain programme. This guide is written for Noiz hosting and explains how top-level domains work in general. The exact list of available TLDs, their prices and their eligibility rules change over time, so treat the IANA and ICANN references below as the live, authoritative sources for the current picture. This article complements, and does not replace, that official documentation.
### Official Documentation Reference
- [IANA Root Zone Database](https://www.iana.org/domains/root/db): the authoritative, complete list of every top-level domain currently in existence, each one labelled by type (generic, country-code, sponsored and so on) and showing the organisation that operates it. This is the single source of truth for "is this a real TLD, and who runs it?".
- [ICANN New gTLD Program](https://newgtlds.icann.org/): the reference for the wave of newer generic endings such as `.shop`, `.app` and `.online`, how they came to exist, and the rules that govern them.
- [ZADNA (.za Domain Name Authority)](https://www.zadna.org.za/): the South African statutory body that oversees the `.za` namespace, including `.co.za`, `.org.za` and the restricted endings. The place to check current `.za` policy and dispute procedures.
## The Part After the Last Dot
Domain names are organised as a hierarchy, and the trick to reading one is to read it from right to left, because the rightmost label is the most senior. At the very top of the hierarchy sits the DNS root (an invisible dot at the end that you never type). Directly beneath the root are the top-level domains: `.com`, `.org`, `.net`, `.za`, `.uk`, and well over a thousand others. Everything else in a web address is a branch growing beneath one of those TLDs.
So in `yourbusiness.com`, the `.com` is the top-level domain and `yourbusiness` is the specific name registered underneath it. The TLD is not decorative: it is a genuine level of the naming system, run by its own operator, with its own rules about who may register and what a name costs. There are currently more than 1,500 TLDs in the root, and because new ones are added and old ones occasionally retired, the IANA Root Zone Database linked above is the only place with a guaranteed-current count and list.
## The Anatomy of a Domain Name
A full web address is built from labels separated by dots, and each label sits at a level of the hierarchy. Read right to left, the usual shape is `subdomain.name.TLD`. It helps to see two worked examples side by side, one on a generic ending and one on a South African ending, because the `.za` case has a wrinkle worth understanding.
| Layer | `shop.yourbusiness.com` | `mail.yourbusiness.co.za` |
| --- | --- | --- |
| Top-level domain (TLD) | `.com` | `.za` |
| Registration namespace | none: you register directly under `.com` | `co.za` |
| The name you register and pay for | `yourbusiness.com` | `yourbusiness.co.za` |
| Subdomain (you create these yourself, for free, once you own the domain) | `shop.yourbusiness.com` | `mail.yourbusiness.co.za` |
The label you actually choose and register is `yourbusiness`. The registry adds the ending, and the whole registered domain (`yourbusiness.com` or `yourbusiness.co.za`) is what appears on your invoice and what you renew each year. Once you hold that domain, you can create as many subdomains as you like at no extra cost: `www`, `shop`, `mail`, `blog` and so on are all subdomains you control yourself. Replace `yourbusiness` with your own name throughout; it is only a stand-in here.
Now the `.za` wrinkle. Strictly speaking, the top-level domain in `yourbusiness.co.za` is `.za`, the country-code TLD for South Africa. The `co` is a second-level label that South Africa uses to group commercial registrations, so `co.za` behaves as a public registration namespace sitting beneath `.za`. In everyday hosting language nobody splits this hair: people simply call `.co.za` "the extension" and treat it as one unit, which is perfectly fine. It is just worth knowing that the `.za` registry sits at the top and that `co.za` is one of several namespaces under it, alongside `.org.za`, `.net.za`, `.web.za` and restricted ones such as `.gov.za` and `.ac.za`.
## The Main Families of TLD
TLDs fall into a few families, and knowing which family an ending belongs to tells you most of what you need about how trusted it is, who may register it, and what audience it signals.
### Generic top-level domains (gTLDs)
These are the open, general-purpose endings not tied to any country. The originals are `.com`, `.net` and `.org`, and `.com` remains the most recognised domain ending in the world. Since the early 2010s ICANN has added hundreds of newer generic endings that spell out a purpose or theme, such as `.shop`, `.store`, `.online`, `.blog`, `.app` and `.dev`, together with geographic ones like `.africa`. Anyone may register most gTLDs, subject only to availability.
### Country-code top-level domains (ccTLDs)
These are the two-letter endings tied to a country or territory, assigned from the international standard list of country codes: `.za` for South Africa, `.uk` for the United Kingdom, `.de` for Germany, `.au` for Australia, and so on. For South African registrants the practical entry point is the `.za` family, most commonly `.co.za` for businesses and individuals, with `.org.za` for organisations and `.net.za` also available. A ccTLD is the clearest signal you can send that your presence is local. Some ccTLDs have taken on a second life far from their home country because the letters happen to be catchy: `.io`, `.ai`, `.co` and `.tv` are all country codes that technology and media brands use for their initials rather than their geography. That is fine, but remember an `.io` or `.ai` address does not read as South African the way `.co.za` does.
### Restricted and sponsored TLDs
Some endings carry eligibility rules and are not open to the general public. Within the `.za` family, `.gov.za` is reserved for government and `.ac.za` for accredited academic institutions. Internationally, endings such as `.gov`, `.edu` and `.mil` are restricted to specific United States bodies. You cannot simply buy these, so do not build a plan around one unless your organisation qualifies. If in doubt for a `.za` ending, the ZADNA reference above sets out who may register what.
| Family | What it is | Examples | Typical use |
| --- | --- | --- | --- |
| Generic (gTLD) | Open, general-purpose endings, not country-specific | `.com`, `.net`, `.org`, `.info` | Anyone; `.com` is the global default |
| Newer generic (gTLD) | Descriptive or themed endings added since the 2010s | `.shop`, `.store`, `.online`, `.app`, `.africa` | Spelling out a purpose, theme or region |
| Country-code (ccTLD) | Two-letter endings tied to a country or territory | `.za`, `.co.za`, `.uk`, `.de` | Signalling a local presence |
| Restricted / sponsored | Endings with eligibility rules | `.gov.za`, `.ac.za`, `.gov`, `.edu` | Only qualifying bodies may register |
## Who Runs a TLD: Registry, Registrar, Registrant
Three roles sit behind every domain, and the words are easy to confuse because they look alike. Understanding them makes the rest of the domain world far less mysterious, and it explains exactly where Noiz fits in.
| Role | What it does | Who that is |
| --- | --- | --- |
| **Registry** | Operates a single TLD and keeps the master database of every domain registered under it. There is one registry per TLD. | The operator of `.com`, for instance; the `.za` namespace is overseen by ZADNA, South Africa's statutory domain authority. |
| **Registrar** | An accredited business that registers domains for the public, takes payment, and manages your account and renewals with the registry on your behalf. | Noiz, through the domain search on the Noiz website and the Noiz client area. |
| **Registrant** | The person or organisation that registers a domain and holds the exclusive right to use it for the registration period. | You. |
Above all of this sits ICANN, the non-profit that coordinates the domain name system globally, with IANA maintaining the master list of TLDs (the Root Zone Database you saw earlier). When you register a name with Noiz, Noiz acts in the registrar-facing role: you search for an available name, register it, and then manage it and its renewals from your Noiz client area, while the registry keeps the authoritative record. A domain is not a one-off purchase but a registration you hold for a term (typically a year at a time) and renew to keep. Let a registration lapse and the name returns to the pool for someone else to register, so keeping the renewal current is the single most important thing you can do to protect a domain.
## Choosing the Right TLD for Your Site
There is rarely one correct answer, but there is usually a best fit. Work through these factors in order and the choice tends to make itself.
1. **Purpose and audience geography.** This is the biggest lever. If your customers are mainly in South Africa, `.co.za` is the natural home: it reads as local, it is instantly familiar to a South African audience, and the name you want is far more likely to be free than on `.com`. If you serve, or want to appear to serve, an international audience, `.com` is the safest global default. A non-profit or association may prefer `.org` or `.org.za` for the not-for-profit connotation those endings carry.
2. **Trust and familiarity.** The most recognised endings, `.com` globally and `.co.za` in South Africa, are the ones visitors type without thinking and trust on sight. A newer or unusual ending can work well when it fits the name (a shop on `.shop`, a developer tool on `.dev`), but an ending your audience has never seen can make people hesitate, mistype the address, or assume you could not get the "real" one. Weigh cleverness against instant recognisability.
3. **Availability and price to renew.** Check your chosen name across a few endings using the domain search on the Noiz website before you settle. Prices vary widely between TLDs, and, crucially, some newer endings advertise a cheap first year but renew at a much higher rate. Always look at the renewal price, not just the first-year price, because you will pay it every year you keep the domain.
4. **Protecting your name.** If your brand matters, consider registering the same name on more than one key ending, most commonly both `.co.za` and `.com`. You point visitors at your main site and redirect the others to it, which stops a competitor or an imitator from taking the version you did not buy, and catches people who guess the wrong ending.
5. **Eligibility rules.** Confirm you are actually allowed to register the ending you have in mind. Restricted endings such as `.gov.za` or `.ac.za` are off the table unless you qualify, so do not design a brand around one you cannot have.
## Does the TLD Change Anything Technical?
This is where a lot of worry can be put to rest, because the honest answer is: for almost everything that matters, no. A common myth is that some endings are "faster" or work differently once your site is live. They do not.
- **Hosting and email work identically.** A website on `yourbusiness.shop` is hosted exactly the same way as one on `yourbusiness.co.za`, and a mailbox at `you@yourbusiness.online` sends and receives just like `you@yourbusiness.com`. The TLD has no bearing on your hosting plan, your mailboxes, your site's speed, or your reliability. Whatever ending you choose, you host it on Noiz the same way: you register it through Noiz, or you point the domain at the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za`, and everything downstream is the same.
- **Search engines: a small, geographic nuance.** Search engines treat a country-code ending like `.co.za` as a signal that your site is aimed at that country, which can genuinely help you reach a South African audience. Generic endings, whether `.com`, `.org` or a newer one like `.shop`, carry no country signal and are treated the same as each other. Importantly, putting a keyword in the ending (for example choosing `.shop` for a store) gives no ranking boost on its own; it is a branding choice, not an SEO trick.
- **A couple of endings enforce good security.** A few newer endings, notably `.app` and `.dev`, require every site on them to be served over HTTPS. That is a benefit rather than a catch, but it is worth knowing that a plain, unencrypted site simply will not load on those endings, so you will always need a valid TLS certificate, which Noiz provides.
## Getting Help From Noiz
If you are weighing up which ending to register, or you are unsure whether a particular `.za` ending is open to you, the Noiz support team can talk it through before you commit. Once you have chosen, you search for and register the domain through the domain search on the Noiz website and manage it from your Noiz client area, and Noiz handles the registry side for you. If you already own a domain elsewhere and want to bring it to Noiz hosting, or you are not sure whether a name is still available, open a support ticket with the name you have in mind and the audience you are trying to reach, and the team will point you to the ending that fits best.
# What Is the Domain Guardian (Registrant Contact) and How to Update It
Source: https://docs.noiz.ie/domains-dns/what-is-the-domain-guardian-registrant-contact-and-how-to-update-it/
This guide explains the domain "guardian", which is really the **registrant contact** on your domain, and shows you how to keep it correct in the Noiz client area. The registrant contact is the person and, above all, the **email address** recorded as the legal holder of the domain. It is where transfer-approval requests and transfer tickets are sent, where expiry and renewal reminders arrive, and where the registry or ICANN sends the verification messages that keep the domain valid. You will hear it called several things, including the *domain guardian*, the *registrant*, the *registrant email*, the *owner contact*, or simply *the domain owner*; they all mean the same record. This article is for anyone whose domain is registered with, or managed through, Noiz, and it matters most at exactly the moments people forget about it: when you try to move a domain, when it is due for renewal, or when an old email address has quietly stopped working.
**Last reviewed:** 27 July 2026. Domain registration rules change over time, and the specifics differ by top-level domain, so this guide is kept current against the authoritative policies and registries listed below. It gives Noiz-specific guidance for finding and updating the registrant contact, and it complements, and does not replace, those sources. Where a rule depends on the exact top-level domain or registry, this guide says so plainly rather than guessing.
### Official Documentation Reference
- [ICANN Transfer Policy](https://www.icann.org/resources/pages/transfer-policy-2016-06-01-en): the authoritative policy that governs transfers of generic top-level domains such as `.com`, `.net` and `.org`, including the "Change of Registrant" process and the transfer lock that can follow a change to the registrant details.
- [ICANN Registrant Rights and Responsibilities](https://www.icann.org/resources/pages/responsibilities-2014-03-14-en): the definitive statement of what you, as the registered holder, are entitled to and obliged to do, including keeping your registrant contact details accurate.
- [ICANN Lookup](https://lookup.icann.org): the official registration-data (WHOIS/RDAP) lookup tool, useful for seeing how your domain's contact record appears publicly.
- [.ZA Domain Name Authority (ZADNA)](https://www.zadna.org.za): the statutory regulator of South Africa's `.za` namespace, and the authoritative source on how `.co.za` and its sibling domains handle registrant details and transfers, which is not the same as the ICANN process for generic domains.
## Before You Start
- A domain that is registered with, or managed through, Noiz and appears in your Noiz client area under your domains.
- Your Noiz client area login.
- Ideally, access to read email at the address currently set as the registrant contact. If that inbox is dead or unreachable, that is precisely the problem this guide helps you fix, so read on before you attempt a transfer or wait for a renewal notice that will never arrive.
## What the Domain Guardian (Registrant Contact) Actually Is
Every domain has a small set of contact records attached to it. The most important of these is the **registrant**: the individual or organisation recorded as the holder of the domain. The nickname "guardian" is apt, because this contact is treated as the ultimate authority over the domain. When something significant happens to the domain, the registrant is who gets asked, and the registrant email is where the message lands.
In practice, the registrant email is the single most consequential field on the whole domain. It is the address that receives the approval request when a domain is being moved between providers, the reminders as the domain approaches expiry, and the verification messages that registries and ICANN send to confirm the details are real. If that address is wrong, out of date, or pointing at a mailbox nobody reads, the domain can drift into trouble without anyone noticing until it is urgent.
## Why an Out-of-Date Registrant Email Is a Real Risk
This is not a tidy-your-records nicety. A stale registrant email is one of the most common reasons ordinary domain problems turn into serious ones. The concrete risks are worth stating plainly.
- **A transfer that silently fails.** When a domain is transferred between providers, the approval or authorisation message is directed to the registrant contact. If it arrives at an address you no longer control, the transfer stalls, times out, and is cancelled. You never see the message, so you never know why nothing happened.
- **A lost verification, leading to suspension.** Registrars accredited by ICANN are required to verify the registrant email for generic domains, both on new registrations and after certain changes. If a verification message is sent to your registrant address and is not confirmed within the required window, which is typically around 15 days, the domain can be **suspended** until you confirm. A suspended domain stops resolving, so the website and email attached to it go dark.
- **A missed renewal, ending in loss.** Expiry and renewal reminders go to the registrant email. Miss them and a domain can lapse, enter a redemption or pending-delete period at extra cost, and ultimately drop, at which point anyone is free to register it. Domains lost this way are often impossible to recover.
The common thread is simple: the most important messages about your domain go to one address, and if that address is wrong, you are flying blind at exactly the moments that matter. Keeping the registrant email current is the cheapest insurance you will ever buy for a domain.
## Registrant, Admin, Tech and Billing: Four Contacts, Different Jobs
A domain traditionally carries four contact roles. They are not interchangeable, and understanding the difference tells you which one to keep watertight.
- **Registrant (the guardian).** The legal holder of the domain and the highest authority over it. This is the contact that governs ownership and, on generic domains, whose change can trigger the transfer rules described below. If you update only one contact, update this one.
- **Administrative (admin) contact.** The person responsible for managing the domain day to day. Historically the admin address received many of the operational notices, so it is worth keeping current too, but it does not carry the ownership authority of the registrant.
- **Technical (tech) contact.** The person who deals with the technical side, such as nameservers and DNS. Relevant for coordination, not for ownership decisions.
- **Billing contact.** The address for invoicing and payment matters relating to the domain.
On many modern domains these four often point at the same person, and for generic domains the public listing of admin, tech and billing details has been sharply reduced for privacy reasons. Regardless of what shows publicly, the registrant remains the record that decides who owns the domain, so treat it as the one that must never be wrong.
## How to Find Your Current Registrant Email
Before you change anything, confirm what the record says now. There are two reliable ways to check.
### From the Noiz client area
Log in to the Noiz client area, open **Domains**, and select the domain you want to inspect. The domain's management page has a **Contact Information** section that shows the stored registrant details, including the email address. This is the authoritative view of what Noiz holds for the domain and what will be pushed to the registry.
### With a WHOIS or RDAP lookup
You can also look the domain up publicly. A registration-data lookup shows how the record appears to the outside world, which is exactly what another provider sees when they process a transfer. The [ICANN Lookup](https://lookup.icann.org) tool is a neutral place to do this. If you are new to reading these results, the Noiz guide on [the WHOIS lookup service](/domains-dns/what-is-the-whois-lookup-service/) explains what each field means. Note that if WHOIS privacy is switched on, the public lookup will show masked or proxy details rather than your real email, which is covered further down.
## How to Update the Registrant Contact in the Noiz Client Area
Updating the registrant is done from the same place you found it.
1. Log in to the Noiz client area and open **Domains**.
2. Select the domain you want to update from your list of domains.
3. Open the domain's **Contact Information** section. Depending on the domain, you may see the registrant on its own or alongside separate admin, tech and billing entries.
4. Edit the registrant details, and in particular the **email address**, so they are accurate and point at a mailbox you actually read. Correct the name, organisation, postal address and phone number at the same time if they have changed.
5. Save the change. Noiz submits the updated details to the registry for the domain.
Two things are worth knowing before you save. First, different top-level domains treat contact changes differently: for some, the update applies quickly and quietly; for others, especially generic domains, changing the registrant email starts a confirmation process that asks you to approve the change by email before it takes effect. Second, a small number of top-level domains restrict registrant edits or require them to be handled through a support request rather than the self-service form. If the fields are locked, greyed out, or the save does not seem to apply, that is usually the reason, and a Noiz support ticket is the way through.
## WHOIS Privacy and the Registrant Email
If you use WHOIS privacy, sometimes called ID protection, the public lookup hides your personal details behind the privacy service and shows a proxy address instead. This is good for keeping your name, home address and email out of public view, but it changes nothing about the underlying obligation: the **real** registrant email stored beneath the privacy service still has to be valid and monitored.
The reason is that the critical messages, the transfer approvals and the verification requests, are still routed to the underlying registrant, usually forwarded through the privacy service to your real address. If that real address is dead, privacy will not save you; the approval simply never reaches a working inbox. Turning privacy on also does not exempt a generic domain from the change-of-registrant process. So treat WHOIS privacy as a shield for your public data, not as a reason to stop maintaining the registrant email underneath it. Keep the underlying address current exactly as you would without privacy.
## The Transfer Lock After a Registrant Change
Here is the gotcha that catches people out, and the reason to update the registrant email *before* you plan a move rather than during one.
### Generic domains (.com, .net, .org and similar)
Under the [ICANN Transfer Policy](https://www.icann.org/resources/pages/transfer-policy-2016-06-01-en), changing the registrant name, organisation or email address on a generic top-level domain is treated as a **Change of Registrant**. Once that change is confirmed, the domain is normally placed under a lock, commonly **60 days**, that prevents transferring it to a different provider during that period. Some registrars allow you to opt out of this lock at the time you make the change, and some do not.
The practical consequence is important: if you are about to transfer a generic domain and you update the registrant email as part of the move, you can trigger the lock and find the transfer blocked for weeks. The safer sequence is to get the registrant email correct well ahead of any planned transfer, let any resulting lock expire, and then transfer. Be aware, too, that ICANN's transfer rules are periodically reviewed and updated, so the exact triggers, the lock length, and whether opting out is offered can change over time and can vary between providers. If the timing of a transfer matters to you, confirm the current position with Noiz support before you change anything.
### .co.za and other .za domains
South African `.za` domains, including `.co.za`, do not run on ICANN's generic-domain transfer policy. The `.za` namespace is administered under [ZADNA](https://www.zadna.org.za), with its own registry and its own rules for registrant changes and for moving a domain between providers. In particular, the ICANN 60-day change-of-registrant lock described above is a generic-domain mechanism and does not apply to `.co.za` in the same way; `.za` transfers use their own authorisation process. That said, the registry's exact handling of a registrant change is something this guide cannot fully verify for your specific domain without checking the registry directly, and the rules can be updated. The honest advice is the same either way: keep the registrant email current, and if you are planning a `.co.za` transfer or a registrant change and want to be certain of the sequence and any waiting period, ask Noiz to confirm the current registry position for you first.
## Troubleshooting
**Symptom: you changed the registrant email and now a transfer is blocked.** On a generic domain this is almost certainly the change-of-registrant lock, typically 60 days. Wait for it to expire, or check with Noiz whether an opt-out was available. This is exactly why the registrant email should be corrected ahead of a planned transfer, not during it.
**Symptom: the transfer-approval or verification email never arrived.** Check the spam and junk folders of the registrant mailbox first. Then confirm, in the client area Contact Information section, that the registrant email is correct and points at a live mailbox. If it was wrong, correct it and ask Noiz to resend the message.
**Symptom: the domain shows as pending verification, or has stopped resolving.** On a generic domain this can mean the registrant email failed ICANN verification and the domain has been suspended. Correct the registrant email, complete the verification message when it is resent, and the domain should be reinstated.
**Symptom: the Contact Information fields will not save, or are locked.** Some top-level domains restrict registrant edits or require them to go through support. Open a Noiz support ticket and the change can be made on your behalf.
**Symptom: a public WHOIS lookup still shows the old details after you saved.** Allow time for the change to propagate to the registry and for cached lookups to refresh. If WHOIS privacy is enabled, remember the public record will show masked details by design, even though the real underlying email has been updated.
## Keep Your Domain Safe: Ask Noiz
The registrant contact is the quietest field on your domain and the one most likely to bite when it is wrong. If you are unsure what your current registrant email is, whether a change will trigger a transfer lock, or how a registrant change works for your particular top-level domain, do not guess with a domain you care about. Open a support ticket and the Noiz team can confirm what the registry holds, make the change safely, and time it around any planned transfer or renewal so nothing is put at risk. A two-minute check now is far cheaper than recovering a domain later.
# What Is the WHOIS Lookup Service?
Source: https://docs.noiz.ie/domains-dns/what-is-the-whois-lookup-service/
When learning how to bring your website online, you will inevitably come across the **WHOIS** lookup service. It is a searchable, public directory of every domain name currently registered in the world. Even if you have never heard the term, it is worth understanding what it does and how it affects you as a domain owner.
**Last reviewed:** 27 July 2026. WHOIS, and its modern successor **RDAP** (Registration Data Access Protocol), are governed by ICANN policy and by the relevant country registries. This guide is written for Noiz customers and is kept current against those policies. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [ICANN Registration Data Lookup Tool](https://lookup.icann.org/en) (the official RDAP-based lookup).
- [ICANN: About WHOIS and RDAP](https://whois.icann.org/en/about-whois).
- [ZA Domain Name Authority](https://www.zadna.org.za) (policy for .za domains such as .co.za).
## What exactly is a WHOIS lookup, and why would I use it?
**WHOIS** is a free public database, and a search service that lets you look up the publicly listed information associated with an already registered domain name. It is regulated by **ICANN**. The information is passed to the registry database by your registrar when you register a domain name.
A **WHOIS** search returns no registration information if a domain is not yet registered, which usually means the name is available for public registration.
The first reason you might use the **WHOIS** service, then, is to check whether a domain is available before you settle on a name for your website. You can do this directly from the [Noiz domain search](https://www.noiz.co.za/cart.php?a=add&domain=register).
Another reason is to report abuse to a website or domain administrator, or to get in touch with a domain owner.
## Why does the WHOIS database exist?
At its inception, the database was meant simply as a domain directory, listing the contact information of anyone transmitting data over the early stages of what is now the internet. This was before the advent of search engines.
## What information is stored in the WHOIS database?
When a domain name is registered, the registrant (probably you) has to supply contact information. This information must be accurate and true: supplying false details when you register a domain can lead to the domain being suspended or cancelled under ICANN policy.
Registrant information typically includes:
- Name.
- Postal address.
- Phone number.
- Email address.
- Nameservers.
### So is all of my information public?
Historically, yes. By default, a registered domain recorded the registrant, the registrar, the technical and abuse contacts, the registrant email address, the nameservers and more.
That has changed. Since the introduction of modern data-protection rules, most personal contact details for individual registrants are now **redacted** by default in the public record for generic top-level domains (such as .com and .org), and are only released by the registrar in response to specific, justified requests. Organisation and technical fields, along with the nameservers and registration dates, generally remain visible.
If you want to keep even more of your details out of the public record, many registrars and hosting providers offer a paid **domain privacy** (WHOIS privacy) service that substitutes proxy contact details for your own. Noiz customers can enable this on eligible domains from the client area. Note that some registries, including the .za registry, do not permit WHOIS privacy on their domains.
## How to perform a WHOIS lookup
There are a few ways to perform a **WHOIS** lookup. This guide covers two:
- An online **WHOIS** service through a web browser.
- The `whois` command from a Linux command line.
### Using an online WHOIS service
The most authoritative source is ICANN itself. Point your browser to the ICANN [Registration Data Lookup Tool](https://lookup.icann.org/en), enter the domain name you want to search, complete the captcha and click **Lookup** to view the results. This tool now uses **RDAP**, the structured successor to the original WHOIS protocol, which ICANN has been retiring since early 2025.
The ICANN tool does not cover .co.za domains. South Africa's old whois.co.za web lookup is now defunct, so for .za domains the command-line method below is the most reliable option, as it queries the correct .za registry server automatically.
Other general-purpose online WHOIS services include:
- [https://www.whois.com/](https://www.whois.com/)
- [https://who.is/](https://who.is/)
### Using the whois command on Linux
From a Linux terminal, run the command (using `noiz.co.za` as an example, which you would replace with the domain you want to look up):
```markup
whois noiz.co.za
```
The tool returns all of the public information available for that domain, and automatically contacts the right registry server for the domain's extension.
If the `whois` command is not installed, update your package lists and install it:
```markup
sudo apt update
sudo apt install whois
```
Then run the lookup again as shown above.
## Summary
You now know what the WHOIS database is, what it stores, how to search it with both a browser and the command line, and how modern privacy rules and RDAP have changed what you will actually see in the results.
If you have registered a domain with Noiz and need help checking or updating its public records, or enabling domain privacy, the Noiz support team is happy to assist from your client area.
# Your Free .co.za Domain with Noiz Shared Hosting
Source: https://docs.noiz.ie/domains-dns/your-free-coza-domain-with-noiz-shared-hosting/
This guide is for anyone about to buy, or who has just bought, a Noiz shared or reseller hosting plan and has seen that it comes with a free `.co.za` domain. It explains, in plain terms, exactly what that free domain is and is not: which plans include it, which domain extensions are covered, how to claim your free registration when you order hosting or afterwards from the client area, and, most importantly, what happens when the domain comes up for renewal a year later. It also covers the common case where you already own a domain and would rather keep it, in which case there is nothing to register and you point your existing domain at Noiz instead.
One distinction runs through everything below, so it is worth fixing in your mind at the outset. **Registration** is the one-off act of taking a brand-new domain name that nobody currently owns and putting it in your name for a period, usually a year. **Renewal** is paying again, each period after that, to keep it. The word "free" in "free domain" refers to the first registration that comes bundled with your hosting. Renewals are a separate, recurring domain charge that continues for as long as you want to keep the name. Keeping those two ideas apart is the single biggest thing that prevents a surprise on a future invoice.
**Last reviewed:** 27 July 2026, against the current Noiz shared and reseller hosting plans and the Noiz client area. Which domain extensions a given plan includes for free, and what a renewal costs, are commercial terms that Noiz can change from time to time. For that reason this guide deliberately sends you to your chosen plan's page and to your own invoice for the exact figures, rather than printing numbers here that would quietly go out of date. It complements, and does not replace, the `.za` registry rules referenced below.
### Official Documentation Reference
- [ZADNA, the .za Domain Name Authority](https://www.zadna.org.za/): the statutory authority for South Africa's `.za` namespace, which includes `.co.za`, `.net.za`, `.org.za` and `.web.za`. This is the authoritative source for your rights as a registrant and for the rules that govern local domains, including renewal and expiry.
- [IANA Root Zone Database: .za delegation record](https://www.iana.org/domains/root/db/za.html): the authoritative delegation record for the South African country-code top-level domain, showing the chain of authority under which every `.co.za` name sits.
The genuinely authoritative source for what *your* plan includes and what it will cost to renew is not any of the links above. It is the plan page you order from and the invoice Noiz issues you. Everything in this guide is written to help you read those two documents correctly, not to substitute for them.
## Prerequisites
- You are ordering, or already hold, a Noiz shared or reseller hosting plan. The free domain is bundled with hosting; it is not sold on its own.
- You have a name in mind that you would like as `yourdomain.co.za`, written that way throughout as an example to replace with the name you actually want. It helps to have a second choice ready in case your first is already taken.
- You can sign in to the Noiz client area, or you are at the checkout stage of ordering hosting, which is where the free registration is offered.
- If you already own a domain and intend to keep it, you have access to it at your current registrar. In that case you will not be registering anything new; see [If You Already Own a Domain](#already-own) below.
## What the Free Domain Actually Is
When a Noiz shared or reseller hosting plan advertises a free domain, it means the plan includes a credit that covers the **first registration** of one new domain, at no extra charge, when you take the hosting. The domain and the hosting are set up together, and the registration is handled for you as part of the order.
The extension included as standard is `.co.za`, South Africa's commercial second-level domain and by far the most common choice for a South African site. Some plans, typically the larger shared plans and the reseller plans, extend the free registration to further members of the `.za` family, such as `.net.za`, `.org.za` and `.web.za`. Whether your plan covers only `.co.za` or several of these is a per-plan detail, and it is shown on the plan's own page and again on the order form when you choose your domain. This guide will not list which plan includes which extensions, precisely because that is the kind of thing Noiz adjusts over time; the order form is always the current, correct answer.
A quick word on what those extensions signify, since people often wonder which to pick:
- **`.co.za`** is the default general-purpose and commercial choice, and the one most South African visitors expect to type.
- **`.net.za`** was originally intended for network-related organisations, though it is now used broadly.
- **`.org.za`** suits non-profit and community organisations.
- **`.web.za`** is a general alternative often used when a `.co.za` is already taken.
All four are governed by the same `.za` authority and behave identically in technical terms. Pick the one that best fits how you want to be found; if your plan includes only `.co.za` for free and you would prefer another, you can usually still register it, just not under the free credit. What that other registration costs is shown at the point of ordering.
## What the Free Domain Is Not
Being clear about the edges of the offer saves disappointment later.
- **It is not free forever.** The credit covers the initial registration. From the next renewal onward, the domain is billed at the standard `.za` renewal rate, as explained under renewals below.
- **It does not usually cover a `.com`, `.net` or other international extension.** The free registration is for the `.za` extensions your plan lists. A `.com` or similar is registered at its normal price. If your plan is silent on an extension, treat it as not covered by the free credit and check the price on the order form.
- **It is one domain, not many.** The credit applies to a single new registration bundled with the plan. Additional domains are registered at their normal price.
- **It is for a new registration, not for a domain you already own.** If you already hold the name you want, there is nothing to register; you point that existing domain at your Noiz hosting instead. There is more on this below.
## How to Claim Your Free Domain
There are two moments at which you can claim the free registration: during checkout when you first order the hosting, which is the cleaner path, or afterwards from within the client area.
### At checkout, while ordering hosting (recommended)
The most reliable way to claim the free domain is to register it as part of the same order that buys the hosting, because the free credit is designed to apply at exactly that point.
1. Choose your shared or reseller plan on the Noiz website and begin the order.
2. At the domain step of the order, choose the option to **register a new domain**, then search for the name you want, entering it as `yourdomain` and selecting the extension. If your first choice is already taken, the search will say so and you can try another name or another eligible extension.
3. When you pick a name and extension that your plan covers, the order form shows the first-period registration as free. Confirm that the domain line reads as free before continuing; this is your on-screen proof that the credit has applied.
4. Complete the order and pay for the hosting as normal. Noiz registers the domain and connects it to your hosting, setting the Noiz nameservers `ns1.noiz.co.za` and `ns2.noiz.co.za` for you, so the domain is pointed at your site from the start.
### Afterwards, from the client area
If you did not register a domain when you first ordered, or you want to add one to an existing service, you can also start a registration from the client area.
1. Sign in to the Noiz client area and open the **Domains** area, then choose to **register a new domain**.
2. Search for the name and extension you want, in the same way as at checkout.
3. Add it to your cart and review the price. Whether the free credit applies automatically when you register separately, rather than alongside a new hosting order, depends on how the offer is configured for your plan. If the domain shows as free, complete the order. If it shows the standard registration price and you believe your plan entitles you to a free one, do not pay first and query later; open a support ticket, quote your plan and the domain you want, and let Noiz apply the credit before the registration is processed.
## What Happens at Renewal
This is the part worth reading slowly, because it is where the honest limits of "free" live. A `.za` domain is registered for a period, normally one year. The free credit pays for that first period. When the period is coming to an end, the domain must be renewed to stay yours, and that renewal is charged at the standard rate for the extension. The renewal is a genuine cost that Noiz passes on, so it is not something the free offer removes; it simply was not due yet when you registered.
In practice this means:
- **Your first year is free** (or first period, if the registration term differs), because the plan's credit covered the initial registration.
- **Each renewal after that is billed at the normal `.za` rate**, unless your plan page explicitly states that renewals are also included, which is unusual. Do not assume free renewals; assume standard renewals unless the plan says otherwise in writing.
- **The renewal is separate from your hosting fee.** Hosting and the domain are two different services with their own charges, even though they were ordered together and may fall due around the same time.
- **You will be invoiced before the renewal date.** Noiz sends a renewal invoice ahead of time so the domain does not lapse. The exact renewal amount for your extension is shown on that invoice.
The single most useful habit here is to read the domain line on your invoices. The invoice, not this guide and not the plan's headline, is the authoritative statement of what you are paying and for what period. If a renewal amount ever looks wrong, that invoice is the thing to raise with Noiz support.
## If You Already Own a Domain
The free domain is a nice extra when you are starting fresh, but many people come to Noiz already owning the name they want to use, whether a `.co.za` or a `.com`. If that is you, the free registration is simply not relevant: there is nothing to register, because the name is already yours. You have two straightforward choices.
- **Keep the domain where it is and point it at Noiz.** You leave the domain registered with your current registrar and change where it points so that your website and email load from your Noiz hosting. This needs no transfer and no new registration. The full method is in [How to Point Your Domain to Noiz](/domains-dns/how-to-point-your-domain-to-noiz-hosting/), which walks through delegating to the Noiz nameservers or pointing individual records. This is the usual route when you already own a name.
- **Register a different new domain under the free credit anyway.** There is nothing stopping you from claiming the free `.co.za` for a new name even though you already have one, for example to protect a variation of your brand or to run a second site. It is your credit to use if you have a use for it.
What the free offer cannot do is retroactively make a domain you registered elsewhere free, or refund what you paid another registrar. The credit only applies to a new registration placed through Noiz.
## Troubleshooting
- **Symptom: the domain is not showing as free at checkout.** First confirm the extension you chose is one your plan covers; a plan that includes a free `.co.za` may not include a free `.net.za`, and a `.com` is not part of the `.za` offer at all. Check the plan's page for the extensions it lists. If you have chosen an eligible extension and it still shows a price, the free credit may be tied to a particular billing term for the hosting, so review the term selected. If it still does not apply, stop before paying and contact Noiz support with your plan and the domain you want.
- **Symptom: you were charged for the domain.** Look at the invoice line for the domain and note whether it is a first-time **registration** or a **renewal**. A renewal charge is expected and correct: the free credit only ever covered the first period. A registration charge on a plan you believe includes a free domain is worth querying; open a ticket with the invoice number so Noiz can check whether the credit should have applied.
- **Symptom: your first-choice name is already taken.** Domain names are first come, first served, and a great many `.co.za` names are already registered. Try a variation, or one of the other `.za` extensions your plan may include, such as `.web.za`. The order form's search tells you instantly what is available.
- **Symptom: you want to use a domain you already own instead of registering a new one.** You do not need the free registration at all. Leave the domain with your current registrar and follow [How to Point Your Domain to Noiz](/domains-dns/how-to-point-your-domain-to-noiz-hosting/) to point it at your hosting.
- **Symptom: you registered the free domain but the site does not load yet.** A brand-new registration and its hosting take a short while to become visible across the internet as DNS updates. When the domain was registered together with the hosting, the Noiz nameservers are already set for you, so this is normal settling time rather than a misconfiguration. Allow a little while and check again.
## Noiz Support
If you are unsure whether your plan includes a free domain, which extensions it covers, or what a renewal will cost, the quickest answer is to open a ticket with the Noiz support team, or to read the plan page and your latest invoice, which carry the current figures. When you contact support, mention your plan and the exact domain name and extension you want, for example `yourdomain.co.za`, so the team can confirm your eligibility and apply the free registration correctly. If you already own a domain and only need it connected to your Noiz hosting, say so, and support can guide you through pointing it rather than registering something new.
# How to Block an IP Address Using an htaccess Rule
Source: https://docs.noiz.ie/security/how-to-block-an-ip-address-using-an-htaccess-rule/
This guide shows you how to block one or more IP addresses from reaching a website using a rule in the site's `.htaccess` file. It works on any website served by Apache, so you do not need a particular control panel to use it, and the rules travel with your site if you move it. If you would rather block an address from inside cPanel instead of editing a file by hand, see the companion guide [How to Block an IP Address in cPanel](/cpanel/how-to-block-an-ip-address-in-cpanel/).
**Last reviewed:** 27 July 2026, against the Apache HTTP Server **2.4** series (current stable). This guide is written for Noiz hosting and is kept current against Apache. It complements, and does not replace, the official Apache documentation linked below.
### Official Documentation Reference
- [Apache HTTP Server: Access Control How-To](https://httpd.apache.org/docs/2.4/howto/access.html)
- [Apache `mod_authz_core`: the `Require` directive](https://httpd.apache.org/docs/2.4/mod/mod_authz_core.html#require)
- [Apache `mod_authz_host`: `Require ip` and `Require host`](https://httpd.apache.org/docs/2.4/mod/mod_authz_host.html)
- [Apache: Upgrading 2.2 access control to 2.4](https://httpd.apache.org/docs/2.4/upgrading.html#access)
## Prerequisites
- Access to your website's files, through your hosting control panel's **File Manager** or over SFTP or FTP.
- The IP address you want to block. If you are acting on abusive traffic, take the address from your raw access logs or your control panel's visitor statistics so you block the right visitor.
- A site served by Apache. On Nginx and some other web servers the `.htaccess` file is ignored entirely, so these rules have no effect there.
## Where the Rule Goes
The `.htaccess` file lives in your website's document root, usually the `public_html` or `httpdocs` folder, or inside the specific subfolder you want to protect. The rule applies to that folder and everything beneath it, so a file in the document root covers the whole site while a file in an admin subfolder restricts only that area.
The filename begins with a dot, which makes it hidden by default. Enable **Show hidden files (dotfiles)** in File Manager if you cannot see it, and create the file if it does not yet exist.
**Back up first.** A single typo in `.htaccess` can take the whole site offline with a **500 Internal Server Error**, so download or copy the existing file before you change it. Restoring a known-good copy is the fastest way out of a bad edit.
## Block a Single IP Address
Add the following block to your `.htaccess` file and save it. The `Require all granted` line keeps the site open to everyone, and `Require not ip` carves out the address you want to refuse.
```apacheconf
Require all granted
Require not ip 203.0.113.45
```
Replace `203.0.113.45` with the address you want to block. The address shown is a reserved documentation example, so it is safe to paste while you find your way around, but it will not block anything real.
The block takes effect on the very next request. There is nothing to restart and no cache to clear. The blocked visitor receives a `403 Forbidden` response.
### Why the RequireAll Wrapper Is Not Optional
This is the detail most snippets on the web get wrong. Apache treats a plain list of `Require` lines as a *RequireAny* group, where any one satisfied condition grants access. A negated condition such as `Require not ip` can never grant access on its own, so left unwrapped it refuses everybody and takes your site down for all visitors.
Wrapping the pair in `` changes the logic to "every condition must hold": access is granted, **and** the visitor is not the address you named. Always keep the two lines together inside the block.
## Block Several Addresses, Ranges or Networks
Add as many `Require not ip` lines as you need, or list several values on one line separated by spaces. All the usual notations are accepted:
```apacheconf
Require all granted
Require not ip 203.0.113.45 203.0.113.60
Require not ip 198.51.100.0/24
Require not ip 192.0.2
Require not ip 2001:db8::/32
```
- **Single address:** `203.0.113.45`
- **CIDR range:** `198.51.100.0/24` covers `198.51.100.0` through `198.51.100.255`
- **Partial address:** `192.0.2` covers the whole `192.0.2.*` range, and `192.0` covers `192.0.*.*`
- **IPv6:** full addresses and prefixes both work, for example `2001:db8::/32`
Watch for the address family. If a visitor can reach your site over IPv6 and you have only blocked their IPv4 address, they will still get through. When you are dealing with a persistent nuisance, check your logs for both.
## Allow Only Your Own Address
The reverse case is useful for a staging site or an admin folder that only you should reach. Place an `.htaccess` file containing this line inside the folder you want to restrict:
```apacheconf
Require ip 203.0.113.45
```
Everyone except that address receives a `403 Forbidden`. Replace the example with your own address, which you can find by searching the web for "what is my IP". No `` wrapper is needed here because this is a positive condition rather than a negated one.
Take care with this on a home or mobile connection. Most residential and mobile lines use dynamic addresses that change without warning, so a rule that works today may lock you out tomorrow.
## If You See the Older Apache 2.2 Syntax
Plenty of guides, and earlier versions of this article, use the older style:
```apacheconf
Order allow,deny
Deny from 203.0.113.45
Allow from all
```
Two things are worth knowing about it. First, `Order` takes a comma-separated pair with **no space after the comma**. Writing `order allow, deny` is a syntax error that will bring the site down with a 500 Internal Server Error, and it is one of the most common causes of a site breaking immediately after an `.htaccess` edit.
Second, these directives were deprecated in Apache 2.4 and only function while the `mod_access_compat` module is loaded. That module is still present on many servers, but it is a compatibility shim rather than a supported long-term option, and mixing the old and new styles in the same configuration gives unpredictable results. Use the `Require` form shown above for anything new, and convert legacy rules when you next touch them rather than layering one style on top of the other.
## Troubleshooting
**Symptom: a 500 Internal Server Error appears as soon as you save.** There is a syntax error in the file. Restore your backup, then re-add the rule carefully, checking for a stray space (as in `order allow, deny`), a missing `` closing tag, or a directive your server does not support. Adding the lines back one at a time will identify the offending line quickly.
**Symptom: every visitor is blocked, not just the address you named.** The `Require not ip` line is missing its `` wrapper and the accompanying `Require all granted` line. See the explanation above.
**Symptom: the blocked visitor still gets through.** The usual cause is that Apache is not seeing the visitor's real address. If your site sits behind a content delivery network, reverse proxy or firewall service, every request arrives from that service's own IP address and the visitor's address travels in a header instead. Block the visitor in the CDN or proxy control panel rather than in `.htaccess`. Otherwise, confirm you edited the `.htaccess` file in the document root actually serving the site, and that the address in your logs matches the one you blocked.
**Symptom: the rule has no effect at all.** Confirm the site runs on Apache and that `AllowOverride` permits these directives for the folder. On Nginx and other non-Apache servers, `.htaccess` is never read. If nothing in the file has any effect, open a support ticket and the team will confirm what your site is served by.
**Symptom: you have blocked yourself.** Reach your control panel from a different connection, such as mobile data or a phone hotspot, and edit the file to remove the rule. Control panel, FTP and SFTP access are separate from web access, so an `.htaccess` block never shuts you out of file management.
## Good to Know
- **What it covers:** these rules control HTTP and HTTPS access to your website only. They do not block email, FTP or SSH.
- **Dynamic addresses:** a determined visitor on a home or mobile connection can pick up a new address within minutes. Blocking a range lasts longer, but weigh that against catching innocent visitors on the same network.
- **Search engines:** avoid blocking ranges belonging to search engine crawlers, or your pages may begin dropping out of search results.
- **Scale:** `.htaccess` is read on every single request. A handful of block rules costs nothing measurable, but a list running to hundreds of entries is a sign the problem needs a firewall or CDN rule instead.
## Need a Hand?
If you are on a managed Noiz plan and would like the block applied for you, or you are dealing with sustained abusive traffic that a single rule will not stop, open a support ticket from your Noiz client area and the team will help you put the right protection in place at the right layer.
# How to Disable Directory Browsing Using .htaccess
Source: https://docs.noiz.ie/security/how-to-disable-directory-browsing-using-htaccess/
Directory browsing, also called directory listing or directory indexing, is the behaviour where a web server, finding no index file (such as `index.html` or `index.php`) in a folder, shows visitors an automatically generated list of every file and sub-folder it contains instead. That listing can expose backups, configuration files, scripts, and other material you never intended the public to see, which makes it a common target during reconnaissance. This guide shows you how to switch directory browsing off across your whole site with a single line in your `.htaccess` file, how to confirm it worked, and where the rule can catch you out.
**Last reviewed:** 27 July 2026, against Apache HTTP Server **2.4** (current stable series). This guide is written for Noiz hosting and is kept current against Apache. It complements, and does not replace, the official Apache documentation linked below.
### Official Documentation Reference
- [Apache HTTP Server: the `Options` directive](https://httpd.apache.org/docs/2.4/mod/core.html#options)
- [Apache HTTP Server: `mod_autoindex` (directory indexing)](https://httpd.apache.org/docs/2.4/mod/mod_autoindex.html)
- [Apache HTTP Server: the `DirectoryIndex` directive](https://httpd.apache.org/docs/2.4/mod/mod_dir.html#directoryindex)
- [Apache HTTP Server: `.htaccess` files how-to](https://httpd.apache.org/docs/2.4/howto/htaccess.html)
## Prerequisites
- A Noiz hosting account you can sign in to, with access to your site's files through the File Manager or FTP.
- A site served by Apache. The `.htaccess` file is read only by Apache, so this method has no effect on a site served purely by Nginx. If you are unsure which applies to your account, open a support ticket and the Noiz team will confirm.
- A copy of your current `.htaccess` file, saved before you make any change. A single typo in this file can take the whole site offline with a **500 Internal Server Error**, so always have something to roll back to.
## Check Whether Directory Browsing Is Currently On
Test before you change anything, so you know whether there is a problem and can tell afterwards that the fix worked. In a browser, request a folder on your site that contains no index file, remembering the trailing slash, for example `https://yourdomain.com/uploads/`. Replace `yourdomain.com` with your own domain.
- A page headed **Index of /uploads** listing the folder's contents means directory browsing is enabled and worth switching off.
- A **403 Forbidden** response means listings are already blocked.
- A **404 Not Found** response means there is no folder at that path, so pick a different one to test.
Choose a folder that genuinely has no `index.html` or `index.php` in it. A folder that has one will always serve that file, which tells you nothing about the autoindex setting.
## Add the Rule to .htaccess
The `.htaccess` file is a plain text configuration file that Apache reads from the folder it sits in. Its name begins with a dot, which marks it as a hidden file, so you may need to enable **Show Hidden Files (dotfiles)** in your File Manager to see it. Place the rule in the `.htaccess` file at the root of your website (for example `httpdocs` or `public_html`, depending on your hosting plan) to protect every folder on the site.
1. Open your site's document root in the File Manager or over FTP.
2. Open the existing `.htaccess` file for editing. If there is no `.htaccess` file yet, create one with exactly that name, including the leading dot and with no file extension.
3. Add the following line:
```apacheconf
Options -Indexes
```
4. Save the file. The change takes effect immediately, because Apache re-reads `.htaccess` on every request. There is nothing to restart.
The minus sign in `-Indexes` is what does the work: it removes the `Indexes` option, which is the option that tells Apache to generate a listing when no index file is present. A line reading `Options +Indexes` would switch the behaviour back on, so check for that if a folder is still showing its contents.
Use the `-` prefix rather than writing a bare option list. `Options -Indexes` subtracts one option and leaves everything else the folder inherits untouched. Writing something like `Options FollowSymLinks` with no prefix replaces the entire inherited set, which can silently disable behaviour other parts of your site depend on and is awkward to diagnose weeks later.
## Confirm It Is Working
Re-request the same folder you tested earlier, for example `https://yourdomain.com/uploads/`. Where you previously saw a list of files, Apache now returns a **403 Forbidden** page, which is exactly what you want: the folder's contents are hidden while the files inside it remain reachable by their direct URLs.
If you still see the old listing, load the page in a private browsing window. Browsers and any content delivery network sitting in front of your site will happily keep serving a cached copy of the listing after the rule is in place.
## Allow Listings in One Folder Only
The rule inherits downwards, so if you deliberately want a listing in a single folder, such as a public download archive, place a separate `.htaccess` in that folder containing the opposite rule.
```apacheconf
Options +Indexes
```
Be deliberate about this. Every file that lands in that folder becomes discoverable by anyone who visits it, including files an upload script, plugin or backup job puts there without your knowledge.
## Make Sure Your Index File Is Recognised
Apache only falls back to a listing when it cannot find a file named in the `DirectoryIndex` list. On a typical hosting account that list covers `index.html` and `index.php`. If a folder's landing page is named something else, name it explicitly so the server serves it instead of returning 403.
```apacheconf
DirectoryIndex index.php index.html home.php
```
You can also give visitors a friendlier response than the default 403 page by pointing Apache at a custom error page. The path is relative to your document root, and the target page must itself be reachable.
```apacheconf
Options -Indexes
ErrorDocument 403 /403.html
```
## Good to Know
- The rule applies to the folder it sits in and every folder beneath it, so a single `.htaccess` at your document root covers the whole site. You can override it for one folder by placing a separate `.htaccess` there.
- Disabling directory browsing hides the listing, it does not protect the files themselves. Anyone who already knows or guesses a file's exact URL can still request it. Treat this as one layer of hardening, not a substitute for proper permissions on anything sensitive. If a file must never be public, move it above the document root, put it behind authentication, or delete it.
- Adding an empty `index.html` to a folder achieves a similar result for that one folder, but it is a per-folder patch you have to repeat forever and it is easy to miss a folder created later by a script. `Options -Indexes` is cleaner because it protects every existing and future folder at once and needs no upkeep.
- Listings are exactly what automated scanners look for, and what they routinely turn up is material nobody meant to publish: `backup.zip`, `db.sql`, `config.php.bak`, an old staging copy, or documents dropped into an uploads folder. None of that is protected by simply being unlinked, only by nobody knowing the file name.
- Some Noiz hosting plans already disable directory browsing at the server level. If a test folder returns **403 Forbidden** before you change anything, the protection is already active and the rule simply makes it explicit and portable, so it travels with the site if it is ever moved.
## Troubleshooting
**Symptom:** the site returns a 500 Internal Server Error as soon as you save. The most likely cause is that `Options` is not permitted in `.htaccess` for that folder, which writes an `Options not allowed here` line into the error log. Restore your backup to bring the site straight back, then open a support ticket so the override can be enabled for your account.
**Symptom:** one folder still lists its contents while the rest of the site is fine. A `.htaccess` inside that folder overrides the one above it, so check that folder for a stray `Options +Indexes` or `Options All` line.
**Symptom:** the whole site now returns 403 Forbidden. That is not caused by `Options -Indexes` on its own. Confirm your document root still contains a valid index file, and check whether another rule in `.htaccess` is denying access.
**Symptom:** nothing changes and nothing is logged. The site is most likely not served by Apache. Nginx and similar servers ignore `.htaccess` entirely and control listings in their own configuration.
## Related Guides
- [How to Protect the htaccess File](/security/how-to-protect-the-htaccess-file/)
- [How to Password Protect a Directory in cPanel](/cpanel/how-to-password-protect-a-directory-in-cpanel/)
- [How to Edit the .htaccess File in the cPanel File Manager](/cpanel/how-to-edit-the-htaccess-file-in-the-cpanel-file-manager/)
## Need a Hand?
If a folder is still listing its contents after you add the rule, or you would like Noiz to review your site's `.htaccess` hardening for you, open a support ticket from your Noiz client area and the team will assist.
# How to Generate a CSR (Certificate Signing Request) in cPanel
Source: https://docs.noiz.ie/security/how-to-generate-a-csr-certificate-signing-request-in-cpanel/
A Certificate Signing Request (CSR) is the block of encoded text a Certificate Authority (CA) asks for when you buy an SSL/TLS certificate. It carries your domain name and organisation details, and it is mathematically tied to a private key that stays on the server. This guide shows you how to generate a CSR in cPanel on your Noiz hosting account, and explains the details that most often cause a CA to reject a request.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (current release tier). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: SSL/TLS interface](https://docs.cpanel.net/cpanel/security/ssl-tls/), including the Private Keys, Certificate Signing Requests and Certificates sections.
- [cPanel Documentation: SSL/TLS Wizard](https://docs.cpanel.net/cpanel/security/ssl-tls-wizard/), for purchasing and installing a certificate from inside cPanel.
- [cPanel Documentation: SSL/TLS Status](https://docs.cpanel.net/cpanel/security/ssl-tls-status/), the interface that reports AutoSSL coverage per domain.
## Do You Actually Need a CSR?
Most Noiz-hosted sites never need one. cPanel issues and renews free domain-validated certificates automatically through AutoSSL, and those certificates are generated for you with no CSR involved. Before you start, check whether your site is already covered: see [How to Install an SSL on Your Domain Using AutoSSL in cPanel](/security/how-to-install-an-ssl-certificate-on-your-domain-using-autossl-in-cpanel/).
Generate a CSR manually when one of the following applies:
- You are buying a commercial certificate from a specific CA, for example an organisation-validated (OV) or extended-validation (EV) certificate that shows your registered company details.
- You need a wildcard certificate covering `*.yourdomain.com`.
- You are reissuing or renewing an existing purchased certificate and the CA has asked for a fresh CSR.
- You need a self-signed certificate for a staging or internal service.
## Prerequisites
- A cPanel hosting account with Noiz, and your cPanel login details from the welcome email or the Noiz client area.
- The domain name the certificate must cover, already pointed at the account.
- Your exact registered organisation details if you are buying an OV or EV certificate. The CA verifies these against public records, so they must match.
- The **SSL/TLS** feature enabled on your package. It is enabled on standard Noiz cPanel packages; if the icon is missing, open a support ticket.
## Step 1: Open the SSL/TLS Interface
1. Log in to cPanel.
2. In the **Security** section, click **SSL/TLS**.

On some cPanel builds this opens as a tab inside a combined **SSL/TLS Certificates** screen rather than as a standalone page. The sections and buttons are identical either way.
## Step 2: Open the Certificate Signing Requests Section
Under **Certificate Signing Requests (CSR)**, click **Generate, view, or delete SSL certificate signing requests**. Older cPanel versions labelled this link **Generate, View or Delete CSR**, and the screenshot below reflects that wording; the position on the page has not changed.

The page that opens has two parts: a **Certificate Signing Requests on Server** table listing any requests you have already made, and a **Generate a New Certificate Signing Request (CSR)** form below it.
## Step 3: Choose the Private Key
Current cPanel versions start the form with a **Key** menu, because a CSR can only be created against a private key. You have two options:
- **Select an existing key** if you already generated one under **Private Keys (KEY)**, for example when reissuing a certificate that must keep the same key.
- **Select a key type to generate a new key**, which is the normal choice for a first-time certificate. RSA 2,048-bit is the safest default for compatibility. ECDSA keys are smaller and faster, but confirm your CA supports them before you commit.
The account-wide default comes from the **Default SSL/TLS Key Type** setting on the main SSL/TLS page, so changing that changes what this menu pre-selects.
The private key never leaves the server and is never sent to the CA. Keep this in mind: if you later delete that key, or generate the CSR on one server and buy the certificate for another, the issued certificate cannot be installed. Generate the CSR on the server where the certificate will live.
## Step 4: Complete the CSR Details
Fill in the fields below the **Key** menu:
- **Domains:** the fully qualified hostname the certificate must secure, such as `www.yourdomain.com` (replace this with your own domain). For a wildcard certificate enter `*.yourdomain.com`. Everything the certificate must cover has to be listed before you generate, because names cannot be added to a CSR afterwards.
- **City:** the full city name, for example `Cape Town`. Do not abbreviate.
- **State:** the full province or state name, for example `Western Cape` or `Gauteng`. CAs routinely reject two-letter abbreviations here.
- **Country:** choose from the drop-down menu, which supplies the correct two-letter ISO code (`ZA` for South Africa). Typing a country name into this field is one of the most common causes of a rejected request.
- **Company:** your registered organisation name, exactly as it appears on your company registration. If the certificate is not for a business, enter your own legal name.
- **Company Division:** the department or unit, for example `IT`. Optional for most certificate types.
- **Email:** an address you can receive mail on, since some CAs use it for validation messages.
- **Passphrase:** optional. This is the challenge password embedded in the request, not a password protecting your private key. Most CAs ignore it and a few reject requests that contain one, so leaving it blank is usually the safer choice. If you do set one, keep it short and use letters and numbers only.
- **Description:** a label for your own reference, so you can identify this request later in the table.

Use plain characters throughout. Ampersands, accented letters and punctuation in the company or city fields frequently fail CA validation, so write `Smith and Sons` rather than `Smith & Sons` unless the CA has told you otherwise.
A note on `www`: most CAs issue a certificate for `www.yourdomain.com` that also covers the bare `yourdomain.com` as a Subject Alternative Name, but that is the CA's policy rather than something cPanel controls. Confirm the coverage on the order page before you pay.
## Step 5: Generate and Save the CSR
1. Click **Generate**.
2. cPanel displays the encoded request. Copy the entire block, including the `-----BEGIN CERTIFICATE REQUEST-----` and `-----END CERTIFICATE REQUEST-----` lines and every character between them.
3. Paste it into a plain text file and keep it somewhere safe. You will need it when placing the order, and again if the CA asks you to reissue the certificate.

The request stays saved in your account, so you do not need to regenerate it if you close the page. To fetch it again later, see [How to Retrieve a CSR from cPanel](/security/how-to-retrieve-a-saved-csr-in-cpanel/). To clear out requests you no longer need, see [How to Remove a CSR Code in cPanel](/security/how-to-remove-a-csr-code-in-cpanel/).
## What Happens Next
Submit the CSR to your chosen CA and complete their validation, which for a domain-validated certificate usually means answering an email or publishing a DNS or file-based token. The CA then returns a signed certificate, plus a CA bundle or intermediate chain.
Install the result from the same SSL/TLS page, under **Install and Manage SSL for your site (HTTPS)**. Because cPanel already holds the matching private key, it fills that field in for you once you select the domain.
## Troubleshooting
**Symptom**: the form will not let you generate, or no key is available. You must have a private key first. Return to the SSL/TLS page, open **Private Keys (KEY)**, generate one, then start the CSR again.
**Symptom**: the CA rejects the CSR for an invalid country or state. Re-select the country from the drop-down rather than typing it, and write the province or state name in full.
**Symptom**: the CSR contains the wrong domain or wrong organisation details. A CSR cannot be edited after generation. Delete it and create a new one with the corrected values, then supply the new CSR to the CA.
**Symptom**: the CA reports that it is not authorised to issue for your domain. A CAA record in your DNS zone restricts which CAs may issue certificates for that name. Check the zone in cPanel under **Domains** > **Zone Editor** and either remove the conflicting CAA record or add one naming your chosen CA. If no CAA records exist at all, any CA may issue, and this error points elsewhere.
**Symptom**: the issued certificate will not install and cPanel reports a key mismatch. The certificate was signed against a different CSR or private key than the one on this server. Retrieve the original private key, or generate a fresh CSR and ask the CA to reissue.
**Symptom**: the certificate installs but browsers still warn. The intermediate chain is usually missing. Reinstall the certificate with the CA bundle the CA supplied alongside it.
## Need a Hand?
Certificate purchases fail on small details far more often than on anything technical, so if a CA has bounced your request and the reason is not obvious, send Noiz support the exact error alongside your domain name. If your site only needs standard HTTPS rather than a branded or wildcard certificate, ask Noiz support to confirm AutoSSL coverage first, since that route needs no CSR and renews itself.
# How to Install an SSL Certificate on Your Domain Using AutoSSL in cPanel
Source: https://docs.noiz.ie/security/how-to-install-an-ssl-certificate-on-your-domain-using-autossl-in-cpanel/
AutoSSL is the cPanel feature that issues and renews a free domain-validated SSL certificate for your domains automatically, so your site loads over `https://` without you buying or installing anything. In normal operation you never touch it. This guide covers the case where it has not fired: your domain is still showing as unsecured, and you want to force AutoSSL to run now and tell you why it failed.
**Last reviewed:** 27 July 2026, against cPanel & WHM **136** (current RELEASE tier). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel: SSL/TLS Status](https://docs.cpanel.net/cpanel/security/ssl-tls-status/), the interface used throughout this guide.
- [cPanel: Guide to SSL](https://docs.cpanel.net/knowledge-base/security/guide-to-ssl/), background on certificate types and validation.
- [Let's Encrypt: Rate Limits](https://letsencrypt.org/docs/rate-limits/), relevant if you have already retried many times.
## Prerequisites
- Access to your cPanel account.
- The domain's DNS already pointing at your Noiz hosting server. AutoSSL cannot validate a domain that does not resolve to the server holding the account.
- The domain not currently excluded from AutoSSL. See [How to Include or Exclude a Domain from AutoSSL in cPanel](/cpanel/how-to-include-or-exclude-a-domain-from-autossl-in-cpanel/).
If your control panel has no **SSL/TLS Status** page under a **Security** section, your hosting is not on cPanel and this procedure does not apply. Open a ticket and Noiz support will handle the certificate on the panel you are actually using.
## Before You Force a Run: Check the Last Result
cPanel runs AutoSSL on a schedule on the server, so a newly added domain is usually secured within a few hours without any action. If more than 24 hours have passed and the domain is still unsecured, read the last result first. Forcing a run without reading the error just repeats the same failure and consumes certificate authority rate limit allowance.
1. Log in to your cPanel account.
2. In the **Security** section, click **SSL/TLS Status**.
3. Find your domain in the list and read its **Certificate Status**. Domains that AutoSSL attempted and failed are marked with an AutoSSL problem, and the message explains what the validation could not do.

Two outcomes matter here:
- **There is an error message.** Work through the [Troubleshooting](#troubleshooting) section below. Most AutoSSL failures are caused by something on the domain itself, and fixing that is what makes the next run succeed.
- **There is no error message and the domain simply is not secured.** AutoSSL never picked the domain up. Force a run using the steps below.
## Run AutoSSL on Your Domain
1. Log in to your cPanel account.
2. In the **Security** section, click **SSL/TLS Status**.
3. Tick the domains you want to secure, or use **Show Unsecured Domains** to narrow the list to the ones that still need a certificate.
4. Click **Run AutoSSL**. cPanel queues the check immediately and reports a success or an error against each domain.

A success message means validation passed and the certificate has been requested. Installation is automatic from that point. Allow a short while for the certificate to be issued and deployed, and note that browsers may hold the old response in cache, so test in a private window before concluding it has not worked.
## What a Successful Result Looks Like
Once the certificate is live, the domain's entry on **SSL/TLS Status** changes to an **AutoSSL DV certificate** with a **Certificate Status** of **Active**, and the expiry date is shown. Renewal is then automatic: cPanel reissues the certificate well before it expires, and you do not need to repeat this procedure each time.
**Installing the certificate is not the same as forcing traffic onto it.** Visitors reaching `http://yourdomain.com` will still be served over plain HTTP unless a redirect is in place. Use the **Force HTTPS Redirect** toggle on the cPanel **Domains** page, or the equivalent setting in your CMS, once the certificate is confirmed active. Enabling the redirect before the certificate exists will break the site.
## Troubleshooting
AutoSSL proves you control a domain by requesting a token file over HTTP from that domain, under a `/.well-known/` path. Nearly every failure is something interrupting that request.
**Symptom**: the error mentions the domain does not resolve, or resolves elsewhere. The domain's DNS is not pointing at the hosting server. Check the A record, and if you use external nameservers, confirm they have been updated and have propagated. A domain that is registered but not yet pointed cannot be validated.
**Symptom**: the error mentions an unexpected response, a redirect, or a 404 on the validation URL. A rule is intercepting the request before the token is served. Common causes are a catch-all redirect in `.htaccess`, a forced HTTPS redirect added before a certificate existed, a "coming soon" or maintenance mode plugin, or a CMS routing every unknown path to a custom 404 page. Temporarily disable the rule, run AutoSSL again, then re-enable it.
**Symptom**: the domain sits behind a CDN or proxy. If traffic is proxied rather than pointed directly at the server, the validation request never reaches your account. Either pause the proxy for the domain while AutoSSL runs, or use the certificate your proxy provider issues at the edge and keep a valid certificate on the origin.
**Symptom**: the error mentions CAA. A CAA record in your DNS restricts which certificate authorities may issue for the domain, and the authority cPanel uses is not on the list. Either add the correct CAA entry or remove the record, then run AutoSSL again.
**Symptom**: some names on the domain fail while the rest succeed. Service subdomains such as `mail.`, `webmail.` or `cpanel.`, and the `www.` variant, are validated individually. If one of them does not resolve to the server it is dropped from the certificate while the others are still secured. Point the missing name at the server, or exclude it so it stops reporting a problem. See [How to Include or Exclude a Domain from AutoSSL in cPanel](/cpanel/how-to-include-or-exclude-a-domain-from-autossl-in-cpanel/).
**Symptom**: the domain is skipped entirely with no error. It is most likely excluded from AutoSSL, or it already carries a valid certificate that AutoSSL will not overwrite. If you previously installed a purchased or third-party certificate, AutoSSL leaves it alone until it is close to expiry or removed.
**Symptom**: repeated runs now fail with a rate limit or "too many certificates" message. Certificate authorities cap how many certificates can be issued for a domain in a given window. Stop retrying, fix the underlying cause, and wait for the window to clear. This is why it is worth reading the error before forcing another run.
## Still Not Secured
If you have worked through the above and the domain will not validate, open a ticket with Noiz support and include the exact error text shown under **Certificate Status**, along with the domain name. That message identifies the failure precisely and lets support resolve it on your behalf, including cases that need action at server level rather than in your cPanel account.
### Related Articles
- [How to Include or Exclude a Domain from AutoSSL in cPanel](/cpanel/how-to-include-or-exclude-a-domain-from-autossl-in-cpanel/)
- [How to Generate a Certificate Signing Request (CSR) in cPanel](/security/how-to-generate-a-csr-certificate-signing-request-in-cpanel/)
# How to Protect the htaccess File
Source: https://docs.noiz.ie/security/how-to-protect-the-htaccess-file/
Your `.htaccess` file often holds sensitive configuration: rewrite rules, access controls, references to password files, and directory locations. Serving it as plain text to anyone who requests `https://yourdomain.com/.htaccess` hands an attacker a map of your site's defences. This guide explains how `.htaccess` protection actually works on Noiz hosting, how to confirm your file is not publicly readable, how to add an explicit rule correctly, and how to extend the same protection to the sensitive files Apache does *not* cover for you.
**Last reviewed:** 27 July 2026, against Apache HTTP Server **2.4** (current stable series). This guide is written for Noiz hosting and is kept current against Apache. It complements, and does not replace, the official Apache documentation linked below.
### Official Documentation Reference
- [Apache HTTP Server: .htaccess files (how-to)](https://httpd.apache.org/docs/2.4/howto/htaccess.html)
- [Apache core: the `` directive](https://httpd.apache.org/docs/2.4/mod/core.html#files)
- [Apache core: the `` directive](https://httpd.apache.org/docs/2.4/mod/core.html#filesmatch)
- [Apache mod\_authz\_core: the `Require` directive](https://httpd.apache.org/docs/2.4/mod/mod_authz_core.html#require)
- [Apache: upgrading 2.2 access control to 2.4](https://httpd.apache.org/docs/2.4/upgrading.html)
## Prerequisites
- Access to your website's files, through your hosting control panel's **File Manager** or over SFTP/FTP.
- A site served by Apache. The `.htaccess` file is read only by Apache, so none of this applies to a site served purely by Nginx. If you are unsure which applies to your account, open a support ticket and the Noiz team will confirm.
- A copy of your existing `.htaccess` file. One typo in this file can take an entire site offline with a **500 Internal Server Error**, so back it up before you edit.
## The Short Answer: Apache Already Protects It
On modern Apache (version 2.4, which is what Noiz hosting runs), access to `.htaccess` is denied by default. The standard server configuration ships with a rule equivalent to the following, applied globally so that no client can read any file whose name begins with `.ht`:
```apacheconf
Require all denied
```
Some Apache packages write the same rule as ``. Either form does the same job, and because it is set in the main server configuration, an `.htaccess` file cannot override it. In the vast majority of cases you therefore do **not** need to add anything to your own `.htaccess` at all. The best first step is not to add a rule, but to confirm the protection is working.
## Confirm Your .htaccess Is Not Publicly Readable
Request the file directly and look at the status code rather than the page, because some browsers silently download the file instead of displaying it:
```bash
curl -I https://yourdomain.com/.htaccess
```
Replace `yourdomain.com` with your own domain. What the response means:
- **403 Forbidden**: the file is protected. This is the expected result on Noiz hosting, and it means Apache is refusing to serve the file.
- **404 Not Found**: either there is no `.htaccess` file in that folder, or the server is hiding its existence outright. Both are safe.
- **200 OK**: the server is willing to serve the file. That is unusual on Noiz hosting, and the explicit rule below closes the gap.
If you would rather not use a shell, opening `https://yourdomain.com/.htaccess` in a browser works too. A 403 page is the pass; the file downloading or displaying as text is the fail.
## Adding an Explicit Rule (Defence in Depth)
If you want the protection written into your own `.htaccess` rather than relying solely on the server default, add the block below to the `.htaccess` file at your document root, usually `httpdocs` or `public_html` depending on your hosting plan. It costs nothing, it documents the intent, and it travels with the site if you ever move it to a host that is less careful.
```apacheconf
# Deny web access to .htaccess and .htpasswd
Require all denied
```
Save the file. The change takes effect on the next request, and there is nothing to restart.
**Do not paste the deny directives on their own.** A bare `Require all denied` (or the legacy `Deny from all`) with no `` wrapper applies to the entire directory, not just the `.htaccess` file, and returns 403 for every page and asset in that folder and everything below it. The `` wrapper is what limits the rule to the files you actually want to hide.
### If You See Older Apache 2.2 Syntax
Guides written for Apache 2.2, including earlier versions of this article, use a different and now-deprecated set of directives. They are worth recognising, because they turn up constantly in copy-and-paste hardening snippets:
```apacheconf
Order allow,deny
Deny from all
Satisfy all
```
Three points matter here.
1. **The argument to `Order` is a single token with no space after the comma.** `Order allow,deny` is valid; `order allow, deny` is a syntax error that Apache rejects, and it will take the site down with a 500 error until you remove it. This one typo is behind a large share of "my site broke after editing .htaccess" tickets.
2. **The `` wrapper is not decorative.** Strip it away and correct the comma, and the block becomes valid but denies the whole folder rather than one file, producing a site-wide 403. The snippet only ever made sense inside a container.
3. **The directives are obsolete.** On Apache 2.4, `Order`, `Deny`, `Allow` and `Satisfy` survive only through the legacy `mod_access_compat` module, and mixing them with the modern `Require` style in the same file gives results that are hard to predict. `Satisfy all` in particular achieves nothing useful here. Prefer the 2.4 block above for anything you write today.
## Protect the Files Apache Does Not Cover
This is where the real exposure usually sits. Apache shields `.ht*` files by default and nothing else, so everything below is served happily to anyone who guesses the URL. If you only make one change after reading this guide, make it this one.
### Dot-Prefixed Files
A single rule covers `.env`, `.gitignore`, `.user.ini`, `.DS_Store` and anything else beginning with a dot:
```apacheconf
# Refuse to serve any file whose name starts with a dot
Require all denied
```
`.env` is the one that matters most. Laravel, Symfony and many other frameworks keep database passwords and API keys in it, and automated scanners request `/.env` on every site they touch as a matter of routine.
**Gotcha worth knowing:** this rule does not interfere with SSL certificate renewal. `` tests the filename only, not the folder path, and the validation files placed in `/.well-known/acme-challenge/` have ordinary names. A rule that blocked the `/.well-known/` *directory* would break renewals, so do not convert this into a path-based block without testing.
### Backups, Database Dumps and Editor Leftovers
Files such as `index.php.bak`, `database.sql` or `config.php.old` are served as plain text, because Apache only hands a file to PHP when the name ends in `.php`. A database dump sitting in your document root is a complete copy of your site's data, available to anyone who asks for it by name.
```apacheconf
# Refuse to serve backups, dumps, logs and editor leftovers
Require all denied
```
Treat this as a safety net rather than a solution. Move backups and database dumps out of the document root entirely, so they are never reachable over the web in the first place.
### WordPress Configuration
On a WordPress site, add:
```apacheconf
Require all denied
```
Under normal conditions PHP executes `wp-config.php` and the visitor sees nothing, so this rule can look redundant. It exists for the abnormal condition: if the PHP handler fails after an update or a configuration change, Apache falls back to serving the file as plain text and your database credentials go out over the wire. It is cheap insurance against a bad five minutes.
### A Deployed .git Folder
If your site was put live with `git clone` or `git pull`, the `.git` folder came with it, and it holds your complete source history. A `` rule will not help, because the exposed items are files *inside* a dot-prefixed folder rather than dot-prefixed files themselves. Block the path instead:
```apacheconf
RedirectMatch 404 ^/\.git(/|$)
```
Returning **404 Not Found** rather than **403 Forbidden** is deliberate. A 403 confirms there is something there worth protecting, while a 404 gives a scanner nothing to work with. Better still, do not deploy the `.git` folder to a live site at all.
## Check the File Permissions Too
Apache rules govern who can fetch the file over the web. Filesystem permissions govern who can read or change it on the server, and that is a separate question. Set `.htaccess` to `644`, which lets the owner read and write it while everyone else may only read it:
```bash
chmod 644 .htaccess
```
You can set the same value from your File Manager's permissions dialog if you prefer. Never set `.htaccess` to `777`. A world-writable configuration file lets any compromised script on the server rewrite your access rules and inject redirects, which is a favourite trick of malware that targets shared hosting.
## Confirm It Is Working
Test each protected path and read the status line. A **403** or **404** is a pass; a **200** is a fail:
```bash
curl -I https://yourdomain.com/.htaccess
curl -I https://yourdomain.com/.env
curl -I https://yourdomain.com/wp-config.php
curl -I https://yourdomain.com/.git/config
```
Then load your home page and click through a few pages, including anything that submits a form or loads content in the background. If something returns a 403 that should not, one of the rules is broader than you intended, so remove the blocks one at a time until you find it.
## Troubleshooting
**Symptom: the whole site or folder returns 403 after editing `.htaccess`**. You almost certainly pasted `Require all denied` or `Deny from all` without the `` wrapper, so the deny applies to the entire directory. Wrap the directives in ` ... ` and reload.
**Symptom: `.htaccess` still downloads as text**. The default protection is not being applied. Add the explicit `` block above. If it still serves, contact Noiz support so the server configuration can be checked.
**Symptom: a 500 Internal Server Error appears after saving**. There is a syntax error in the file, commonly the stray space in `order allow, deny`, an unclosed `` or `` tag, or a missing quotation mark. Restore your backup to confirm, then re-add the rules one at a time.
**Symptom: the error log says a directive is "not allowed here"**. `AllowOverride` is restricted for that folder, so Apache will not accept these containers from an `.htaccess` file. Open a support ticket and the Noiz team will apply the rule at server level for you.
**Symptom: nothing changes at all**. Confirm the file is named exactly `.htaccess`, with the leading dot and no hidden `.txt` extension, and that it sits in the folder you intend to protect rather than its parent. Enable **Show hidden files (dotfiles)** in your File Manager if you cannot see it. If the site is served by Nginx, `.htaccess` is ignored entirely.
**Symptom: SSL certificate renewal starts failing**. Check that no rule blocks the `/.well-known/` path. The `` rule above is safe, but a path-based block on dot-prefixed folders is not.
## Related htaccess Guides
- [How to Disable Directory Browsing Using the htaccess Rule](/security/how-to-disable-directory-browsing-using-htaccess/)
- [How to Block Any IP Address via an htaccess Rule](/security/how-to-block-an-ip-address-using-an-htaccess-rule/)
- [How to Restrict Access to Directories by IP Address](/security/how-to-restrict-access-to-directories-by-ip-address/)
## Need a Hand?
You can edit `.htaccess` from your hosting control panel's File Manager or over SFTP. If you are unsure whether your file is protected, or an `.htaccess` change has taken a site offline and you need it reversed quickly, open a support ticket from your Noiz client area and the team will assist. On a managed plan, hardening of this kind is handled for you as standard.
# How to Remove a CSR Code in cPanel
Source: https://docs.noiz.ie/security/how-to-remove-a-csr-code-in-cpanel/
A Certificate Signing Request (CSR) is a one-off block of encoded text you hand to a Certificate Authority (CA) when you buy an SSL/TLS certificate. Once the CA has issued your certificate, the request itself has done its job, but cPanel keeps storing it. This guide shows you how to delete a CSR you no longer need from your Noiz cPanel account, and explains exactly what deleting one does and does not affect.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (current release tier). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: SSL/TLS interface](https://docs.cpanel.net/cpanel/security/ssl-tls/), covering the Private Keys, Certificate Signing Requests and Certificates sections.
- [cPanel Documentation: SSL/TLS Status](https://docs.cpanel.net/cpanel/security/ssl-tls-status/), the interface that reports certificate and AutoSSL coverage per domain.
## Deleting a CSR Does Not Break Your Live Certificate
This is the single point worth understanding before you click anything. Three separate items live in the cPanel SSL/TLS interface, and they are stored independently of one another:
- **Private key**: the secret half of the key pair. Your live HTTPS depends on this.
- **Certificate Signing Request**: the request you sent to the CA. It is derived from the private key, but nothing serves traffic from it.
- **Certificate**: the signed file the CA returned. This is what browsers actually receive.
Deleting a CSR removes only the request. An SSL certificate that is already issued and installed keeps working exactly as before, because it is paired with the private key rather than with the request. Visitors see no change, and nothing needs reinstalling.
The item you must not casually delete is the **private key**. Removing a key that an installed certificate depends on will break HTTPS on that domain, and the certificate cannot be reinstalled without it. Keys are listed under **Private Keys (KEY)** on the same page, so take care that you are working in the Certificate Signing Requests section and not the one above it.
## When to Keep a CSR Instead
Deleting a CSR is safe, but it is not always convenient. Keep the request if any of the following apply:
- The CA has not issued the certificate yet. Validation is still in progress and the request may need to be resubmitted.
- You expect to reissue the certificate, for example to add a domain or replace a lost copy. Several CAs ask for the original CSR during a reissue, and some renewal flows accept it as well.
- You maintain records of what was submitted for an organisation-validated or extended-validation certificate.
A CSR cannot be recovered once deleted. You can always generate a fresh one, but a new request is tied to a new key pair unless you deliberately reuse the existing key, and that means the CA has to reissue rather than simply renew.
## Prerequisites
- A cPanel hosting account with Noiz, and your cPanel login details from the welcome email or the Noiz client area.
- A copy of the CSR text saved locally if you might need it again. See [How to Retrieve a CSR from cPanel](/security/how-to-retrieve-a-saved-csr-in-cpanel/) to fetch the text before you remove it.
## How to Delete a CSR in cPanel
### Step 1: Open the SSL/TLS Interface
Log in to your cPanel account. In the **Security** section, click **SSL/TLS**.

### Step 2: Open the Certificate Signing Requests Manager
Under **Certificate Signing Requests (CSR)**, click **Generate, view, or delete SSL certificate signing requests**.

### Step 3: Identify the Correct Request
Under **Certificate Signing Requests on Server**, cPanel lists every CSR the account has generated, with the domains each one covers and the date it was created.

Check the domain column carefully before going further. Accounts that have been through a few certificate purchases often hold several near-identical requests for the same domain, and the creation date is usually the only thing that distinguishes them. If you are unsure which one the CA holds, open the request and compare it against the copy you submitted rather than guessing.
### Step 4: Delete the Request
Click **Delete** in the **Actions** column for the request you want to remove, then click **Delete** again to confirm.

The CSR is removed immediately and is no longer stored on the server. Your private keys and installed certificates are untouched.
## Troubleshooting
**Symptom**: you deleted the wrong CSR. There is no undo, and cPanel keeps no copy. If the certificate it relates to is already installed, nothing is broken and you can carry on. If the CA still needs it, generate a replacement using the same private key so the CA can reissue against the existing key pair. See [How to Generate a Certificate Signing Request in cPanel](/security/how-to-generate-a-csr-certificate-signing-request-in-cpanel/).
**Symptom**: the Certificate Signing Requests list is empty. Either no CSR was ever generated in cPanel, or the certificate on the domain was issued automatically by AutoSSL, which never creates a CSR. Both are normal.
**Symptom**: HTTPS broke shortly after you tidied up this page. A deleted CSR is not the cause. Check whether a private key or certificate was removed at the same time, and confirm the domain's status under **SSL/TLS Status**. Restoring service means reinstalling the certificate together with its matching key.
**Symptom**: the CA asks for the CSR during renewal and you no longer have it. Ask the CA whether they will accept a new request. Most will reissue against a fresh CSR at no extra cost within the certificate's validity period, though the certificate must then be reinstalled once they return the new file.
## Related Guides
- [How to Generate a Certificate Signing Request in cPanel](/security/how-to-generate-a-csr-certificate-signing-request-in-cpanel/)
- [How to Retrieve a CSR from cPanel](/security/how-to-retrieve-a-saved-csr-in-cpanel/)
## Need a Hand?
If you are clearing out old certificate material and are not certain which keys or requests are still in use, send Noiz support your domain name before deleting anything. Noiz can confirm what the live certificate depends on, so the tidy-up removes only the clutter. Most Noiz-hosted sites are covered by automatically issued and renewed certificates that need no CSR at all, and Noiz support can tell you whether yours is one of them.
# How to Restrict Access to Directories by IP Address
Source: https://docs.noiz.ie/security/how-to-restrict-access-to-directories-by-ip-address/
Restricting a directory to a short list of trusted IP addresses is one of the simplest and most effective ways to keep attackers away from a sensitive area of your website, such as a WordPress admin login (`/wp-admin/`), a staging folder, or any private tool. Even if someone knows your password, they cannot reach the login page unless they are connecting from an approved address.
This guide shows you how to lock a directory to your own IP address using an `.htaccess` file on Noiz hosting. It applies to any directory, not just WordPress. It is the mirror image of shutting out a single nuisance visitor: if that is what you need, see [How to Block Any IP Address via an htaccess Rule](/security/how-to-block-an-ip-address-using-an-htaccess-rule/) instead.
**Last reviewed:** 27 July 2026, against Apache HTTP Server **2.4** (latest stable). This guide is written for Noiz hosting and is kept current against Apache. It complements, and does not replace, the official Apache documentation linked below.
### Official Documentation Reference
- [mod\_authz\_host](https://httpd.apache.org/docs/2.4/mod/mod_authz_host.html): the `Require ip` and `Require host` directives.
- [mod\_authz\_core](https://httpd.apache.org/docs/2.4/mod/mod_authz_core.html): the ``, `` and `Require all` containers.
- [.htaccess files](https://httpd.apache.org/docs/2.4/howto/htaccess.html): how per-directory configuration works.
- [Upgrading to 2.4 from 2.2](https://httpd.apache.org/docs/2.4/upgrading.html): why the older `Order`, `Deny` and `Allow` syntax is deprecated.
- [WordPress: brute force attack hardening](https://developer.wordpress.org/advanced-administration/security/brute-force/): where an IP restriction fits alongside the other defences.
## Prerequisites
- Access to your website files, either through your control panel File Manager or over SFTP.
- The public IP address you connect from (covered in the first step). A fixed or static IP is strongly recommended, because a changing address will lock you out.
- A site served by Apache. On Nginx and some other servers `.htaccess` files are ignored entirely, so these rules have no effect there.
## Decide Whether an IP Restriction Suits Your Connection
Most home and mobile internet connections hand out a **dynamic** IP address that changes when the router reboots, when the line reconnects, or simply overnight. An allow list built on a dynamic address will eventually lock you out of your own admin area, usually at the worst possible moment.
Use this method when you connect from a fixed business line, a static IP, or a VPN with a known exit address. If your address moves around, password protection on the directory is the safer control, and it is available as a built-in feature in every mainstream control panel. The two also combine well: allow your office range by IP, and keep a password prompt for everywhere else.
## Find Your Public IP Address
Before you lock anything down, confirm the address you are currently connecting from. Open a search engine and search for **what is my IP**, or visit any IP-checking service. Note the value it returns, for example `203.0.113.5`. The address your computer reports on your local network, typically one beginning `192.168.` or `10.`, is not the address Apache sees, so do not use it.
If your internet connection uses IPv6, the service may show an address such as `2001:db8::a00:20ff:fea7:ccea`. Use whichever address your browser actually connects with, because Apache matches on the exact protocol you arrive over. If in doubt, add both your IPv4 and IPv6 addresses. This catches out a lot of people: a rule listing only an IPv4 address will refuse you the moment your browser prefers the IPv6 route.
## Create the .htaccess File
Create a file named `.htaccess` (note the leading dot, and no file extension) inside the directory you want to protect. For a WordPress admin area that is `/wp-admin/.htaccess`. The rule applies to that directory and everything beneath it. If a `.htaccess` file already exists in that directory, add the lines to it rather than overwriting it.
The leading dot makes the file hidden by default, so switch on **Show hidden files (dotfiles)** in File Manager if you cannot see it. Take a copy of any existing file before you edit it, because a single typo in `.htaccess` can take the directory, or the whole site, offline with a **500 Internal Server Error**.
## Restrict the Directory (Apache 2.4)
Add the following, replacing the example address with your own:
```apacheconf
Require ip 203.0.113.5
```
That single line tells Apache to allow the directory only for that address and to return a **403 Forbidden** to everyone else. No matching `deny` line is needed, because anything the `Require` rules do not match is refused automatically. The `203.0.113.5` value is an example from the documentation range only. Replace it with your real IP address.
### Allowing Several Addresses or a Range
To permit more than one address, list them on the same line separated by spaces:
```apacheconf
Require ip 203.0.113.5 198.51.100.10
```
Separate `Require ip` lines work equally well, and Apache treats a plain list of them as "any one of these may pass":
```apacheconf
Require ip 203.0.113.5
Require ip 198.51.100.10
Require ip 2001:db8::a00:20ff:fea7:ccea
```
To permit a whole block, use CIDR notation. This is useful if your connection hands out an address that changes within a known range, or if you want to admit a whole office:
```apacheconf
Require ip 203.0.113.0/24
```
That example covers every address from `203.0.113.0` to `203.0.113.255`. A partial address such as `Require ip 203.0.113` behaves the same way and matches everything beginning with those numbers. If you prefer to be explicit about the "any one of these" behaviour, or you are nesting rules inside a larger configuration, wrap the list in a `` block, which behaves identically:
```apacheconf
Require ip 203.0.113.5
Require ip 198.51.100.0/24
```
## Keep admin-ajax.php Working (WordPress)
If you restrict `/wp-admin/` on a WordPress site, be aware that many front-end features, such as contact forms, "load more" buttons, cart updates and some page builders, call `/wp-admin/admin-ajax.php` from your visitors' browsers rather than yours. Blocking that one file breaks those features for everyone, and it usually fails silently: the form simply never submits, with no error message to point you at the cause.
To keep it reachable while still protecting the rest of the admin area, add an exception below your `Require ip` line:
```apacheconf
Require ip 203.0.113.5
Require all granted
```
## Do Not Forget wp-login.php
The WordPress login form itself is `wp-login.php`, and it sits in the site root, not inside `/wp-admin/`. Locking the admin directory therefore does nothing to slow the automated login attempts hitting that one file. To cover it as well, add the following to the `.htaccess` file in your document root, usually `public_html`:
```apacheconf
Require ip 203.0.113.5
```
Place this block outside and above the `# BEGIN WordPress` section of the root file. WordPress rewrites everything between its own `# BEGIN` and `# END` markers whenever you save permalink settings, so anything added inside them will eventually disappear.
## Why Not "Order deny,allow"?
Older tutorials, and earlier versions of this guide, told you to use this:
```apacheconf
Order deny,allow
Deny from all
Allow from 203.0.113.5
```
That syntax belongs to **Apache 2.2**, which reached end of life years ago. On **Apache 2.4**, which current Noiz hosting servers run, those directives are deprecated and only work through the legacy `mod_access_compat` module, which is not guaranteed to be loaded. Mixing the old `Order`, `Deny` and `Allow` style with the new `Require` style in the same file can also produce results you do not expect. There is one more trap worth knowing: `Order` takes its two arguments with no space after the comma (`Order deny,allow`), so a stray space, as in `order deny, allow`, is read as two separate arguments and returns a 500 Internal Server Error on every page in that directory. Use `Require ip` and you avoid the whole problem.
## Test Your Restriction
Save the file, then confirm it works from an address that is *not* on your allow list. The easiest way is your mobile phone with Wi-Fi turned off, so it uses mobile data. You should receive a **403 Forbidden** response. From your own approved connection, the directory should load normally.
A private or incognito browser window is not a valid test. It changes your cookies, not your IP address, so the rule will still let you straight in.
## Troubleshooting
- **You locked yourself out**: your public IP has probably changed, as most home and mobile connections use dynamic addresses. Edit or rename the `.htaccess` file through your control panel File Manager or over SFTP, both of which bypass the browser rule, then update it with your new IP or a CIDR range.
- **The rule has no effect and everyone still gets in**: confirm the file is named exactly `.htaccess`, with the leading dot and no hidden `.txt` extension, and that it sits in the directory you intend to protect rather than the parent. Check too that the site really is served by Apache and that `AllowOverride` permits these directives for that directory.
- **Everyone is blocked, including you**: the address you allowed is probably not the one your connection presents. Re-check it, and add your IPv6 address alongside your IPv4 address if your connection has both.
- **You see a 500 Internal Server Error**: there is a syntax error in the file. Check for a stray space, a typo in `Require ip`, or an unclosed `` or `` block.
- **WordPress front-end features stopped working**: add the `admin-ajax.php` exception shown above.
- **Blocked visitors still get through, or everyone appears to share one address**: your site may sit behind a content delivery network or reverse proxy, in which case Apache sees the proxy's address rather than the visitor's. When traffic is proxied, apply the restriction at the proxy or CDN level instead.
- **The directory is locked but the attacks continue**: automated login traffic that never reaches the directory still consumes resources. Treat the IP restriction as one layer, alongside strong passwords, two-factor authentication and a login rate limit, rather than as your only defence.
If you are on a Noiz managed plan and would like help locking down an admin area, or you have locked yourself out and cannot regain access, open a ticket from your [Noiz client area](https://www.noiz.co.za) and the support team will assist.
# How to Retrieve a Saved CSR in cPanel
Source: https://docs.noiz.ie/security/how-to-retrieve-a-saved-csr-in-cpanel/
If you generated a Certificate Signing Request (CSR) in cPanel and then lost the copy you saved, you do not need to start again. cPanel keeps every CSR you generate in the **SSL/TLS** area of your account, and you can open it and copy the encoded text out at any time. This guide shows you where to find it. You may also see a CSR referred to as a certificate request or a PKCS#10 request.
A CSR is the block of Base64 text you hand to a certificate authority when you buy or reissue a commercial SSL certificate. It contains your domain name, your organisation details and the public half of a key pair. It contains no secret material, so it is safe to paste into an order form, an email or a support ticket. The matching **private key** is the part that must stay on the server, and cPanel stores that separately in the same SSL/TLS area.
**Last reviewed:** 27 July 2026, against cPanel with the **Jupiter** interface (current default). This guide is written for Noiz hosting and is kept current against cPanel. It complements, and does not replace, the official cPanel documentation linked below.
### Official Documentation Reference
- [cPanel Documentation: SSL/TLS](https://docs.cpanel.net/cpanel/security/ssl-tls/)
- [cPanel Documentation: SSL/TLS Status](https://docs.cpanel.net/cpanel/security/ssl-tls-status/)
## Prerequisites
- An active Noiz cPanel hosting account and your cPanel login details.
- A CSR that was previously generated *in this cPanel account*. cPanel can only show you requests it created itself, so a CSR generated on another server or with a local `openssl` command will not appear here. If you have never generated one, see [How to Generate a Certificate Signing Request (CSR) in cPanel](/security/how-to-generate-a-csr-certificate-signing-request-in-cpanel/).
## Retrieve Your Saved CSR
The whole job takes about a minute. If you cannot spot the SSL/TLS tile on the cPanel home page, type `SSL` into the search box at the top of the page to jump straight to it.
1. Log in to your cPanel account.
2. In the **Security** section, click **SSL/TLS**. 
3. Under **Certificate Signing Requests (CSR)**, click **Generate, view, or delete SSL certificate signing requests**. 
4. Look at the **Certificate Signing Requests on Server** table. Every CSR this account has generated is listed here, with its domains and the description you gave it when you created it.
5. In the **Actions** column, click **Edit** (shown as a pencil icon on newer cPanel builds) next to the request you want. 
6. Copy the text in the **Encoded Certificate Signing Request** box. Take the whole block, including the first and last lines: `-----BEGIN CERTIFICATE REQUEST-----` through to `-----END CERTIFICATE REQUEST-----` 
The same page also shows the decoded contents of the request, so you can confirm the common name, organisation and country before you submit it. That is worth a glance: a certificate authority will reject or reissue against exactly what the CSR says, not what you meant to type.
## Good to Know
- **Identify the right request by its description.** If several CSRs exist for the same domain, the domain column alone will not tell them apart. Open each one and check the decoded details, or delete the stale ones so only the current request remains.
- **A CSR is bound to one private key.** The certificate you receive back will only work with the key that generated the request. Never mix a CSR from one account or server with a key from another. As long as you retrieve the CSR from the same cPanel account you generated it in, the matching key is already in place.
- **Copy the whole block.** Include both the BEGIN and END lines and keep the line breaks. A missing header, a stray space or a request pasted with the lines joined together is the most common reason a certificate authority rejects a CSR.
- **Losing a CSR is not a crisis.** A CSR has no value on its own and costs nothing to replace. If you cannot find the one you want, simply generate a new request for the same domain and use that for the order or reissue.
- **Deleting a CSR does not affect a live certificate.** Once a certificate is issued and installed, the request has done its job. Removing old entries only tidies the list.
- **You may not need a CSR at all.** Noiz cPanel hosting issues and renews free certificates automatically through AutoSSL, which handles the request and the key for you. A CSR is only required when you are buying or reissuing a commercial certificate, such as an organisation validated or extended validation certificate. See [How to Install an SSL on Your Domain Using AutoSSL in cPanel](/security/how-to-install-an-ssl-certificate-on-your-domain-using-autossl-in-cpanel/).
## Troubleshooting
**The Certificate Signing Requests table is empty:** no CSR has been generated in this cPanel account. Check that you are logged in to the correct account, then generate a fresh request. A CSR created elsewhere, for example with `openssl` on your own machine, is never stored in cPanel.
**You can see the CSR but not the private key:** the key is kept in a separate list on the SSL/TLS Manager page, under **Private Keys (KEY)**. Open that list rather than the CSR list. Treat the key as a secret and never paste it into an order form or send it by email.
**The certificate authority says the CSR is invalid or malformed:** re-copy it and check that both the BEGIN and END lines are present, that nothing was truncated and that no extra characters were picked up from the clipboard. If it still fails, generate a new CSR and submit that.
**The certificate authority says the details do not match:** the common name in the CSR must match the exact hostname you are securing, so a request for `yourdomain.com` will not cover `www.yourdomain.com` unless the certificate is issued for both. Replace `yourdomain.com` with your own domain, and generate a new CSR with the correct details if they are wrong.
**SSL/TLS is missing from your cPanel:** the feature is controlled by the hosting package. If your plan should include it, contact Noiz support.
If you are ordering a commercial certificate and want a second pair of eyes on the request before you submit it, open a support ticket from your Noiz client area and the team will check it. On a managed plan, the certificate request and installation can be handled for you.
# Diagnosing Webmail 'Invalid Request' Session Errors on the Server (Roundcube/Plesk)
Source: https://docs.noiz.ie/server-administration/diagnosing-webmail-invalid-request-session-errors-on-the-server-roundcubeplesk/
This is the server-side companion to the client-facing guide [How to Fix the Webmail Error "Invalid Request. No Data Was Saved."](/email/how-to-fix-the-webmail-error-invalid-request-no-data-was-saved/) It is written for administrators and self-managing server owners with shell access who need to confirm, on the server, why a user is seeing that webmail message. It is an internal and advanced reference, not client-facing help: send clients to the guide above for the resolution steps.
The diagnostic approach here applies to any control panel that ships Roundcube webmail: establish the ground truth, then exclude each candidate cause on evidence. The specific commands and paths shown are for Plesk Obsidian on Debian 12 with the stock Roundcube it ships (the `psa-roundcube` package), not the Plesk Premium Mail extension. On another panel the same checks apply against that panel's Roundcube paths and logs. Throughout, `` is the placeholder for the affected domain.
**Last reviewed:** 27 July 2026, against Plesk **Obsidian 18.0** (latest stable) and the stock Roundcube it ships. This reference is written for Noiz-managed servers and is kept current against Plesk. It complements, and does not replace, the official Plesk and Roundcube documentation linked below.
### Official Documentation Reference
- [Roundcube webmail project](https://roundcube.net/): the upstream webmail software, its configuration reference and session handling.
- [Plesk Obsidian Administrator's Guide](https://docs.plesk.com/en-US/obsidian/administrator-guide/): the official reference for the mail stack and webmail that Plesk ships and manages.
## The Short Version
The client message "Invalid request. No data was saved." is almost always the ordinary Roundcube session inactivity timeout: the browser submits a request token that no longer matches a live server-side session, and Roundcube refuses the request rather than writing partial data. This is a shipped default, not a fault. The single most important thing to know before you start digging is that the ordinary expiry path writes **nothing** to the server logs, so an empty error log is consistent with this cause, not evidence against it.
## Server-Side Verification Procedure
### Establish the Ground Truth First
Before forming any hypothesis, establish what is actually running and what is actually configured. Do not assume a version, a path, or a default value.
```
# Roundcube version
grep -rhoE "RCMAIL_VERSION',[[:space:]]*'[^']+'" /usr/share/psa-roundcube/ 2>/dev/null | head -1
# What is actually overridden locally (defaults apply to everything absent here)
grep -vE "^[[:space:]]*(//|#|/\*|\*|$)" /usr/share/psa-roundcube/config/config.inc.php
# The settings that matter, from stock defaults
grep -nE "\$config\['(session_lifetime|session_storage|ip_check|log_logins|session_debug|debug_level)'\]" /usr/share/psa-roundcube/config/defaults.inc.php
# Log location and rotation state
ls -la /var/log/plesk-roundcube/
```
Stock Roundcube on Plesk logs to `/var/log/plesk-roundcube/errors`. If the Plesk Premium Mail extension is installed the path is `/var/log/roundcubemail/errors.log` instead. Check which applies before grepping, and adjust the paths in the commands below to match.
### Work Through the Exclusions
Each command below is read-only. Run one block, confirm its output, and read what that output proves or excludes before moving to the next.
```
# Server-side equivalent of the browser message, where it logs at all
zgrep -h "Request security check failed" /var/log/plesk-roundcube/errors /var/log/plesk-roundcube/errors.1 /var/log/plesk-roundcube/errors.*.gz 2>/dev/null
# Frequency by day - establishes whether this is systemic or baseline noise
zgrep -h "Request security check failed" /var/log/plesk-roundcube/errors /var/log/plesk-roundcube/errors.1 /var/log/plesk-roundcube/errors.*.gz 2>/dev/null | awk -F'[][]' '{print $2}' | awk '{print $1}' | sort | uniq -c
# Session row write failures (concurrent requests racing the same session)
zgrep -hE "DB Error.*Duplicate entry.*session" /var/log/plesk-roundcube/errors /var/log/plesk-roundcube/errors.1 /var/log/plesk-roundcube/errors.*.gz 2>/dev/null | sed -E "s|'[A-Za-z0-9+/=]{100,}'|''|g"
# Session table health - rules out storage degradation or failed garbage collection
MYSQL_PWD=$(cat /etc/psa/.psa.shadow) mariadb -uadmin roundcubemail -e "SELECT COUNT(*) AS rows_total, MIN(changed) AS oldest, MAX(changed) AS newest FROM session; SELECT COUNT(*) AS stale_over_24h FROM session WHERE changed < NOW() - INTERVAL 1 DAY;"
# Cookie scope - rules out competing cookies from dual entry paths
for u in "https://webmail./" "https://webmail./roundcube/"; do
echo "--- $u"
curl -sk -D- -o /dev/null "$u" | grep -iE "^(HTTP/|location:|set-cookie:)"
done
# HTTP-layer correlation for the affected domain
zcat -f /var/www/vhosts/system//logs/access_ssl_log* | grep -a "_task="
zcat -f /var/www/vhosts/system//logs/access_ssl_log* | grep -a "_err=session"
zcat -f /var/www/vhosts/system//logs/access_ssl_log* | grep -a "_task=" | grep -aE '" [45][0-9]{2} '
# Referer check - exposes bookmarked post-login URLs
zcat -f /var/www/vhosts/system//logs/access_ssl_log* | grep -a "_task=" | grep -aoE '"https://[^"]*index\.php\?_user=[^"]*"' | sort | uniq -c
```
### What Each Result Means
- **`ip_check` false:** rules out client IP churn, proxy IP restoration, and CDN egress rotation as a cause. Do not pursue those.
- **Session table with zero rows stale beyond 24h:** garbage collection is working and storage is healthy. Rules out session backend degradation.
- **Both entry paths returning `roundcube_sessid` with `path=/`:** one cookie scope, no competing cookies. Rules out the dual entry path (DocumentRoot plus the `/roundcube/` alias) as a cause.
- **"Request security check failed" appearing only a handful of times across months, server-wide:** baseline noise. It does not account for a single user reporting recurring problems, because the ordinary expiry path writes nothing at all.
- **No `_err=session` entries:** expected, and not an exclusion. When the session has lapsed, Roundcube renders the login page at the requested URL rather than redirecting, so the absence of `_err=session` does not rule out expiry.
- **Duplicate entry errors on the session table:** concurrent requests holding the same session ID. This is commonly caused by security-suite link scanners or browser prefetch re-fetching webmail URLs from a different address moments behind the user. Cosmetic in isolation. Run a whois on the requesting IPs before drawing any conclusion.
State the central diagnostic point plainly, because it is where most investigations go wrong: the ordinary expiry path produces no server-side log entry at all, so an empty error log is consistent with this cause rather than evidence against it. Absence of evidence in the Roundcube log is the expected result here, not a dead end.
### Optional Instrumentation (Changes Live Configuration)
The following overrides add logging that can confirm the pattern on a stubborn case. Treat this as a change that alters live configuration: apply it deliberately, one change at a time, and remove it once the case is understood.
```
$config['log_logins'] = true; // writes to /var/log/plesk-roundcube/userlogins.log
$config['session_debug'] = true;
$config['debug_level'] = 1;
```
Note that `/usr/share/psa-roundcube/config/config.inc.php` can be replaced by a package update, so any override placed there belongs under version control and should be re-checked after every Plesk update. Raising `session_lifetime` is a deliberate security and usability trade-off, not a default remedy: it should only be changed with explicit sign-off, never as a first response.
## Reusable AI Prompts
The two prompts below are written to be pasted, as they stand, into an AI assistant that has shell access on a Plesk mail server. Use Prompt A to diagnose a reported case, and Prompt B to walk a client through the resolution. They are complete prompts, not summaries.
### Prompt A: Diagnosis
```
You are assisting a Plesk mail-server administrator diagnosing intermittent
webmail failures where users see "Invalid request. No data was saved."
The platform is Plesk Obsidian on Debian 12 with stock Roundcube
(the psa-roundcube package), not the Plesk Premium Mail extension.
Work strictly from evidence. Do not assume any path, version, or config value.
1. First establish the ground truth before forming any hypothesis:
- the running Roundcube version,
- the active log location (stock is /var/log/plesk-roundcube/errors;
the Premium Mail extension uses /var/log/roundcubemail/errors.log),
- and exactly which settings are overridden in config.inc.php versus
left at defaults.inc.php.
2. Then exclude these causes, on evidence, in this order, and after each one
state which hypothesis you have killed and the exact output that killed it:
a. ip_check (client IP churn / proxy / CDN egress rotation),
b. session storage health (session table row counts and stale rows,
confirming garbage collection is working),
c. cookie scope (that both entry paths return one session cookie at path=/,
ruling out competing cookies from the dual entry path).
3. Then correlate at the HTTP layer in the domain's access logs
(/var/www/vhosts/system//logs/access_ssl_log*): look at _task=
requests, 4xx/5xx responses, and Referer values that expose bookmarked
post-login URLs.
4. Treat an empty Roundcube error log as CONSISTENT WITH session expiry, not
as an exclusion: the ordinary expiry path writes nothing to the log, so its
absence is the expected result, not proof the cause is something else.
Rules: issue exactly ONE read-only command block at a time and wait for me to
paste the output before continuing. Never assume a path or config value you
have not read. Never assert a conclusion without quoting the log line or query
result that supports it. End by listing each hypothesis you tested, whether it
was killed or survived, and the specific output that decided it.
```
### Prompt B: Resolution
```
You are helping a client resolve a webmail message that reads
"Invalid request. No data was saved." on a Plesk-hosted mailbox using
stock Roundcube webmail. The underlying cause is the webmail session's
inactivity timeout, which is a shipped default of the webmail software,
not a fault or an outage.
Before proposing anything server-side, confirm that the cause is this shipped
default rather than a genuine fault. Only once that is established should any
server-side change even be discussed.
Give the client this sequence, in this order:
1. Sign in again (this clears most occurrences).
2. If it persists, clear cookies and site data for the webmail address, close
the browser fully, reopen, and sign in again.
3. Check the bookmark or saved shortcut and replace it with the plain webmail
address only, https://webmail., then sign in from there.
4. Try a different browser or a private/incognito window.
Explain that step 4 is a DIAGNOSTIC, not a permanent fix: it confirms whether a
stale session was the cause, but the timeout applies in every browser, so it
cannot be switched off by changing browser.
Check specifically for a bookmarked post-login URL, because bookmarking the
address shown after login (which carries one-time session and mailbox
parameters) is a frequent trigger.
For anyone who keeps mail open all day, recommend a desktop mail application
(Mozilla Thunderbird is the free cross-platform option), because a mail
application holds its own connection and is not subject to the webmail session
timeout.
Treat raising the webmail session_lifetime as a deliberate security-and-
usability trade-off that requires explicit sign-off, NOT as a default remedy.
Do not offer it as the first answer.
```
# Fix PHP Error: Allowed Memory Size of X Bytes Exhausted
Source: https://docs.noiz.ie/server-administration/fix-php-error-allowed-memory-size-of-x-bytes-exhausted/
When a PHP script tries to use more memory than PHP is allowed to give it, the script stops with a fatal error like this:
```
Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 20480 bytes) in /home/example/public_html/wp-content/plugins/example/file.php on line 512
```
The number (here `134217728` bytes, which is 128 MB) is your current `memory_limit`. This guide shows you how to raise that limit correctly for your site, and, just as importantly, how to tell whether raising it is actually the right fix.
**Last reviewed:** 27 July 2026, against PHP **8.x** (all currently supported branches behave the same for this setting). This guide is written for Noiz hosting and is kept current against PHP. It complements, and does not replace, the official PHP documentation linked below.
### Official Documentation Reference
- [PHP Manual: the `memory_limit` directive](https://www.php.net/manual/en/ini.core.php#ini.memory-limit)
- [PHP Manual: per-directory `.user.ini` files](https://www.php.net/manual/en/configuration.file.per-user.php)
- [PHP Manual: setting a value at runtime with `ini_set()`](https://www.php.net/manual/en/function.ini-set.php)
## Important: the old `RLimitMem` trick does not work
Older guides tell you to add `RLimitMem max` to your `.htaccess` file. Do not use it for this problem. `RLimitMem` is an Apache directive that limits the operating-system memory of helper processes Apache launches (such as CGI scripts). It has nothing to do with PHP's `memory_limit` and will not change the value in the error message. Use one of the methods below instead.
## First, decide whether to raise the limit at all
The PHP default is `128M` (128 MB) and that is enough for most well-behaved sites. A memory error is often a symptom rather than the disease. Before you raise the limit, ask:
- **Did this start suddenly?** A recent plugin, theme, or code change that suddenly needs far more memory usually points to a bug or a runaway loop, not to a limit that is genuinely too low.
- **Is the requested amount tiny?** If the script fails while trying to allocate only a few kilobytes (as in the example above), memory has already been used up elsewhere. Raising the limit may only delay the crash.
- **Is it a known heavy task?** Large image processing, big imports/exports, or a busy WordPress site legitimately need more than `128M`. Here, raising the limit is the correct fix.
Raise the limit to a sensible figure such as `256M` or `512M`. Avoid `-1` (unlimited) on shared hosting: a single faulty script could then consume all available memory. If a value like `512M` still is not enough, treat that as a strong sign of a code problem and investigate the script rather than raising the number again.
## Which method should you use?
How you change the limit depends on how PHP runs on your account. The methods below are ordered from most reliable to most situational. If you are not sure how your site runs PHP, start with the control panel method, which works in every case.
## Method 1: Your hosting control panel (recommended)
The most reliable way to change PHP settings is through the PHP settings screen in your hosting control panel. This applies the value at the account level, so it works no matter how PHP is served.
- **Plesk:** open **Websites & Domains**, select your domain, click **PHP Settings**, set **memory\_limit** to your chosen value, then click **OK** or **Apply**.
- **DirectAdmin:** open your account's PHP configuration for the domain and edit the **memory\_limit** value for the active PHP version.
- **cPanel:** open **MultiPHP INI Editor**, choose your domain, and set **memory\_limit** in the editor.
If your control panel does not expose a memory\_limit field, or you manage the server yourself, use one of the file-based methods below.
## Method 2: A `.user.ini` file (modern PHP-FPM and FastCGI setups)
Most current hosting runs PHP as FPM or FastCGI rather than as an Apache module. On those setups the correct file-based approach is a `.user.ini` file, not `.htaccess`.
1. Using File Manager or FTP, go to the folder where your site's PHP runs. For most sites this is your document root, for example `public_html` or `httpdocs`.
2. Create a plain-text file named `.user.ini` (note the leading dot).
3. Add this single line and save: `memory_limit = 256M`
**Give it a few minutes.** PHP caches `.user.ini` files, so a change can take up to five minutes to take effect. If nothing appears to happen, wait, then reload the page.
## Method 3: `.htaccess` (only when PHP runs as an Apache module)
The classic `.htaccess` method works only if PHP is loaded as an Apache module (mod\_php). On that kind of setup, add this line to the `.htaccess` file in your document root:
```
php_value memory_limit 256M
```
If the error keeps appearing, add the same line to the `.htaccess` file inside the specific folder named in the error message, for example `yourdomain.com/wp-admin/.htaccess`.
**Watch for a 500 error.** If adding `php_value` makes the whole site return a **500 Internal Server Error**, your server is not using mod\_php. Remove that line immediately and use Method 1 or Method 2 instead.
## Method 4: In the script itself (targeted, temporary)
If you only need more memory for one specific script and you can edit it, add this near the top, before any heavy work runs:
```
Require all granted
Require not ip 203.0.113.45
```
Replace `203.0.113.45` with the address you want to block. That address is from a reserved documentation range and is only an example, so it will not block anything real.
Read it as two conditions that must both pass: the request is allowed in general, *and* it does not come from that IP. Anyone matching the blocked address receives a `403 Forbidden` response.
**Why the `` wrapper matters.** Several `Require` lines that are not wrapped in a container are treated as a *RequireAny* group, meaning any one of them passing is enough to grant access. A negated line such as `Require not ip` can never grant access on its own, so a group containing only negations always fails and a mixed unwrapped group quietly ignores your block. Wrapping the rules in `` is what makes the exclusion actually apply.
## Blocking Ranges, Networks and Multiple Addresses
Add one `Require not` line per entry inside the same container. Apache accepts several notations:
```markup
Require all granted
Require not ip 203.0.113.45
Require not ip 198.51.100.0/24
Require not ip 192.0.2
Require not ip 2001:db8:abcd::/48
```
- `203.0.113.45` blocks one address.
- `198.51.100.0/24` blocks a CIDR network, in this case 256 addresses.
- `192.0.2` is a partial address, and blocks everything starting with those octets.
- IPv6 addresses and prefixes work in exactly the same way. If a visitor reaches your site over IPv6, blocking only their IPv4 address achieves nothing, so check your logs for both.
You can also block by hostname with `Require not host example-crawler.net`, but this forces a reverse DNS lookup on every request and is easy for an attacker to defeat. Prefer IP based rules.
## Allowing Only Specific IP Addresses
For a staging site, an admin area or a client preview, an allow list is far stronger than a block list. This denies everyone except the addresses you name:
```markup
Require ip 203.0.113.45
Require ip 198.51.100.0/24
```
No container is needed here. Multiple positive `Require` lines behave as "any of these may pass", which is exactly what an allow list wants. Everyone else gets a `403`.
**Gotcha:** most home and mobile connections use a dynamic IP that changes without warning. Lock yourself out this way and you will need File Manager or SFTP access to undo it, so confirm you have a second route in before you save.
## Protecting a Single File or Directory
To restrict one file rather than the whole site, wrap the rules in a `` block. A common use is limiting access to a login script:
```markup
Require ip 203.0.113.45
```
To restrict a directory instead, place a separate `.htaccess` file inside that directory containing the rules. Directives in a subdirectory replace, rather than merge with, the authorisation rules inherited from the parent.
## Why the Old `order allow,deny` Snippet No Longer Works
Older guides, including earlier versions of this article, recommended this:
```markup
order allow, deny
deny from IP-ADDRESS
allow from all
```
There are two problems with it.
1. **The syntax is invalid.** Apache expects `Order allow,deny` with no space after the comma. The space alone is enough to produce a `500 Internal Server Error` on every page of the site, which is the usual reason a site goes down immediately after someone pastes in a blocking snippet.
2. **The directives are obsolete.** `Order`, `Allow` and `Deny` belong to the Apache 2.2 access control model, replaced in Apache 2.4 by the `Require` directives shown above. They only still function if the compatibility module `mod_access_compat` happens to be loaded, and mixing old and new style directives in the same context produces unpredictable results. Treat the old syntax as removed and convert any of it you find in existing files.
## Blocking the Real Visitor IP Behind a CDN or Proxy
If your site runs through a CDN, a reverse proxy or a web application firewall, Apache sees the proxy's IP address on every request, not the visitor's. Two consequences follow:
- Blocking the address that appears in your logs may block the proxy itself, taking your whole site offline for every visitor.
- Blocking the visitor's true address does nothing, because Apache never compares against it.
The real address is normally carried in the `X-Forwarded-For` header, and the server needs `mod_remoteip` configured with the trusted proxy ranges before `Require not ip` will match it. That is a server level change, not an `.htaccess` one. Where a CDN is in front of your Noiz site, the cleanest fix is to apply the block in the CDN's own firewall rules, so unwanted traffic is stopped before it ever reaches the server. Open a ticket in the Noiz client area if you are unsure which applies to your setup.
## Verifying the Block
1. Save the file and load your own site in a browser. If you see a `500 Internal Server Error`, the file has a syntax error. Remove the lines you just added and re-add them carefully.
2. Check that the blocked address now receives a `403`. If you cannot test from that address, a VPN or a mobile connection on a different network gives you a second vantage point.
3. Watch the access log for the blocked IP. Entries should continue to appear, now with status `403`, which confirms the rule is matching rather than the visitor simply having stopped.
Changes take effect on the next request. No restart is needed, and no caching layer sits in front of `.htaccess` parsing.
## Troubleshooting
**Symptom**: the entire site returns `500 Internal Server Error` after editing. The rules contain a typo, a stray space (as in `order allow, deny`), or an unclosed container. Restore your backup of `.htaccess`, or comment the new lines out with `#` at the start of each.
**Symptom**: the blocked visitor still gets through. Check that the site actually reads this `.htaccess` file. A file in the wrong directory, or a subdirectory `.htaccess` with its own `Require` rules, will override what you expect. Confirm you are blocking the address the server sees, not the one a proxy is hiding.
**Symptom**: the rules are ignored entirely. `AllowOverride` may be set to `None` for that directory, which disables `.htaccess` processing. Raise a ticket in the Noiz client area to have it checked.
**Symptom**: you locked yourself out with an allow list. Edit the file through the File Manager in your control panel or over SFTP, neither of which is affected by web server access rules.
**Symptom**: blocking one address does nothing useful, because the traffic returns from a new one within minutes. That pattern points to a distributed source, and no `.htaccess` list will keep up with it.
## Know the Limits: .htaccess Is Not a Firewall
These rules are applied by the web server, after the connection has been accepted, so a blocked request still consumes a connection slot and a small amount of CPU. That is fine for a nuisance scraper, a spam referrer or a single abusive address. It is not a defence against a flood, and a long block list maintained by hand becomes a maintenance burden that slows every request on the site, since Apache re-reads and re-evaluates `.htaccess` on each one.
For sustained or distributed abuse, blocking at the network edge is the right answer. Noiz servers run automated intrusion prevention that blocks repeat offenders at the firewall before the web server is involved, and CDN level rules stop traffic even earlier. If you find yourself adding addresses to `.htaccess` every day, open a ticket in the Noiz client area with a sample of the log lines and the Noiz team will advise on the right layer to block at, or apply it for you on managed plans.
# How to Change the PHP Version Using the CloudLinux Selector in cPanel
Source: https://docs.noiz.ie/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/
On Noiz cPanel hosting that runs CloudLinux, the **Select PHP Version** tool (usually called the CloudLinux PHP Selector) lets you change the PHP version your account runs on, without opening a support ticket. This guide shows you where the tool lives, how to switch versions safely, and what changes underneath when you do.
The tool appears under a few different names depending on where you read about it: **Select PHP Version** is the cPanel icon label, **PHP Selector** is the CloudLinux product name, and **alt-php** is the name of the alternative PHP builds it switches between. They all refer to the same thing.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the *stable* and *LTS* tier in cPanel's own wording) with the Jupiter interface, and against the PHP branches the PHP project currently supports (**8.2, 8.3, 8.4 and 8.5**, with **8.5.8** as the current release). This guide is written for Noiz hosting and is kept current against cPanel and CloudLinux. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [CloudLinux OS Components: PHP Selector](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#php-selector): what the Selector is, how the alt-php builds are packaged, and its known limitations.
- [PHP: Supported Versions](https://www.php.net/supported-versions.php): the authoritative list of which PHP branches still receive bug fixes and security fixes, with end-of-life dates.
- [cPanel: MultiPHP Manager](https://docs.cpanel.net/cpanel/software/multiphp-manager-for-cpanel/): the separate, cPanel-native tool that some accounts have instead of (or alongside) the CloudLinux Selector.
## Prerequisites
- A Noiz cPanel hosting account and its login details.
- A recent backup, or at least a note of which version you are switching away from. Switching back is a two-click job, but only if you remember where you started.
- Confirmation of what your application actually needs. Check the requirements page for your CMS or framework before you move it onto a newer branch.
## Change the PHP Version
### 1. Open Select PHP Version
Log in to your cPanel account, scroll to the **Software** section, and click **Select PHP Version**. If you cannot find it, type `PHP` into the search box at the top of the cPanel home page.

### 2. Choose the version you want
At the top of the page, next to **Current PHP version**, open the drop-down menu and pick the version you want to run. The list shows every PHP build available on the server, plus a **native** entry, which is the server's own system PHP rather than a CloudLinux alt-php build.

### 3. Apply the change
Click **Set as current**. The change applies straight away, so no restart is needed on your side. Load your site in a fresh browser tab and check that everything still renders and that the admin area still logs in.

## What the Change Actually Affects
This is the part the button does not tell you, and it is where most follow-up tickets come from.
- **The setting is account-wide, not per-domain.** The CloudLinux Selector sets one PHP version for the whole cPanel account, so every domain, subdomain and add-on domain in that account moves together. If you need two sites on two different PHP versions, they need to live in separate cPanel accounts. Noiz support can advise on the cleanest way to split them.
- **Extensions are stored per version.** Each PHP version keeps its own list of enabled extensions. Switching from one version to another does not carry your extension choices across, so a site that needed `imagick` or `soap` on the old version will need them ticked again on the new one. Check the **Extensions** tab immediately after switching.
- **Options are stored per version too.** The same applies to values on the **Options** tab, such as `memory_limit`, `max_execution_time` and `display_errors`. A newly selected version starts on its own defaults, not on the values you tuned previously.
- **The native entry behaves differently.** When **native** is selected, the Extensions and Options tabs are not available, because that build is managed by the server rather than by the Selector. Choosing a numbered alt-php version is the normal choice for a hosting account.
- **Two tools can exist on one server.** cPanel ships its own **MultiPHP Manager**, which works per-domain. The CloudLinux Selector works per-account. If both icons appear in your Software section, change the version in one place only and contact Noiz support to confirm which one governs your account, rather than setting a version in both and guessing which wins.
## Choosing a Sensible Version
The Selector lists a lot of versions, and not all of them are a good idea.
- **Stay on a supported branch.** As of this review, the PHP project supports **8.2, 8.3, 8.4** and **8.5**. Anything older than 8.2, including the entire 7.x series and PHP 8.0 and 8.1, has reached end of life upstream and no longer receives fixes from the PHP project. Check the supported versions page linked above before you commit, since branches drop off that list every year.
- **Do not jump multiple major branches blind.** Moving a site from 7.4 straight to 8.5 crosses several rounds of removed functions and changed behaviour. Move up one branch at a time, testing each step, and read your application's own upgrade notes as you go.
- **Treat legacy branches as temporary.** The Selector may still list end-of-life versions so that older applications keep running. That is a stopgap for buying time to update the application, not a destination. A site left on an unsupported branch will eventually run into both security problems and plugin incompatibility.
- **Match the application, not the highest number.** Newest is not automatically best. If your CMS, theme or plugin set has not certified the newest branch, pick the newest branch that it has.
## Troubleshooting
- **Symptom: the site returns a blank white page or a 500 error after switching.** Switch straight back to the previous version to restore service, then investigate. In almost all cases the cause is either a missing extension on the new version or application code that is not compatible with the newer branch.
- **Symptom: a feature that worked before now fails, for example image uploads or a payment callback.** An extension is missing. Open the **Extensions** tab and re-enable the ones your application needs on the new version.
- **Symptom: uploads or long imports now fail on size or time.** The per-version defaults are lower than the values you had tuned. Raise them on the **Options** tab for the version you are now running.
- **Symptom: the drop-down will not save, or Select PHP Version is missing entirely.** Some hosting configurations manage PHP centrally and hide or lock the Selector. Contact Noiz support and state which version you need.
- **Symptom: `phpinfo()` or your CMS still reports the old version.** Clear any full-page or object cache in your application and any caching layer in front of the site, then reload. Browsers and CDN caches frequently serve the pre-switch page for a while.
## Related Guides
- [How to Enable or Disable PHP Extensions Using the CloudLinux Selector in cPanel](/server-administration/how-to-enable-or-disable-php-extensions-using-the-cloudlinux-selector-in-cpanel/)
- [How to Increase or Decrease PHP Memory Limit via CloudLinux Selector in cPanel](/server-administration/how-to-increase-or-decrease-php-memory-limit-via-cloudlinux-selector-in-cpanel/)
- [How to Enable or Disable PHP's display\_errors via CloudLinux Selector in cPanel](/server-administration/how-to-enable-or-disable-phps-display-errors-via-cloudlinux-selector-in-cpanel/)
If you are unsure which PHP version your site should be on, or a version change has broken something you cannot pin down, open a ticket with Noiz support. Include your domain name, the version you moved from and the version you moved to, and the exact error text. On managed plans, Noiz will test the upgrade path and move you across for you.
# How to Connect to Your FTP Account Using FileZilla
Source: https://docs.noiz.ie/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/
FileZilla is a free, open source FTP client that lets you move files between your computer and your Noiz hosting account without using a web-based file manager. This guide shows you how to connect it to your hosting account, how to force an encrypted connection instead of plain FTP, and how to read the errors FileZilla gives you when a connection fails.
The steps below apply to any Noiz hosting account, whichever control panel your account uses. FTP is a server-level service, so the connection details come from your hosting account rather than from any particular panel screen.
**Last reviewed:** 27 July 2026, against FileZilla Client **3.x** (current stable series). This guide is written for Noiz hosting and is kept current against FileZilla. It complements, and does not replace, the official FileZilla documentation linked below.
### Official Documentation Reference
- [FileZilla Client Tutorial](https://wiki.filezilla-project.org/FileZilla_Client_Tutorial_(en)): the vendor walkthrough of the interface and first connection.
- [Using FileZilla](https://wiki.filezilla-project.org/Using): Site Manager, transfer queue, and directory comparison.
- [FileZilla Network Configuration](https://wiki.filezilla-project.org/Network_Configuration): active versus passive mode, firewalls, and router behaviour.
- [FileZilla Client downloads](https://filezilla-project.org/download.php?type=client): official builds only.
## Prerequisites
- FileZilla Client installed on your computer. See [How to Install Filezilla Client on Windows](/server-administration/how-to-install-filezilla-on-windows/).
- An active FTP account on your hosting service, along with its username and password.
- The hostname to connect to, which is either your domain name or the server hostname shown in your Noiz welcome email.
## Gather Your FTP Connection Details
Every FTP connection needs four pieces of information. Collect them before you open FileZilla so you are not guessing at the prompt.
- **Host**: `ftp.yourdomain.com` or `yourdomain.com`, replacing `yourdomain.com` with your own domain. If your domain is not yet pointed at Noiz nameservers, that hostname will not resolve to the right server, so use the server hostname from your welcome email instead.
- **Username**: the FTP username created in your hosting control panel. On most platforms this is either the main hosting account username or a separate FTP user in the form `user@yourdomain.com`.
- **Password**: the password set for that FTP user. This is not your Noiz client area password, and it is not your email password.
- **Port**: `21` for FTP and FTPS. Leave the Port field empty and FileZilla uses `21` automatically. Port `22` is SFTP, which is a different protocol carried over SSH.
If you do not have an FTP user yet, create one in your control panel first. The exact screen differs by platform, so search the Noiz knowledgebase for "create an FTP account" and follow the article that matches the panel your account uses.
## Connect Using Quick Connect
Quick Connect is the fastest way to test that your details work. It is best treated as a test rather than as your everyday method, for the reasons explained in the next section.
1. Open the FileZilla Client.
2. Enter your FTP host, username and password in the Quick Connect bar across the top of the window. Leave **Port** blank unless Noiz has given you a specific port. 
3. Click **Quickconnect**. The connection takes a few seconds. Watch the message log in the top pane: a successful login ends with a directory listing rather than an error.
4. Your local computer files appear in the left pane and your hosting account files appear in the right pane. 
You can now browse, upload, download and delete files by dragging between the two panes.
## Use Explicit FTP Over TLS Instead of Plain FTP
Plain FTP sends your username and password across the network in clear text. Anyone able to observe the connection, which matters most on shared office networks, hotel networks and public Wi-Fi, can read those credentials. Noiz recommends that you always connect over explicit FTP with TLS, usually written as FTPS.
Quick Connect will opportunistically upgrade to TLS when the server offers it, but it silently falls back to an unencrypted session when the negotiation fails. That silent fallback is the problem. Setting the connection up in the Site Manager lets you require encryption, so a failed negotiation produces an error instead of an insecure login.
1. In FileZilla, open **File** then **Site Manager**.
2. Click **New site** and give it a recognisable name, such as your domain.
3. Set **Protocol** to **FTP** (File Transfer Protocol).
4. Enter your **Host** and leave **Port** blank.
5. Set **Encryption** to **Require explicit FTP over TLS**.
6. Set **Logon Type** to **Ask for password** if you would rather not store the password on disk, or **Normal** if you are on a machine only you use.
7. Enter your **User** and, if applicable, your password, then click **Connect**.
The first time you connect, FileZilla shows the server certificate and asks you to confirm it. Tick **Always trust this certificate in future sessions** and click **OK**. You will not be asked again for that server unless the certificate changes.
If your hosting account offers SSH access, choose **SFTP** (SSH File Transfer Protocol) as the protocol instead. SFTP is encrypted by default, uses port `22`, and needs no separate TLS setting.
## Know Where to Put Your Files
When you log in, FileZilla usually drops you into the home directory of the FTP user, not into the folder your website is served from. Files placed in the home directory will not appear on your site.
Look in the right pane for the web root folder, commonly named `public_html`, `httpdocs` or `web` depending on the platform your account runs on, and open it before uploading. Anything intended to be publicly visible belongs inside that folder. Your homepage, for example, belongs there as `index.html` or `index.php`.
If the FTP user was created and scoped to a single site, the web root may already be the folder you land in. In that case the right pane shows your existing site files immediately after login.
## Troubleshooting
**Symptom**: `530 Login authentication failed` or `530 Login incorrect`. The username or password is wrong, or you are using client area or email credentials. Reset the FTP user's password in your control panel and try again. Also check for a trailing space if you pasted the password.
**Symptom**: `ECONNREFUSED` (Connection refused by server). Nothing is listening on the port you asked for. Confirm you left the Port field blank or set it to `21`, and confirm you did not select SFTP for an account without SSH access.
**Symptom**: `ETIMEDOUT` (Connection attempt timed out). Either the hostname resolves to the wrong place or your network blocks outbound FTP. Try the server hostname from your welcome email rather than your domain, and test from a different network such as a mobile hotspot. Corporate and school networks frequently block port 21 outright.
**Symptom**: login succeeds but the directory listing never completes, or it fails with `Failed to retrieve directory listing`. This is nearly always a passive mode or firewall issue. In the Site Manager, open the **Transfer Settings** tab and set **Transfer mode** to **Passive**. If it still stalls, check that your local firewall or security software is not filtering FileZilla.
**Symptom**: `Connection closed by server` shortly after a period of inactivity. FTP sessions time out by design. Reconnect and, for long transfers, keep the queue running rather than leaving the window idle.
**Symptom**: transfers fail partway through with permission errors. Check that you are inside a folder the FTP user owns. An FTP user scoped to one site cannot write outside its own directory tree.
## Related Articles
- [How to Install Filezilla Client on Windows](/server-administration/how-to-install-filezilla-on-windows/)
- [How to Create or Delete a Directory Using FileZilla](/server-administration/how-to-create-or-delete-a-directory-using-filezilla/)
- [How to Upload the Index File to Your Website via FileZilla](/server-administration/how-to-upload-the-index-file-to-your-website-via-filezilla/)
- [How to Download Files and Directories to Your Computer via FileZilla](/server-administration/how-to-download-files-and-directories-to-your-computer-via-filezilla/)
## Need a Hand?
If the connection still fails after working through the troubleshooting steps, open a ticket from your Noiz client area and include the full FileZilla message log from the top pane. That log names the exact stage the connection failed at, which lets the Noiz support team confirm the server side and point you at the fix quickly.
# How to Create RAID Arrays for a Private ISPConfig Mail Server
Source: https://docs.noiz.ie/server-administration/how-to-create-raid-arrays-for-a-private-ispconfig-mail-server/
## Overview
This guide shows you how to create software RAID arrays with `mdadm` for a self-managed ISPConfig mail server, then format, tune and mount the storage so the operating system and the mailboxes are both resilient and fast. The worked example uses two arrays:
- **RAID1** across two SSDs (or NVMe drives) for the system disk, hosting the operating system and root filesystem.
- **RAID10** across four HDDs for large-capacity mail storage mounted at `/var/vmail`.
You can choose other RAID levels to suit your hardware and your own balance of performance against redundancy. The process below is the same regardless of the level you pick.
**Important scope note:** the root RAID1 is normally created *during operating-system installation* (the Debian and Ubuntu installers both support software RAID at partitioning time). You cannot build a fresh RAID1 over the disk that is currently running your root filesystem. This guide therefore concentrates on the dedicated mail-storage array at `/var/vmail`, which can safely be added to a server that is already up and running.
**Last reviewed:** 27 July 2026, against `mdadm` on current Debian and Ubuntu Server releases, for use with ISPConfig **3.3.1p1**. This guide is written for Noiz hosting and is kept current against the Linux RAID and ISPConfig documentation. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [Linux RAID Wiki: RAID setup](https://raid.wiki.kernel.org/index.php/RAID_setup) (kernel.org)
- [mdadm(8) manual page](https://man7.org/linux/man-pages/man8/mdadm.8.html)
- [tune2fs(8) manual page](https://man7.org/linux/man-pages/man8/tune2fs.8.html) (ext4 tuning)
- [ISPConfig official documentation](https://www.ispconfig.org/documentation/)
## Prerequisites
- Root (or `sudo`) access to the server console.
- Dedicated, empty disks for the data array. Never target the disk that holds your running operating system.
- `mdadm` installed: `apt install mdadm`.
- An understanding that creating an array is destructive to every disk you name. Back up anything you cannot lose before you begin.
## Step 1: Identify the disks
List the block devices and confirm exactly which drives you intend to use before you touch anything:
```
lsblk -o NAME,SIZE,TYPE,MOUNTPOINT
mdadm --examine /dev/nvme0n1 /dev/nvme1n1 /dev/sda /dev/sdb /dev/sdc /dev/sdd
```
Make sure the disks you plan to use are clean and carry no old RAID metadata or partitions. If they still hold stale metadata, clear it:
```
mdadm --zero-superblock /dev/sda /dev/sdb /dev/sdc /dev/sdd
wipefs -a /dev/sda /dev/sdb /dev/sdc /dev/sdd
```
**Warning:** `zero-superblock` and `wipefs` permanently erase RAID and filesystem signatures. Run them only against the empty data disks you have positively identified with `lsblk`. Never run them against a disk that is mounted or that holds the running operating system, or you will destroy the server.
## Step 2: Create the array or arrays
Create the system array across the SSDs or NVMe drives (RAID1 in this example). As noted above, do this only at install time or from a rescue environment, never over a live root disk:
```
mdadm --create --verbose /dev/md0 --level=1 --raid-devices=2 /dev/nvme0n1 /dev/nvme1n1
```
Create the mail-storage array across the HDDs (RAID10 in this example). This one can be added to a running server:
```
mdadm --create --verbose /dev/md3 --level=10 --raid-devices=4 /dev/sda /dev/sdb /dev/sdc /dev/sdd
```
When prompted, keep the write-intent bitmap enabled. It costs almost nothing and lets a future rebuild or resync resume only the changed regions rather than re-scanning the whole array, which is a large saving on multi-terabyte disks.
**Safe during resync?** Yes. The initial resync starts automatically in the background as soon as the array is created, and you can continue to the next steps while it runs.
## Step 3: Monitor the resync
```
cat /proc/mdstat
```
The resync runs in the background and can take several hours on large disks. You may continue with the steps below while it is in progress, but expect reduced throughput until it finishes. For a live progress view, run `watch -n5 cat /proc/mdstat`.
## Step 4: Format the array
```
mkfs.ext4 -L vmail /dev/md3
```
Format the array with a filesystem. For maildir mail storage, ext4 is stable and performs well. The `-L vmail` label makes the filesystem easy to identify later.
**Safe during resync?** Yes.
## Step 5: Tune the filesystem
```
# Remove the root-reserved space
tune2fs -m 0 /dev/md3
# Directory indexing for large maildirs
tune2fs -O dir_index /dev/md3
# Faster filesystem checks
tune2fs -O uninit_bg /dev/md3
# Optional: faster journal mode
tune2fs -o journal_data_writeback /dev/md3
```
- `-m 0`: removes the default reservation (around 5% of the array) that is normally set aside for the root user. That reservation protects a system partition from filling completely, but on a dedicated data array it just wastes space, potentially terabytes on a large array.
- `dir_index`: speeds up lookups in directories that hold many files, which is exactly what a busy maildir store becomes.
- `uninit_bg`: lazily initialises block-group metadata so that `fsck` runs faster.
- `journal_data_writeback`: improves write throughput at the cost of slightly weaker crash-consistency guarantees for file data, which is an acceptable trade-off for a maildir workload. Leave this off if you prefer the safer default ordered mode.
**Safe during resync?** Yes.
## Step 6: Get the UUID
```
blkid /dev/md3
```
Copy the `UUID` value from the output. You need it for `/etc/fstab` in the next step. Always mount by UUID rather than by device name, because `/dev/mdX` numbers can change across reboots while the UUID does not.
**Safe during resync?** Yes.
## Step 7: Mount and configure fstab
```
mkdir -p /var/vmail
```
Edit `/etc/fstab` and add a line for the array, substituting the UUID you copied above (the value below is only an example):
```
# RAID array for mail storage
UUID=abcd1234-ef56-7890-1234-56789abcdef0 /var/vmail ext4 noatime,lazytime,commit=60,errors=remount-ro 0 2
```
What the mount options do:
- `noatime,lazytime`: cut down on metadata writes by not updating access times on every read.
- `commit=60`: flushes the journal every 60 seconds instead of the default 5, reducing write load. In a power-loss event this widens the window of data that could be lost, so choose the value deliberately.
- `errors=remount-ro`: remounts the filesystem read-only if an error is detected, which is the safer behaviour for mail storage.
Reload the unit definitions and mount everything from `fstab`:
```
systemctl daemon-reload
mount -a
df -h /var/vmail
```
Confirm that `df` shows `/var/vmail` on the array at the expected size. If `mount -a` reports an error, re-check the UUID and the fstab syntax before rebooting, because a bad fstab entry can leave the server unable to boot cleanly.
**Adding the array to a server that already runs ISPConfig?** Two things bite here. Mounting an empty filesystem over `/var/vmail` hides the mail already stored there, so stop the mail services, copy the existing contents onto the array and only then mount it over the top. And a newly formatted filesystem is owned by root, so hand the mountpoint back to the mail user once it is mounted, matching the ownership and mode the directory had beforehand:
```
chown vmail:vmail /var/vmail
```
`vmail` is the default **Mailuser Name** and **Mailuser Group**, both set on the **Mail** tab under **System > Server Config**. Read those two fields first if your server uses different values.
**Safe during resync?** Yes.
## Step 8: Persist the RAID configuration
```
mdadm --detail --scan >> /etc/mdadm/mdadm.conf
update-initramfs -u
```
This records the arrays so they are recognised and auto-assembled at boot. Without it, the system can boot without the mail array attached, leaving ISPConfig with no mail storage. After running the append, open `/etc/mdadm/mdadm.conf` and remove any duplicate `ARRAY` lines if you ran the command more than once.
While that file is open, set the `MAILADDR` line to an address you actually read. Debian and Ubuntu run `mdadm` in monitor mode as a service, and that address is where the warning goes when a disk drops out of the array.
**Safe during resync?** Yes.
## Step 9: Reboot test
Ideally, wait until the resync completes before rebooting. If you must reboot sooner, the write-intent bitmap ensures the resync resumes from where it left off rather than starting over.
```
reboot
```
After the server comes back up, verify that the array assembled and the mount is present:
```
cat /proc/mdstat
mount | grep vmail
```
## Checking the array from the ISPConfig panel
If ISPConfig is already installed on this server, you do not need an SSH session to check the array. Go to **Monitor > Server State > RAID state**, which shows the same `/proc/mdstat` output used in Step 3, with a status flag on top of it. A degraded array is flagged critical, unless a rebuild is already running, in which case it is flagged as information only.
Two caveats. The page shows a snapshot collected by a scheduled job, so it can sit a few minutes behind the command line. And the status flag is worked out from two-disk mirror patterns, so on a four-disk RAID10 treat the panel as a convenience view and keep the `mdadm` email alert from Step 8 as the alarm you rely on.
## Troubleshooting
**Array does not appear after reboot**: confirm Step 8 was completed, that `/etc/mdadm/mdadm.conf` contains the `ARRAY` line, and that you ran `update-initramfs -u` afterwards.
**`mount -a` fails or the server drops to an emergency shell on boot**: this is almost always a wrong UUID or a typo in `/etc/fstab`. Re-run `blkid /dev/md3` and compare it against the fstab line character for character.
**Resync appears stuck at 0%**: check `cat /proc/mdstat` for a queued state. Only one resync runs at a time per controller, so a second array may wait for the first to finish.
## Next steps
Your arrays are now created, formatted, tuned, mounted and persistent across reboots. You can proceed to [installing ISPConfig](https://www.ispconfig.org/documentation/), which needs no path changes to use this array. The mail settings default to a **Homedir Path** of `/var/vmail` and a **Maildir Path** of `/var/vmail/[domain]/[localpart]`, so the mailbox for `user@yourdomain.com` lands in `/var/vmail/yourdomain.com/user`. Both fields sit on the **Mail** tab under **System > Server Config**.
If you mount the array somewhere other than `/var/vmail` and edit those fields to match, keep **Maildir Path** inside **Homedir Path**. A maildir path that is not below the home directory will most likely stop the mail system working.
### Point the backup directory at the array
ISPConfig writes its backups to one location, set in the **Backup directory** field on the **Server** tab under **System > Server Config**. It defaults to `/var/backup`, which is on the root disk. Change it to a directory on the dedicated array, for example `/var/vmail/backup`, so that backups cannot fill the system partition. Mailbox backups are filed there in a subdirectory per mail domain, alongside any website backups, and on a busy mail server they grow quickly.
Leave **Backup directory is a mount?** on the same tab unticked for an array mounted from `/etc/fstab` as above. That option is for a backup target that has to be attached on demand: it makes ISPConfig run `/usr/local/ispconfig/server/scripts/backup_dir_mount.sh` before the backup starts, and you have to write that script yourself.
One caution on placement. A RAID array survives a disk failing, not a mailbox being deleted or a filesystem being corrupted, so treat the array as the fast local copy and keep a second copy off this server.
## Need a managed mail server instead?
Building and maintaining a self-managed mail server is involved, from RAID and storage tuning through to deliverability and security hardening. If you would rather Noiz handle the infrastructure, the Noiz support team can advise on managed hosting options that remove this operational burden. Reach the team through your Noiz client area.
# How to Create User-Friendly URLs Using .htaccess
Source: https://docs.noiz.ie/server-administration/how-to-create-user-friendly-urls-using-htaccess/
A **user-friendly URL** (sometimes called a clean, pretty, or search-engine-friendly URL) is a short, readable web address that hides a longer file path behind the scenes. Instead of sending visitors to **example.com/files/folder/sitemap.html**, you can let them use **example.com/sitemap** while the real file stays exactly where it is. Tidy URLs are easier to remember, easier to share, and generally read better to both people and search engines.
You achieve this with a small `.htaccess` file and Apache's `mod_rewrite` module. The `.htaccess` file is a per-directory configuration file that Apache reads on every request, so a rewrite rule takes effect the moment you save it, with no restart needed. This is a general Apache technique, so it works the same way whichever control panel your hosting uses.
**Last reviewed:** 27 July 2026, against Apache HTTP Server **2.4** (current stable series) and its `mod_rewrite` module. This guide is written for Noiz hosting and is kept current against Apache. It complements, and does not replace, the official Apache documentation linked below.
### Official Documentation Reference
- [Apache mod\_rewrite Introduction (httpd.apache.org)](https://httpd.apache.org/docs/2.4/rewrite/intro.html)
- [The RewriteRule directive (httpd.apache.org)](https://httpd.apache.org/docs/2.4/mod/mod_rewrite.html#rewriterule)
- [RewriteRule flags: L, R, QSA, NC and others (httpd.apache.org)](https://httpd.apache.org/docs/2.4/rewrite/flags.html)
- [Apache .htaccess how-to (httpd.apache.org)](https://httpd.apache.org/docs/2.4/howto/htaccess.html)
## Prerequisites
- A hosting account served by Apache with `mod_rewrite` available. This is the standard configuration on Noiz shared hosting, so no setup is needed on your side.
- Access to your website files, either through your control panel's File Manager or over SFTP.
- The exact real path of the file or page you want to reach, relative to your document root (for example `/files/folder/sitemap.html`).
- A copy of your current `.htaccess` file kept somewhere safe. A single malformed line takes the whole site offline until it is corrected, so having a known-good version to restore is worth the thirty seconds it costs.
## Where the .htaccess file lives
An `.htaccess` file applies to the folder it sits in and every folder beneath it. For rules that should cover your whole site, put it in your document root, which is the top-level folder that holds your public web files (commonly named `public_html`, `httpdocs`, or `public`, depending on your panel). If a file called `.htaccess` already exists there, edit that one rather than replacing it, since your platform may rely on rules that are already present.
Note the leading dot in the name. It makes the file hidden by default, so if you cannot see it, enable **Show hidden files** (sometimes labelled **dotfiles**) in your File Manager or SFTP client.
## Point a short URL at a longer path
### 1. Open or create the .htaccess file
In your document root, open the existing `.htaccess` file for editing, or create a new plain-text file named exactly `.htaccess` (no other extension). Watch out for text editors that helpfully append `.txt` on save, which is one of the most common reasons a perfectly good rule appears to do nothing.
### 2. Add the rewrite rule
Add the following two lines. Change the pattern and the target path to match your own site, then save the file:
```
RewriteEngine On
RewriteRule ^sitemap/?$ /files/folder/sitemap.html [L]
```
With this in place, a visitor who types **example.com/sitemap** is served the contents of **example.com/files/folder/sitemap.html**, while the tidy address stays in their browser bar.
### 3. Test it
Visit the friendly URL in a private or incognito window (browsers cache redirects aggressively, so a fresh window avoids confusing results). The page should load normally, complete with its images and styling. Then load two or three unrelated pages to confirm your new rule has not swallowed requests it should have ignored. If anything misbehaves, see the troubleshooting notes below.
## Understanding the rule
Reading the rule left to right makes it easy to adapt:
- `RewriteEngine On` switches the rewrite engine on. You only need this line once per `.htaccess` file, before any rules.
- `RewriteRule` is followed by three parts: the pattern to match, the real file to serve, and a set of flags.
- `^sitemap/?$` is the pattern, written as a regular expression. The `^` anchors it to the start of the address and the `$` anchors it to the end, so it matches the whole path and nothing longer. The `/?` makes a trailing slash optional, so both `example.com/sitemap` and `example.com/sitemap/` work.
- `/files/folder/sitemap.html` is the real file that Apache serves when the pattern matches.
- `[L]` is the **Last** flag. It tells Apache to stop processing further rules once this one matches, which keeps behaviour predictable as you add more rules.
Because this is an internal rewrite rather than a redirect, the change happens on the server and the visitor never sees the underlying path.
### Two details that catch almost everyone
**Do not put a leading slash in the pattern.** Inside an `.htaccess` file, Apache strips the leading slash from the path before matching, so the pattern is `^sitemap/?$` and never `^/sitemap/?$`. A stray leading slash produces a rule that is syntactically valid, throws no error, and simply never matches anything.
**Make the trailing slash optional.** An older form of this snippet used `^sitemap/$`, which only matches when the visitor types the trailing slash. Everyone who types `example.com/sitemap` gets a 404 instead. The `/?` in `^sitemap/?$` accepts both forms, which is nearly always what you want.
## Rewrite quietly, or redirect visibly
The rule above is an internal rewrite: the short address stays in the browser bar and the real path is never exposed. If you instead want the browser to move to a different address, for example because a page has genuinely moved, add the **Redirect** flag:
```
RewriteRule ^old-page/?$ /new-page [R=301,L]
```
Use `R=301` for a permanent move, which passes accumulated search ranking to the new address, and `R=302` only for changes that really are temporary. Choose deliberately. Browsers cache 301 responses hard, so a permanent redirect pointed at the wrong place keeps sending returning visitors astray long after the rule itself is fixed. Testing with `R=302` and promoting to `R=301` once the behaviour is confirmed avoids that.
## Handy variations
### Pass part of the URL through as a parameter
To turn `example.com/product.php?id=42` into `example.com/products/42`:
```
RewriteEngine On
RewriteRule ^products/([0-9]+)/?$ product.php?id=$1 [L,QSA]
```
The bracketed group captures one or more digits and hands them to the target as `$1`. The `QSA` flag (query string append) preserves anything the visitor added themselves, so `/products/42?ref=email` still passes `ref=email` along to the script.
### Drop the .html extension across a whole site
```
RewriteEngine On
RewriteCond %{REQUEST_FILENAME} !-d
RewriteCond %{REQUEST_FILENAME}.html -f
RewriteRule ^(.*)$ $1.html [L]
```
The two `RewriteCond` lines act as guards: the request must not already be a real directory, and a matching `.html` file must actually exist on disk. Without those checks the rule fires on requests for images, stylesheets and fonts as well, which is the usual route into a rewrite loop.
### Send everything to a single front controller
Most modern applications route every request through one entry file. The standard pattern is:
```
RewriteEngine On
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteRule ^ index.php [L]
```
Real files and real directories are served normally, and everything else is handed to `index.php` to resolve. If your application already ships its own `.htaccess` block, leave it intact and add your rules above it rather than overwriting it.
### Other useful notes
- **Escape literal dots.** In a regular expression a dot means "any character". If your pattern needs to match an actual dot, write it as `\.` so it is treated literally.
- **Rules run top to bottom.** Apache evaluates each rule in order, so place more specific rules above broader ones and use the `[L]` flag to stop once a match is found.
- **Working inside a subfolder.** If your `.htaccess` lives in a subdirectory rather than the document root, add a `RewriteBase` line (for example `RewriteBase /shop/`) so the paths resolve correctly.
- **Comment your rules.** Any line beginning with `#` is ignored. Six months on, the reason for an obscure pattern is rarely obvious from the pattern alone.
## Watch out for relative asset paths
A page that used to live at `/files/folder/sitemap.html` and is now served at `/sitemap` appears to the browser to sit at a different depth in the site. Any asset referenced relatively, such as `images/logo.png`, will be requested from the wrong folder and the page will load unstyled or without images. Fix it by referencing assets from the site root instead, as `/files/folder/images/logo.png`, or by adding a `` tag in the page head. This catches people out far more often than the rewrite rule itself does.
## Troubleshooting
**You get a 500 Internal Server Error after saving**: this almost always points to a typo in the rule. Check that `RewriteEngine On` appears once, that the rule has exactly three parts, and that there are no stray characters. Comment out the new lines with `#` and reload to confirm the site recovers, then re-enable them one at a time. The error log in your control panel names the offending line number, which turns guesswork into a two-minute fix.
**The friendly URL does nothing**: make sure the file was saved as `.htaccess` with the leading dot and no hidden extension such as `.txt`, and that you edited the file in your document root. Check for a leading slash in the pattern and for a mandatory trailing slash, the two failure modes described above. On Noiz shared hosting `mod_rewrite` is enabled and `.htaccess` overrides are permitted by default, so you should not need to change any server settings.
**The browser reports a redirect loop**: a rule is rewriting a request into something that matches the same rule again. Add `RewriteCond %{REQUEST_FILENAME} !-f` and `RewriteCond %{REQUEST_FILENAME} !-d` above the rule so real files and folders are left alone, and confirm the rule's target cannot match its own pattern.
**A rule catches more than it should**: patterns without `^` and `$` match anywhere in the path, so a bare `RewriteRule sitemap` also fires on `/blog/sitemap-notes`. Anchor every pattern unless you have a specific reason not to.
**The old behaviour keeps appearing**: your browser may have cached an earlier redirect. Test in a private window, or clear your browser cache, before deciding a rule is not working.
**The same rules work on one site but are ignored on another**: `.htaccess` is an Apache feature. A web server such as nginx never reads the file and needs equivalent rewrite rules defined in its own site configuration instead. If the site in question is served by a static host or sits behind a proxy layer that never reaches Apache, the file will have no effect.
## Good practice worth following
- Keep short addresses lowercase and hyphen-separated. Apache paths are case-sensitive, so `/Sitemap` and `/sitemap` are two different requests.
- Pick one canonical form per page, either with or without the trailing slash, and redirect the other to it. Serving identical content at two addresses splits your search ranking between them.
- Keep the original long address working, or redirect it to the short one, so that existing links and bookmarks do not break.
- Save a dated copy of a working `.htaccess` file outside the document root before each round of edits.
## Need a hand?
If a rewrite rule is not behaving as expected, or your site has returned a 500 error after an `.htaccess` edit, open a ticket from the Noiz client area with the domain name and the exact rules you added. The Noiz support team can read the server error log for your account, pinpoint the failing line, and confirm whether the rule is reaching Apache at all.
# How to Create a User-Friendly URL Using htaccess
Source: https://docs.noiz.ie/server-administration/how-to-create-a-user-friendly-url-using-htaccess/
A long, folder-heavy web address such as `example.com/files/folder/sitemap.html` is hard to remember, awkward to share, and rarely the address you want visitors or search engines to see. With Apache's `mod_rewrite` module you can serve the same page under a short, tidy address like `example.com/sitemap`. This guide shows you the rewrite rule to use, explains what each part does, and covers the small gotchas that trip people up.
The technique here uses a **.htaccess** file, the per-directory configuration file Apache reads for your site. If your site runs on Apache (the default on standard Noiz shared and reseller hosting), this is all you need.
**Last reviewed:** 27 July 2026, against Apache HTTP Server **2.4** (current stable) and its `mod_rewrite` module. This guide is written for Noiz hosting and is kept current against Apache. It complements, and does not replace, the official Apache documentation linked below.
### Official Documentation Reference
- [Apache Module mod\_rewrite (httpd.apache.org)](https://httpd.apache.org/docs/current/mod/mod_rewrite.html)
- [Apache mod\_rewrite Introduction](https://httpd.apache.org/docs/current/rewrite/intro.html)
- [Apache .htaccess Files HOWTO](https://httpd.apache.org/docs/current/howto/htaccess.html)
## Prerequisites
- A site hosted on Apache with `mod_rewrite` enabled. On standard Noiz hosting this is already the case.
- The ability to edit (or create) a **.htaccess** file in your site's document root, using your control panel's File Manager or an FTP client.
- The real path to the page you want to expose under a shorter address, for example `files/folder/sitemap.html`.
## Add the Rewrite Rule
Open the **.htaccess** file in your site's document root (usually the `public_html` or `httpdocs` folder). If the file does not exist yet, create a new one named exactly `.htaccess`, including the leading dot. Add the following, adjusting the two paths to match your own site:
```
RewriteEngine On
RewriteRule ^sitemap/?$ /files/folder/sitemap.html [L]
```
Save the file. Visitors can now reach the page at `example.com/sitemap` (with or without a trailing slash), while Apache quietly serves the content from the real file. The address bar keeps showing the short URL, because this is an internal rewrite rather than a visible redirect.
## How the Rule Works
- `RewriteEngine On` switches the rewrite engine on. It only needs to appear once at the top of the file, no matter how many rules follow.
- `^sitemap/?$` is the pattern Apache matches against the requested path. The `^` anchors it to the start, `$` to the end, and `/?` makes the trailing slash optional so that both `/sitemap` and `/sitemap/` match.
- `/files/folder/sitemap.html` is the real file that gets served when the pattern matches. Change this to your own target path.
- `[L]` is the "last" flag. It tells Apache to stop processing further rules once this one matches, which avoids unexpected interactions with other rules in the file.
To map more pages, add one `RewriteRule` line per page beneath the same `RewriteEngine On` line, for example:
```
RewriteEngine On
RewriteRule ^sitemap/?$ /files/folder/sitemap.html [L]
RewriteRule ^about/?$ /pages/company/about-us.html [L]
```
## Good to Know
- **Trailing slash.** The original short snippet used `^sitemap/$`, which only matched the address *with* a trailing slash. The `/?` shown above accepts both forms, which is usually what you want.
- **Internal rewrite versus redirect.** The rule above rewrites the request internally, so the browser keeps showing the short URL. If you would rather send visitors to a different visible address (a genuine redirect), add the `R` flag, for example `[R=301,L]` for a permanent redirect. Only do this when you actually want the address bar to change.
- **Where the file lives.** A `.htaccess` file applies to the folder it sits in and everything below it. Placing it in your document root covers the whole site.
- **Relative paths.** If your rules live in a subdirectory and the substitution paths behave oddly, set a `RewriteBase /` line after `RewriteEngine On` to make Apache resolve paths from a known starting point.
## Troubleshooting
**Symptom:** The site returns a **500 Internal Server Error** after you save the file. This almost always means a syntax slip in the `.htaccess` file, or that `mod_rewrite` is not available. Recheck the rule for typos, make sure there is exactly one `RewriteEngine On` line, and confirm the file is plain text with no stray characters.
**Symptom:** The short URL does nothing and the long URL still works. Confirm the file is named exactly `.htaccess` (with the leading dot and no `.txt` extension), that it is in the correct document root, and that the pattern matches the address you are typing. A browser can also cache an earlier response, so test in a private window or after clearing the cache.
**Symptom:** The page loads but its images, stylesheets, or links break. This happens when the page uses paths relative to its original folder. Switch the page to root-relative paths (beginning with `/`) or absolute URLs so they resolve correctly under the new short address.
If you are on a managed Noiz plan and would prefer the rewrite set up for you, contact the Noiz support team with the long URL and the short address you want, and the team will put it in place.
# How to Create or Delete a Directory Using FileZilla
Source: https://docs.noiz.ie/server-administration/how-to-create-or-delete-a-directory-using-filezilla/
Directories, also called folders, are how you organise a website on the server. You might want an `images` folder for your graphics, a `backup` folder to park an old copy of a page, or a subfolder to hold a second site section. This guide shows you how to create and delete directories on your Noiz hosting account using the FileZilla FTP client, and covers the naming rules and deletion pitfalls that catch people out.
The steps below apply to any Noiz hosting account, whichever control panel your account uses. FTP is a server-level service, so the credentials and the folder actions are the same regardless of the panel you log in to for everything else.
**Last reviewed:** 27 July 2026, against FileZilla Client **3.x** (current stable series). This guide is written for Noiz hosting and is kept current against FileZilla. It complements, and does not replace, the official FileZilla documentation linked below.
The screenshots in this article were captured on an earlier 3.x release. The menu wording and layout are effectively unchanged in the current version, so what you see on screen will match.
### Official Documentation Reference
- [FileZilla Client Tutorial](https://wiki.filezilla-project.org/FileZilla_Client_Tutorial_(en)): the vendor walkthrough of the interface and the file panes.
- [Using FileZilla](https://wiki.filezilla-project.org/Using): browsing, the transfer queue, and directory comparison.
## Prerequisites
- FileZilla Client installed on your computer. See [How to Install FileZilla on Windows](/server-administration/how-to-install-filezilla-on-windows/).
- An active FTP account on your hosting service, with its username and password to hand.
- A working connection to the server. See [How to Connect to Your FTP Account Using FileZilla](/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/) if you have not connected before.
## Connect to Your Hosting Account
1. Open the FileZilla Client.
2. Enter your FTP **Host**, **Username** and **Password** in the Quick Connect bar across the top of the window, then click **Quickconnect**. Leave **Port** blank unless Noiz has given you a specific port.
- The **Host** is your domain name, in the form `ftp.yourdomain.com` or `yourdomain.com`. Replace `yourdomain.com` with your own domain. If your domain is not yet pointed at the Noiz nameservers, use the server hostname from your Noiz welcome email instead.
- The **Username** and **Password** are the FTP credentials issued or created for your hosting account. They are not your Noiz client area login and not your email password.

Once connected, your own computer's files appear in the left pane and your hosting account's files appear in the right pane. Everything in this guide happens in the right pane.
## Create a Directory
1. In the right pane, open the folder you want the new directory to live inside. For a folder that must be reachable on the web, that is your web root, commonly named `public_html`, `httpdocs` or `web` depending on the platform your account runs on. Double-click the folder to enter it. 
2. Right-click on empty space in the file listing, below the existing filenames, and choose **Create directory** from the context menu. Choosing **Create directory and enter it** instead does the same thing and then opens the new folder for you, which saves a click if you are about to upload into it. 
3. Type the directory name, such as `images`, and click **OK**. FileZilla pre-fills the box with a suggested name, so clear it before typing rather than typing after it. 
4. The new directory appears in the listing. Double-click it to go inside. If it does not appear straight away, press **F5** or right-click and choose **Refresh** to reload the listing from the server.
### Name Directories Correctly
Noiz hosting runs on Linux, and Linux filenames are case sensitive. `Images` and `images` are two different folders, and a page linking to `/images/logo.png` will return a 404 error if the folder on the server is actually called `Images`. This is the single most common cause of "it worked on my PC but not on the live site", because Windows does not care about case and the server does.
To stay out of trouble:
- Use lowercase letters only.
- Use hyphens instead of spaces. `product-photos` works cleanly in a URL, `product photos` becomes `product%20photos`.
- Stick to letters, numbers, hyphens and underscores. Avoid `&`, `#`, `?`, `%` and accented characters, which have special meanings in URLs.
- Do not start the name with a dot unless you mean to. A leading dot makes the folder hidden, and FileZilla will not display it until you enable **Server** then **Force showing hidden files**.
A new directory created over FTP is owned by your FTP user and typically gets `755` permissions, which is what a web-served folder needs. You do not normally need to change anything. If a script later reports that it cannot write to the folder, right-click the folder, choose **File permissions**, and check the value there before changing it, as loosening permissions unnecessarily is a security risk.
## Delete a Directory or File
1. In the right pane, right-click the directory or file you want to remove.
2. Choose **Delete** from the context menu, then confirm with **Yes**. 
The same method removes single files. To remove several items at once, hold **Ctrl** and click each one, or hold **Shift** to select a range, then right-click the selection and choose **Delete**.
### Before You Delete Anything
FTP deletion is permanent. There is no recycle bin on the server and no undo in FileZilla. Once the confirmation dialogue is accepted, the only way back is a restore from backup.
- **Deleting a directory deletes everything inside it.** FileZilla walks the folder and removes every file and subfolder within it, because FTP servers refuse to remove a directory that is not empty. On a folder with thousands of files this can take several minutes and the client will look busy while it works. Do not close FileZilla mid-deletion.
- **Check for hidden files first.** A folder that looks empty may still contain a `.htaccess` file or similar. Turn on **Server** then **Force showing hidden files** so you can see the full contents before deciding.
- **Download a copy if you are not certain.** Dragging the folder from the right pane to the left pane pulls a full copy to your computer first. That takes a minute and turns an irreversible action into a reversible one.
- **Do not delete the web root itself.** Removing `public_html`, `httpdocs` or `web` takes your site offline and can break the account's document root configuration. Empty its contents instead of deleting the folder.
- **Deleting a folder does not remove what pointed at it.** Menu links, database records and CMS media references pointing to the old path will start returning 404 errors. Tidy those up in the site itself afterwards.
## Troubleshooting
**Symptom**: `550 Permission denied` or `550 Create directory operation failed`. The FTP user does not have write access to the folder you are in. Confirm you are inside your own account's directory tree and not one level too high. An FTP user scoped to a single site cannot create or delete anything outside its own folder.
**Symptom**: `550 Directory not empty`. The server rejected the removal because files remain inside. Open the folder, enable **Force showing hidden files**, delete the contents, then delete the folder.
**Symptom**: the new folder does not appear after you create it. The listing on screen is a cached view. Press **F5** to refresh from the server.
**Symptom**: the folder exists but the URL returns a 404 error. Check three things in order. First, that the folder is inside the web root and not in the account home directory alongside it. Second, that the spelling and capitalisation in your link match the folder exactly. Third, that the folder contains an index file, since a folder with no `index.html` or `index.php` will not serve anything on its own.
**Symptom**: deletion appears to hang. Large directory trees are removed file by file over the connection, so this is usually slow progress rather than a stall. Watch the message log in the top pane. If it is still listing filenames, it is working.
**Symptom**: `Connection closed by server` partway through a long deletion. The session timed out. Reconnect and repeat the deletion, which will resume on whatever is left.
## Related Articles
- [How to Install FileZilla on Windows](/server-administration/how-to-install-filezilla-on-windows/)
- [How to Connect to Your FTP Account Using FileZilla](/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/)
- [How to Upload the Index File to Your Website via FileZilla](/server-administration/how-to-upload-the-index-file-to-your-website-via-filezilla/)
- [How to Download Files and Directories to Your Computer via FileZilla](/server-administration/how-to-download-files-and-directories-to-your-computer-via-filezilla/)
## Need a Hand?
If a directory will not create or delete, or you have removed something you needed back, open a ticket from your Noiz client area straight away. Include the full FileZilla message log from the top pane and the exact path involved. Acting quickly matters for accidental deletions, because backup retention is finite and the sooner a restore is requested the more likely the file is still recoverable.
# How to Download Files and Directories to Your Computer via FileZilla
Source: https://docs.noiz.ie/server-administration/how-to-download-files-and-directories-to-your-computer-via-filezilla/
Downloading is how you pull a copy of your website files off the server and onto your own computer, whether you want a local backup before making changes, a copy of a single file to edit, or the whole site to hand to a developer. This guide shows you how to download files and directories from your Noiz hosting account using the FileZilla Client, and covers the parts that catch people out: choosing where the files land, hidden files that FileZilla will not show you by default, and what an FTP download does not include.
These steps apply to any Noiz hosting account, whichever control panel your account uses. FTP is a server-level service, so the connection details come from your hosting account rather than from any particular panel screen.
**Last reviewed:** 27 July 2026, against FileZilla Client **3.x** (current stable series). This guide is written for Noiz hosting and is kept current against FileZilla. It complements, and does not replace, the official FileZilla documentation linked below.
### Official Documentation Reference
- [FileZilla Client Tutorial](https://wiki.filezilla-project.org/FileZilla_Client_Tutorial_(en)): the vendor walkthrough of the interface and first connection.
- [Using FileZilla](https://wiki.filezilla-project.org/Using): Site Manager, the transfer queue, and directory comparison.
- [FileZilla Network Configuration](https://wiki.filezilla-project.org/Network_Configuration): active versus passive mode, firewalls, and router behaviour.
- [FileZilla Client downloads](https://filezilla-project.org/download.php?type=client): official builds only.
## Prerequisites
- FileZilla Client installed on your computer. See [How to Install FileZilla on Windows](/server-administration/how-to-install-filezilla-on-windows/).
- An active FTP account on your hosting service, along with its username and password. These are the FTP details created in your hosting control panel, not your Noiz client area login and not your email password.
- The hostname to connect to, which is either your domain name or the server hostname shown in your Noiz welcome email.
- Enough free disk space on your computer for whatever you are about to pull down. A media-heavy site can easily run to several gigabytes.
## Connect to Your Hosting Account
Open the FileZilla Client, then enter your host, username and password in the Quick Connect bar across the top of the window and click **Quickconnect**. Leave **Port** blank unless Noiz has given you a specific port.

For the full connection walkthrough, including how to require encryption rather than sending your password in clear text, see [How to Connect to Your FTP Account Using FileZilla](/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/). Noiz recommends setting the connection up in the Site Manager with **Encryption** set to **Require explicit FTP over TLS**, because Quick Connect will quietly fall back to an unencrypted session if the negotiation fails.
Once you are connected, the FileZilla window splits into two halves. The **left** pane is your own computer. The **right** pane is the server. Downloading means moving files from right to left.
## Choose Where the Files Will Land First
This is the step almost everyone skips, and it is the reason files go missing after a download. FileZilla saves downloaded files into whichever folder is currently open in the **left** pane. It does not ask you, and it does not use your browser's Downloads folder.
Before you download anything, navigate the left pane to the folder you want the files in, or create a new one there by right-clicking and choosing **Create directory**. A folder named after the site and the date, such as `yourdomain-2026-07-26`, saves a great deal of confusion later when you have several copies.
If you always want a particular site to download to the same place, open **File** then **Site Manager**, select the site, open the **Advanced** tab, and set **Default local directory**. FileZilla will then open that folder in the left pane every time you connect to that site.
## Download Files and Directories
In the right pane, browse to the folder holding what you want. For website files this is normally the web root, commonly named `public_html`, `httpdocs` or `web` depending on the platform your account runs on. If the FTP user was scoped to a single site, you may already be in the right place at login.
1. In the right pane, under the **Filename** column, click the file or directory you want.
2. To select more than one item, hold **Ctrl** and click each item you want. To select a continuous block, click the first item, hold **Shift**, then click the last item. **Ctrl** and **A** together selects everything in the current folder.
3. Right-click the selection and choose **Download**. Dragging the selection into the left pane does exactly the same thing, so use whichever you find easier.

Selecting a directory downloads that directory and everything inside it, including all sub-directories, so there is no need to open it and select the contents by hand.
If you would rather queue several separate selections and start them all at once, choose **Add files to queue** instead of **Download**. Nothing transfers until you press the toolbar's **Process queue** button, which is useful when you are gathering files from folders scattered around the site.
## Watch the Transfer and Confirm It Finished
The bottom of the FileZilla window is the transfer queue, and it has three tabs that matter:
- **Queued files**: what is still waiting or in progress, with a per-file progress bar and a running total.
- **Failed transfers**: anything that did not complete. This tab is the one to check before you assume a download worked, because FileZilla does not pop up a warning when individual files fail partway through a large batch.
- **Successful transfers**: everything that completed cleanly.
A large download can take anywhere from seconds to well over an hour. The limiting factor is usually your own upload and download line rather than the server, and thousands of tiny files take far longer than a single file of the same total size, because each one needs its own transfer negotiation.
If the queue stalls or files start failing, right-click inside the **Failed transfers** tab and choose **Reset and requeue all files**. FileZilla will retry only what did not make it, rather than starting the whole job again.
## Gotchas Worth Knowing Before You Rely on the Copy
### Hidden files are not shown by default
Files beginning with a dot, such as `.htaccess`, `.env` and `.user.ini`, are hidden on the server, and FileZilla will not list or download them unless you ask it to. A site backup missing its `.htaccess` file will lose its rewrite rules, redirects and access restrictions.
Open the **Server** menu and tick **Force showing hidden files**, then refresh the directory listing with **F5**. The dot files will appear, and you can select and download them along with everything else.
### An FTP download is not a full site backup
FTP moves files, and nothing else. It does not include your databases, your email messages, your DNS records or your control panel settings. A WordPress, Joomla or similar site downloaded over FTP alone will not restore, because the content lives in the database rather than in the files.
To take a complete copy, download the files as described here and separately export the database from your control panel or from phpMyAdmin, then keep both together. If your plan includes a full account backup feature in the control panel, that route captures everything in one archive and is the better option for a genuine backup.
### Permissions and ownership do not survive the trip
Windows and macOS do not store Unix file permissions the way the server does. When you upload the files back, permissions are reset to whatever your FTP user's defaults are, so a restored site sometimes needs its directory and file permissions corrected. Make a note of anything unusual before you download it.
### Filenames your operating system will not accept
Linux servers allow characters in filenames that Windows refuses, including `:`, `?`, `*` and `|`. Those files land in the **Failed transfers** tab with a file-writing error. Rename them on the server first, then download again. Linux is also case sensitive while Windows is not, so `Logo.png` and `logo.png` can coexist on the server but will collide on your computer.
### Very long paths on Windows
Deeply nested folders, which are common in plugin and dependency directories, can push the full path beyond the Windows path length limit and fail silently at the end of the queue. Downloading into a short destination path such as `C:\Sites\` rather than a folder buried inside your user profile avoids this.
## Troubleshooting
**Symptom**: the download finished but you cannot find the files. They went into whatever folder was open in the left pane at the time. Look at the **Successful transfers** tab, which lists the full local path of every file it wrote, and search for one of those filenames on your computer.
**Symptom**: `550 Permission denied` or `Could not start transfer` on some files. The FTP user does not have read access to those files. This usually happens with files created by a different system user, such as files written by a web application. Fix the permissions in your control panel's file manager, or ask Noiz support to check server-side ownership.
**Symptom**: `Failed to retrieve directory listing`, so you can browse nothing to download. This is nearly always a passive mode or firewall issue rather than a permissions one. In the Site Manager, open the **Transfer Settings** tab and set **Transfer mode** to **Passive**.
**Symptom**: files arrive at 0 bytes, or a text file opens as gibberish. The transfer type is wrong for that file. Open **Transfer** then **Transfer type** and confirm it is set to **Auto**, which is correct in almost all cases, then download the affected files again.
**Symptom**: the connection drops partway through a long download. FTP sessions time out when the control connection sits idle. Reconnect and requeue the failed files. FileZilla can resume a partly transferred file and will ask whether to **Resume**, **Overwrite** or **Skip** when it finds an existing local file of a different size.
**Symptom**: transfers are extremely slow. Open **Edit** then **Settings** then **Transfers** and raise **Maximum simultaneous transfers** to two or three. Going higher rarely helps and some servers will refuse the extra connections outright.
**Symptom**: `Critical file transfer error` with a local write failure. Your computer ran out of disk space, or the destination folder is one your user account cannot write to, such as a folder inside `C:\Program Files`. Choose a destination inside your own user folder or a drive with room.
## Related Articles
- [How to Install FileZilla on Windows](/server-administration/how-to-install-filezilla-on-windows/)
- [How to Connect to Your FTP Account Using FileZilla](/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/)
- [How to Create or Delete a Directory Using FileZilla](/server-administration/how-to-create-or-delete-a-directory-using-filezilla/)
- [How to Upload the Index File to Your Website via FileZilla](/server-administration/how-to-upload-the-index-file-to-your-website-via-filezilla/)
## Need a Hand?
If files keep failing to download, or you are unsure whether the copy you have taken is complete enough to restore from, open a ticket from your Noiz client area. Include the contents of the **Failed transfers** tab and the FileZilla message log from the top pane, and say which domain is involved. That log names the exact stage each transfer failed at, which lets the Noiz support team confirm the server side quickly rather than asking you to repeat the download.
# How to Enable ionCube Loader Using CloudLinux Selector in cPanel
Source: https://docs.noiz.ie/server-administration/how-to-enable-ioncube-loader-using-cloudlinux-selector-in-cpanel/
The ionCube Loader is a PHP extension that lets your server run PHP files which have been protected with the ionCube Encoder. Plenty of commercial PHP software ships this way, including billing systems, licensed themes, and paid plugins, and that software will simply refuse to start if the Loader is missing. On Noiz cPanel hosting that runs CloudLinux, you can switch the Loader on yourself from the **Select PHP Version** tool, without waiting on a support ticket.
The tool goes by a few names depending on where you read about it: **Select PHP Version** is the cPanel icon label, **PHP Selector** is the CloudLinux product name, and the extension itself appears in the list as `ioncube_loader`. They all refer to the same thing.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the *stable* and *LTS* tier in cPanel's own wording) with the Jupiter interface, and against the current CloudLinux PHP Selector. This guide is written for Noiz hosting and is kept current against cPanel, CloudLinux, and ionCube. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [CloudLinux OS Components: PHP Selector](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#php-selector): what the Selector is and the limitations it carries.
- [CloudLinux OS Components: PHP Extensions](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#php-extensions): how per-version extension sets are packaged and enabled.
- [ionCube: Loaders](https://www.ioncube.com/loaders.php): the vendor's own Loader downloads and the PHP versions each build supports.
- [ionCube: Loader documentation](https://docs.ioncube.com/loaders/): how the Loader works and what its error messages mean.
- [cPanel: MultiPHP Manager](https://docs.cpanel.net/cpanel/software/multiphp-manager-for-cpanel/): the separate, cPanel-native tool that some accounts have instead of the CloudLinux Selector.
## Prerequisites
- A Noiz cPanel hosting account and its login details.
- The PHP version your application runs on. Extension settings are stored per PHP version, so you need to know which one you are editing before you start.
- The Loader requirement from your software vendor, if they publish one. Some encoded applications state a minimum ionCube Loader version rather than just "ionCube required".
## Enable the ionCube Loader
### 1. Open Select PHP Version
Log in to your cPanel account, scroll to the **Software** section, and click **Select PHP Version**. If you cannot see the icon, type `PHP` into the search box at the top of the cPanel home page.

### 2. Open the Extensions tab
Click the **Extensions** menu. This lists every PHP extension available for the version currently selected on the account, with a tick box beside each one.

**Note**: if the **Extensions** page shows an error mentioning the native PHP version, the account is set to **native**, which is the server's own system PHP rather than a CloudLinux build. The Selector cannot manage extensions on that build. Change **Current PHP version** to a numbered version first, then come back to the Extensions tab.
### 3. Tick ioncube\_loader
Find `ioncube_loader` in the list and tick its box. The setting saves as soon as you tick it, so there is no separate **Save** button to hunt for.

### 4. Check the confirmation
A success message appears confirming that the **ionCube Loader** module has been saved. If you do not see it, the change did not apply, so reload the page and check whether the tick box is still ticked.

## Confirm the Loader Is Actually Running
A ticked box means the setting was accepted, not that your application can see the Loader. Confirm it properly before you go back to the software that needed it.
- Create a temporary file in your site's document root containing ` **Site Health** > **Info** > **Media Handling**, which reports whether GD is present and which image formats it supports.
## What to Know Before You Change This
- **The setting is per account, not per domain.** The PHP Selector applies to the whole cPanel account. Every domain and subdomain that follows the account's PHP version picks up the extension.
- **A per-domain PHP version can override it.** If a domain has been pinned to a different PHP version in **MultiPHP Manager**, that domain runs a different PHP build with its own extension list, and your change will not reach it. This is the single most common reason GD appears enabled but the site still complains.
- **GD is not Imagick.** They are separate extensions with separate tick boxes. Some applications prefer Imagick and fall back to GD, others use only one. Enabling GD does not enable Imagick.
- **Extensions are not free.** Each enabled extension adds memory to every PHP process. Enabling a long list of extensions you do not use makes it easier to hit your account's memory limit under load. Enable what the application asks for and leave the rest alone.
- **Some builds include GD already.** If the tick box is already ticked and cannot be cleared, GD is compiled into that PHP build and there is nothing to do.
- **Switching PHP version resets the picture.** Extensions are stored per PHP version. If you later move the account from PHP 8.2 to 8.3, check the **Extensions** tab again, because the new version has its own set of enabled modules.
## Troubleshooting
**Symptom: the Extensions tab shows an error about the native PHP version.** Change the version drop-down from `native` to a specific PHP version, then reopen the **Extensions** tab.
**Symptom: gd is ticked but the application still reports it as missing.** Check **MultiPHP Manager** for a per-domain PHP version that differs from the account version, and confirm with a phpinfo page loaded on that exact domain rather than on another one.
**Symptom: images upload but are never resized, and no error appears.** Many applications degrade quietly without GD. Confirm GD is loaded first, then clear any image or page cache and re-upload a test image, because the original upload will not be reprocessed on its own.
**Symptom: gd is not in the Extensions list at all.** The list is specific to the selected PHP version. Very old or very new PHP versions carry different module sets. Try a currently supported version, and if GD is still absent, open a support ticket with Noiz and quote the PHP version you selected.
**Symptom: the tick box reverts when you reload the page.** The change was not saved. Watch for the on-screen confirmation as you tick the box, and try again with browser extensions such as ad blockers disabled, since the Selector saves in the background and a blocked request fails silently.
## Related Articles
- [How to Enable or Disable PHP Extensions Using the CloudLinux Selector in cPanel](/server-administration/how-to-enable-or-disable-php-extensions-using-the-cloudlinux-selector-in-cpanel/)
- [How to Change the PHP Version via CloudLinux Selector in cPanel](/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/)
- [How to Enable the GD Extension of PHP Using CloudLinux Selector in DirectAdmin](/directadmin/how-to-enable-the-gd-extension-of-php-using-cloudlinux-selector-in-directadmin/)
If the **Extensions** tab does not appear on your account, or GD is loaded and the site still will not process images, open a support ticket from your Noiz client area with the domain name and the PHP version you selected, and the Noiz support team will check the account configuration for you.
# How to Extract and Create tar, tar.gz, and tar.bz2 Archives on Linux
Source: https://docs.noiz.ie/server-administration/how-to-extract-and-create-tar-targz-and-tarbz2-archives-on-linux/
This guide shows you how to work with compressed archives from a Linux shell prompt: extracting `.tar`, `.tar.gz` (also written `.tgz`), `.tar.bz2`, `.tar.xz` and `.zip` files, creating your own archives, listing what is inside one without unpacking it, unpacking into a chosen folder, and pulling out just a single file. It is written for Noiz clients who have shell access over SSH, whether on a VPS or dedicated server with a full shell, or through a shell-user account on shared hosting. The aim is not to hand you commands to memorise, but to explain what each `tar` option actually means, so you can read any `tar` command and understand it, and build the one you need with confidence.
A quick note on terminology. A **tar archive** (often called a *tarball*) bundles many files and folders into one file. The name comes from "tape archive". On its own, `tar` does not compress anything; it just packs. The compression is a separate step layered on top, which is why you see the double extension: `.tar.gz` is a tar archive that has then been squeezed with **gzip**, `.tar.bz2` uses **bzip2**, and `.tar.xz` uses **xz**. A `.zip` file is a different format entirely that does both jobs at once, and is handled by separate `zip` and `unzip` tools rather than by `tar`.
**Last reviewed:** 27 July 2026, against GNU tar (1.35 series) and the standard command-line archive tools shipped on Noiz Linux hosting. The `tar` options described here have been stable across GNU tar releases for many years; where a behaviour depends on the version you are running, this guide says so. It complements, and does not replace, the official GNU documentation linked below.
### Official Documentation Reference
- [GNU tar manual](https://www.gnu.org/software/tar/manual/tar.html): the complete, authoritative reference for every `tar` option and mode of operation, maintained by the GNU project.
- [tar(1) man page](https://man7.org/linux/man-pages/man1/tar.1.html): the concise manual page for `tar` as installed on current Linux distributions, listing each flag and its meaning.
- [xz(1) man page](https://man7.org/linux/man-pages/man1/xz.1.html): reference for the `xz` compressor used by `.tar.xz` and `.xz` files.
- [unzip(1) man page](https://linux.die.net/man/1/unzip): reference for the Info-ZIP `unzip` tool used for `.zip` archives.
## Prerequisites
- Shell access to your Noiz server over SSH. On a VPS or dedicated server you have a full shell; on shared hosting a shell-user (SSH) account must be enabled for your site. If you are unsure whether shell access is available on your plan, open a support ticket to check.
- A terminal or SSH client on your own computer, and you are logged in at a shell prompt on the server.
- The name and location of the archive you want to work with. Change into the folder that contains it first, for example with `cd`, or refer to it by its full path.
## Understanding the tar Flags (So You Never Have to Guess)
Almost every `tar` command you will ever see is built from a small set of single-letter options, usually clustered together after a single dash. Learn these seven and you can read and write any of them. The first three choose *what* tar does, and you pick exactly one of them:
- `-c`, long form `--create`: **c**reate a new archive.
- `-x`, long form `--extract`: e**x**tract files out of an archive.
- `-t`, long form `--list`: lis**t** the contents of an archive without extracting anything.
The next three tell tar which *compression* the archive uses. You add one of these only when the archive is compressed:
- `-z`, long form `--gzip`: the archive is gzip-compressed (`.tar.gz` or `.tgz`). Think "**z**ip", as in gzip.
- `-j`, long form `--bzip2`: the archive is bzip2-compressed (`.tar.bz2`).
- `-J`, long form `--xz`: the archive is xz-compressed (`.tar.xz`). Note this is a **capital J**; lower-case `j` is bzip2 and upper-case `J` is xz, which is an easy one to mix up.
The last two are about the archive file itself and the output:
- `-f`, long form `--file`: the very next thing on the command line is the archive **f**ile name. This option is not optional in normal use, and it must be the last letter in a cluster, because tar reads the word after it as the filename. That is why commands are written `-xzvf archive.tar.gz` and not `-xzfv archive.tar.gz`: in the second version tar would treat `v` as the filename.
- `-v`, long form `--verbose`: **v**erbose. Print each file name as it is processed. This is optional and only affects what you see on screen; leave it off for a quiet command, add it when you want to watch progress.
One more option earns its own mention because it is so useful:
- `-C DIR`, long form `--directory DIR`: **c**hange into `DIR` before doing anything. On extraction this decides where files land; on creation it decides which folder tar packs from. The directory must already exist.
So a command like `tar -xzvf backup.tar.gz` reads, letter by letter, as "e**x**tract, from a g**z**ip archive, **v**erbosely, using the **f**ile `backup.tar.gz`". Once you see it that way, the rest of this guide is just rearranging the same handful of letters.
## Extract an Archive
Match the compression flag to the file extension. In each example, replace `archive` with your real file name.
### A plain .tar file (no compression)
```
tar -xvf archive.tar
```
No compression flag is needed because nothing was compressed.
### A .tar.gz or .tgz file (gzip)
```
tar -xzvf archive.tar.gz
```
`.tgz` is simply a shorter spelling of `.tar.gz` and is extracted exactly the same way.
### A .tar.bz2 file (bzip2)
```
tar -xjvf archive.tar.bz2
```
### A .tar.xz file (xz)
```
tar -xJvf archive.tar.xz
```
Remember the capital `J` for xz.
### Do you even need the compression flag?
Modern GNU tar, which is what runs on Noiz Linux servers, inspects the archive when it opens it and recognises the compression automatically on extraction and listing. In practice this means `tar -xvf archive.tar.gz` also works, without the `-z`. Two reasons to keep supplying the correct flag anyway: it makes the command self-documenting for anyone reading it later, and it is required on older or non-GNU versions of tar, and whenever you are *creating* an archive rather than reading one. When in doubt, include it.
### A .zip file
`tar` does not handle the ZIP format; use `unzip` instead:
```
unzip archive.zip
```
This unpacks the archive into the current folder. If `unzip` is not installed, see the troubleshooting section below.
## List What Is Inside Without Extracting
Swap the `-x` (extract) for `-t` (list) and keep everything else the same. Nothing is written to disk; tar just prints the contents. This is the safe way to look before you leap, especially with an archive from an unfamiliar source.
```
tar -tvf archive.tar.gz
```
Drop the `-v` for a plain list of names, or keep it to also see sizes, permissions and dates, much like `ls -l`. The same substitution works for every compression type: `tar -tjvf archive.tar.bz2`, `tar -tJvf archive.tar.xz`, and so on. For a ZIP file, list its contents with:
```
unzip -l archive.zip
```
## Extract Into a Specific Folder
By default tar unpacks into whatever folder you are standing in. To send the contents somewhere else, add `-C` followed by the target folder. The folder must already exist, so create it first if needed:
```
mkdir -p /var/www/restore
tar -xzvf archive.tar.gz -C /var/www/restore
```
This is the clean way to unpack an archive without cluttering your current directory, and it is handy when restoring a site backup into a fresh location before moving it into place.
## Extract a Single File or Folder
You do not have to unpack an entire archive to retrieve one item. Name the file after the archive, using its exact path *as stored inside the archive*. That last part matters: the path must match what tar recorded, which is why it pays to list the archive first and copy the path from there.
```
tar -tzvf archive.tar.gz
tar -xzvf archive.tar.gz wp-content/uploads/2026/logo.png
```
The first command shows you the exact stored paths; the second pulls out just that one file, recreating any leading folders it needs. To extract a whole sub-folder, name the folder instead of a single file, for example `wp-content/uploads/`.
## Create Your Own Archive
Creating flips `-x` to `-c`. Here the order on the command line is: the options, then the name of the archive you want to *produce*, then the files or folders you want to pack into it. When creating, the compression flag is not optional: it is what tells tar to compress at all, and choosing it also decides which extension you should give the file.
### Pack a folder into a gzip archive (.tar.gz)
```
tar -czvf mysite-backup.tar.gz public_html/
```
This reads as "**c**reate, g**z**ip compressed, **v**erbose, into the **f**ile `mysite-backup.tar.gz`, from the folder `public_html/`". gzip is the sensible default: it is fast and universally supported.
### Other compression choices
```
tar -cjvf mysite-backup.tar.bz2 public_html/
tar -cJvf mysite-backup.tar.xz public_html/
tar -cvf mysite-backup.tar public_html/
```
bzip2 (`-j`) and xz (`-J`) compress smaller than gzip but take longer, with xz usually giving the smallest file at the cost of the most time and memory. The last line, with no compression flag, produces an uncompressed `.tar`, which is quick and useful when the contents are already compressed, for example a folder of images or videos, where further compression would gain almost nothing.
### Making a ZIP instead
If you need a `.zip`, for instance to send something to a Windows user, use the `zip` tool with `-r` so it includes sub-folders:
```
zip -r mysite-backup.zip public_html/
```
## A Note on Single Gzipped Files: .gz and .sql.gz
A very common point of confusion, and one worth clearing up because Noiz database backups often arrive this way. A file ending in a bare `.gz` with no `.tar` before it, such as `database.sql.gz`, is a single file that has been gzipped on its own. It is *not* a tar archive, so `tar` is the wrong tool. Uncompress it with `gunzip`:
```
gunzip database.sql.gz
```
That replaces `database.sql.gz` with the uncompressed `database.sql`. To keep the compressed copy as well, decompress to a new file instead:
```
gunzip -k database.sql.gz
```
Or stream it straight into another command without ever writing the plain file to disk, which is a tidy way to import a dump:
```
zcat database.sql.gz | mysql -u dbuser -p dbname
```
In short: two extensions ending in `.tar.gz` means "many files, use tar"; a single `.gz` such as `.sql.gz` means "one file, use gunzip".
## Troubleshooting
- **gzip: stdin: not in gzip format**, often alongside **tar: Child returned status 1** and **tar: Error is not recoverable: exiting now**: you told tar the file is gzip with `-z`, but it is not, or the download is incomplete or corrupt. First check what the file really is with `file archive.ext`, which reads the file's contents rather than trusting the name. If it reports a different compression, use the matching flag; if it looks truncated, download it again.
- **tar: Refusing to read archive contents from terminal (missing -f option?)**, or the write equivalent when creating: you left out `-f`, so tar had no archive to read from or write to. Add `-f` immediately followed by the archive name.
- **tar: archive.tar.gz: Cannot open: No such file or directory**: the name or location is wrong. Confirm you are in the right folder and that the file exists with `ls -l`, watching for typos and the exact extension.
- **tar: /path/to/dir: Cannot open: No such file or directory** when using `-C`: the target folder does not exist. Create it first with `mkdir -p /path/to/dir`, then run the extraction again.
- **tar: somefile: Not found in archive** when extracting one file: the path did not match what is stored inside. List the archive with `-t` first and copy the path exactly as shown, including any leading folders.
- **tar: Removing leading '/' from member names**: this is an informational message, not an error. tar strips the leading slash so the archive unpacks relative to the current folder rather than overwriting absolute system paths. It is a safety feature and nothing is wrong.
- **bzip2: command not found** or **xz: command not found**: the compressor for that format is not installed. On a VPS or dedicated server where you hold root, install it (the packages are typically named `bzip2` and `xz-utils`). On shared hosting, open a support ticket and Noiz will assist.
- **unzip: command not found**: the ZIP tools are not present. Install `unzip` (and `zip` for creating) on a server you control, or raise a ticket on shared hosting.
- **Cannot open: Permission denied** while extracting: you are unpacking into a folder your user cannot write to. Extract into a location you own, such as your home directory or your site's document root, then move the files into place.
If an archive will not open, or a backup does not extract the way you expect, open a support ticket with the Noiz support team. Include the exact command you ran, the full error message, and the output of `file yourarchive` and `ls -l yourarchive` so the team can see the real format and size straight away.
# How to Find the UUID of a Disk or Partition on Linux
Source: https://docs.noiz.ie/server-administration/how-to-find-the-uuid-of-a-disk-or-partition-on-linux/
This guide shows you how to find the UUID of a disk or partition on a Linux server, and, just as importantly, why you should use it. A UUID (Universally Unique Identifier) is a long, fixed label that identifies a filesystem no matter which `/dev` name the kernel gives its disk on a given boot. You will learn the three standard ways to read a UUID (**lsblk**, **blkid** and the `/dev/disk/by-uuid` directory), the difference between a filesystem UUID and a partition UUID, and how to use a UUID in `/etc/fstab` so that extra volumes mount in the right place every time. It is written for Noiz clients who run a self-managed VPS or dedicated server, or who have a shell-user account, and who reach the server over SSH with root or `sudo` access. If you have never needed a UUID before, the short version is this: it is the reliable answer to the question "which disk did I actually mean?"
**Last reviewed:** 27 July 2026, against the standard **util-linux** tools (`blkid` and `lsblk`) and the Linux `fstab(5)` format as shipped on current mainstream distributions. This guide is written for Noiz hosting and is kept current against those tools. Column layout and wording in command output can vary slightly between distributions and util-linux versions, so treat the sample output below as representative rather than character-for-character. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [fstab(5) manual page](https://man7.org/linux/man-pages/man5/fstab.5.html): the authoritative description of the `/etc/fstab` file and its six fields. It states plainly that identifying a filesystem by `UUID=` or `LABEL=` is "the recommended method, as device names are often a coincidence of hardware detection order, and can change when other disks are added or removed."
- [blkid(8) manual page](https://man7.org/linux/man-pages/man8/blkid.8.html): the reference for the `blkid` command, which reads the UUID, LABEL and TYPE tokens directly from filesystem and swap metadata.
- [lsblk(8) manual page](https://man7.org/linux/man-pages/man8/lsblk.8.html): the reference for `lsblk`, whose `-f` option prints filesystem type, label, UUID and mount point in a tree view.
- [Persistent block device naming (Arch Wiki)](https://wiki.archlinux.org/title/Persistent_block_device_naming): a distribution-neutral explanation of why `/dev/sda` style names are not stable, and of the persistent alternatives: by-uuid, by-partuuid, by-label and by-id.
## Prerequisites
- SSH access to your server as `root`, or as a user who can run `sudo`. Reading a UUID works for any user, but `blkid` only returns full, verified details when run with root privileges, and editing `/etc/fstab` always requires root.
- Basic comfort at the Linux command line: running a command, reading its output, and editing a text file with an editor such as `nano` or `vi`.
- This is a server-administration task on a VPS or dedicated server. On a shared hosting account you do not manage disks or `/etc/fstab`, so this guide does not apply there.
## What a UUID is, and the kinds you will meet
A filesystem UUID is a 128-bit identifier written into the filesystem's own metadata (its superblock) when the filesystem is created with `mkfs`. It looks like this:
```
a1b2c3d4-5e6f-4789-9abc-0123456789ab
```
Because the UUID lives inside the filesystem, it travels with the data. Move the disk to a different port, attach it to a different server, or let the kernel assign it a different `/dev` name, and the UUID stays the same. It only changes if you reformat the filesystem or deliberately reset it. That permanence is exactly what makes it useful.
You will run into a few related labels, and it helps to know which is which:
- **Filesystem UUID**: the one described above, stored in the filesystem. This is what you almost always want for mounting, and it is what `lsblk -f` and `blkid` show in the `UUID` column.
- **PARTUUID**: a separate identifier stored in the GPT partition table for a partition, independent of whatever filesystem is inside it. It is useful when there is no filesystem UUID to use, for example for a raw partition, and some bootloaders prefer it.
- **LABEL and PARTLABEL**: optional human-readable names for a filesystem or a partition. Handy for people, but a label is easy to duplicate by accident, so a UUID is the safer choice for automatic mounting.
One quirk to expect: FAT and vfat filesystems, such as an EFI system partition, do not have a full 128-bit UUID. They show a shorter volume serial like `1234-ABCD` instead. That is normal, and it still works in `fstab` as `UUID=1234-ABCD`.
## Why use a UUID instead of /dev/sda: the real reason
The names `/dev/sda`, `/dev/sdb` and so on (and their virtual-disk and NVMe cousins `/dev/vda` and `/dev/nvme0n1`) are handed out by the kernel in the order it discovers storage during boot. That order is not a contract. It can change when you attach a second volume, when a controller is added or reordered, when you restore from a snapshot that has an extra disk attached, or simply on a boot where devices are probed in a different sequence. The disk that is `/dev/sdb` today can come up as `/dev/sda` tomorrow, with nothing on the disk itself having changed.
The consequence is not academic. If `/etc/fstab` mounts your data volume by `/dev/sdb1` and the kernel later swaps the names around, the server can mount the wrong filesystem at your mount point, or fail the mount entirely and drop to an emergency prompt on the next reboot. Because a UUID identifies the filesystem itself rather than its slot in the boot order, mounting by UUID always gives you the filesystem you meant. This is why the `fstab(5)` manual page calls UUID (or LABEL) the recommended method, and why nearly every modern distribution and cloud image already mounts the root filesystem by UUID out of the box.
On a Noiz VPS this matters most the day you attach an additional block-storage volume for data or backups. When Noiz provisions the server, the root filesystem is already referenced by UUID in `/etc/fstab`. When you add your own volume and want it to mount automatically at boot, add it by UUID too. If you take the shortcut of writing `/dev/sdb1` instead, a later reboot may quietly mount it in the wrong place, or leave your server unable to boot cleanly until you fix the entry.
## Find the UUID
Any of the three methods below gives you the same answer. Pick whichever you find easiest to read. Running them as root (or with `sudo`) gives the most complete output.
### Method 1: lsblk -f (clearest overview)
The `lsblk` command lists block devices as a tree. The `-f` option adds filesystem details, including the UUID, and shows how partitions sit under each disk and where they are mounted. This is usually the friendliest place to start:
```
lsblk -f
```
Typical output on a server with a system disk and one attached data volume looks like this:
```
NAME FSTYPE LABEL UUID MOUNTPOINTS
sda
โโsda1 vfat 1234-ABCD /boot/efi
โโsda2 ext4 a1b2c3d4-5e6f-4789-9abc-0123456789ab /
sdb
โโsdb1 ext4 data f0e1d2c3-b4a5-4687-9182-abcdef012345 /mnt/data
```
Read down the `UUID` column to find the value for the partition you care about. In the example above, the data volume `sdb1` has UUID `f0e1d2c3-b4a5-4687-9182-abcdef012345`. If you want a tidier, custom set of columns, you can ask for exactly the fields you need:
```
lsblk -o NAME,SIZE,FSTYPE,UUID,MOUNTPOINT
```
### Method 2: blkid (device-by-device detail)
The `blkid` command reads the identifying tokens straight from each device's metadata. Run on its own it lists every block device it can see:
```
sudo blkid
```
Each line names a device and its attributes:
```
/dev/sda1: UUID="1234-ABCD" TYPE="vfat" PARTUUID="0001a2b3-01"
/dev/sda2: UUID="a1b2c3d4-5e6f-4789-9abc-0123456789ab" TYPE="ext4" PARTUUID="0001a2b3-02"
/dev/sdb1: LABEL="data" UUID="f0e1d2c3-b4a5-4687-9182-abcdef012345" TYPE="ext4" PARTUUID="9f8e7d6c-01"
```
To read just one device, name it. This is the cleanest way to grab a single value:
```
sudo blkid /dev/sdb1
```
You can also ask `blkid` for one field only, which is handy when scripting or copying the value into `fstab`:
```
sudo blkid -s UUID -o value /dev/sdb1
```
Note that `blkid` gives verified, up-to-date results only when run as root. An ordinary user may get cached or incomplete output, which is a common reason a UUID appears to be "missing".
### Method 3: ls -l /dev/disk/by-uuid (the mapping the system uses)
The system itself keeps a directory of symbolic links named after every UUID, each pointing back to the current `/dev` name. Listing it shows the live mapping and is a good sanity check:
```
ls -l /dev/disk/by-uuid/
```
The output makes the point of this whole guide visible at a glance:
```
lrwxrwxrwx 1 root root 10 Jul 21 09:14 1234-ABCD -> ../../sda1
lrwxrwxrwx 1 root root 10 Jul 21 09:14 a1b2c3d4-5e6f-4789-9abc-0123456789ab -> ../../sda2
lrwxrwxrwx 1 root root 10 Jul 21 09:14 f0e1d2c3-b4a5-4687-9182-abcdef012345 -> ../../sdb1
```
Each stable UUID on the left maps to whatever changeable `/dev` name is current on the right. Sibling directories `/dev/disk/by-partuuid`, `/dev/disk/by-label` and `/dev/disk/by-id` provide the same idea for the other persistent identifiers.
### Reading the UUID of an already-mounted filesystem
If the filesystem is already mounted and you only need its source and UUID, `findmnt` is quick:
```
findmnt -o TARGET,SOURCE,FSTYPE,UUID /mnt/data
```
## Use the UUID in /etc/fstab to mount reliably
The `/etc/fstab` file tells the system which filesystems to mount at boot and where. Each line has six fields, in this order: the device to mount, the mount point, the filesystem type, the mount options, the dump flag, and the fsck pass order. To mount by UUID, put `UUID=` followed by the value in the first field instead of a `/dev` name.
A complete line for the data volume from the examples above, mounting it at `/mnt/data`, looks like this:
```
UUID=f0e1d2c3-b4a5-4687-9182-abcdef012345 /mnt/data ext4 defaults 0 2
```
Taking the fields in turn:
- **Device**: `UUID=f0e1d2c3-b4a5-4687-9182-abcdef012345`. Replace this with your own value. Do not put quotation marks around it in `fstab`, even though `blkid` prints them.
- **Mount point**: `/mnt/data`. The directory must already exist. Create it first with `sudo mkdir -p /mnt/data`.
- **Type**: `ext4` here. Use whatever `lsblk -f` or `blkid` reported in the `FSTYPE` or `TYPE` column, for example `xfs` or `vfat`.
- **Options**: `defaults` is a sensible baseline. See the note on `nofail` below for a small change that protects your boot.
- **Dump**: `0`. This field is used by the old `dump` backup tool and is almost always left at `0`.
- **Pass**: the fsck order at boot. Use `1` only for the root filesystem, `2` for other filesystems that should be checked, and `0` to skip the check.
### Test the entry before you trust it
A mistake in `/etc/fstab` can stop the server booting, so never reboot to "see if it worked". Test it while the system is safely running instead. First, ask the system to check the file for obvious errors:
```
sudo findmnt --verify --verbose
```
Then try mounting everything in `fstab` that is not already mounted:
```
sudo mount -a
```
If `mount -a` returns with no error and your filesystem appears where you expect (confirm with `lsblk -f` or `df -h /mnt/data`), the entry is good. If it prints an error, fix the line and test again. Only once `mount -a` is clean should you consider the entry safe across reboots.
### Protect the boot with nofail on non-essential volumes
For any volume that is not required for the server to function, such as an extra data or backup disk, add the `nofail` option so a missing or unreadable disk does not block the boot:
```
UUID=f0e1d2c3-b4a5-4687-9182-abcdef012345 /mnt/data ext4 defaults,nofail 0 2
```
With `nofail`, if that volume is ever detached or fails to appear, the server still boots and simply leaves the mount point empty, rather than dropping into emergency mode. Do not use `nofail` on filesystems the system genuinely needs to run.
## Troubleshooting
- **blkid prints nothing, or an incomplete list**: you are probably running it as an unprivileged user. Run it with `sudo`. As a non-root user, `blkid` returns only cached, unverified information and may show nothing at all.
- **Two disks show the same UUID**: this happens after cloning a disk, restoring an image, or booting from a snapshot alongside its original. Duplicate UUIDs make mounting ambiguous, and the wrong filesystem can be mounted. Give one of them a fresh UUID. For ext2/3/4 use `sudo tune2fs -U random /dev/sdb1`; for XFS use `sudo xfs_admin -U generate /dev/sdb1`. Then re-read the new UUID and update `fstab` to match.
- **A FAT or EFI partition shows a short UUID like 1234-ABCD**: that is expected. FAT/vfat volumes carry a short volume serial rather than a full 128-bit UUID, and it works normally as `UUID=1234-ABCD` in `fstab`.
- **The UUID changed after you formatted the disk**: reformatting with `mkfs` creates a brand-new filesystem with a brand-new UUID, so any old `fstab` entry now points at nothing. Read the new UUID and update the entry.
- **mount -a reports "special device UUID=... does not exist"**: the UUID in `fstab` does not match any current device. Re-check it against `lsblk -f` or `blkid` for a typo, and confirm the disk is actually attached. On a VPS, verify the extra volume is attached to the server in the first place.
- **The server dropped to an emergency prompt after a reboot**: a bad `fstab` line is the usual cause. At the emergency prompt, remount the root filesystem writable with `mount -o remount,rw /`, open `/etc/fstab`, correct or comment out (with a leading `#`) the offending line, save, and reboot. Adding `nofail` to non-essential volumes prevents this class of failure in future.
If you run a managed Noiz plan, or you are attaching a new volume and would rather have it set up for you, open a support ticket with the Noiz support team. Include the server name, the output of `sudo lsblk -f`, the mount point you want, and what the volume is for. Never include private keys or passwords in a ticket.
# How to Increase PHP's post_max_size Value Using CloudLinux Selector in cPanel
Source: https://docs.noiz.ie/server-administration/how-to-increase-phps-post-max-size-value-using-cloudlinux-selector-in-cpanel/
On Noiz cPanel hosting that runs CloudLinux, the **Select PHP Version** tool (commonly called the CloudLinux PHP Selector) lets you raise `post_max_size` yourself, without editing a `php.ini` file or opening a support ticket. This guide shows you where the setting lives, what it actually controls, and why it almost always has to be changed together with `upload_max_filesize`.
`post_max_size` is the maximum size of an *entire* POST request body that PHP will accept. That is not just the file being uploaded. It covers every uploaded file in the form, every text field, every hidden field, and the multipart encoding overhead that wraps them. If you upload one 60 MB file through a form that also carries a title, a description and a security token, the request on the wire is slightly larger than 60 MB, and it is that larger figure that `post_max_size` is measured against.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the *stable* and *LTS* tier in cPanel's own wording) with the Jupiter interface, and against the current CloudLinux PHP Selector. This guide is written for Noiz hosting and is kept current against cPanel and CloudLinux. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [PHP Manual: post\_max\_size](https://www.php.net/manual/en/ini.core.php#ini.post-max-size): the authoritative definition of the directive, its shorthand notation (`8M`, `1G`) and its interaction with `memory_limit`.
- [PHP Manual: Common Pitfalls in File Uploads](https://www.php.net/manual/en/features.file-upload.common-pitfalls.php): why an oversized POST arrives as an empty `$_POST` and `$_FILES` rather than as an error.
- [PHP Manual: upload\_max\_filesize](https://www.php.net/manual/en/ini.core.php#ini.upload-max-filesize): the companion directive that caps each individual file.
- [CloudLinux OS Components: PHP Selector](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#php-selector): how the Selector stores per-version settings and where its limitations lie.
- [cPanel: MultiPHP INI Editor](https://docs.cpanel.net/cpanel/software/multiphp-ini-editor-for-cpanel/): the separate cPanel-native editor that some accounts have instead of, or alongside, the CloudLinux Selector.
## Prerequisites
- A Noiz cPanel hosting account and its login details.
- A note of the current `post_max_size` and `upload_max_filesize` values before you change anything, so you can put them back.
- The largest single upload you actually need to support, and a rough idea of how many files a single form submission may carry.
## Change post\_max\_size
### 1. Open Select PHP Version
Log in to your cPanel account, scroll to the **Software** section, and click **Select PHP Version**. If you cannot see it, type `PHP` into the search box at the top of the cPanel home page.

### 2. Open the Options tab
Click **Options**. This tab lists the PHP directives you are allowed to change for the version currently selected on your account.

**Note:** if the **Options** tab shows an error mentioning the native PHP version, switch to a numbered (alt-php) version first. The **native** build is managed by the server, so the Selector cannot edit its directives. See [How to Change the PHP Version via CloudLinux Selector in cPanel](/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/).
### 3. Set post\_max\_size
Find **post\_max\_size** in the list, open the drop-down beside it, and choose the value you need. The change saves as soon as you select it and applies to new PHP requests immediately. There is no restart to perform and no confirmation button to press.

### 4. Set upload\_max\_filesize in the same visit
While you are on the **Options** tab, check **upload\_max\_filesize** too. Changing only one of the pair is the single most common reason this procedure appears not to work. The next section explains how the two relate.
### 5. Confirm it took effect
Reload the page you were troubleshooting and retry the upload. If your application has a system information screen, read the value there rather than trusting the drop-down: WordPress shows it under **Tools** then **Site Health** then **Info** then **Server**, and most other platforms have an equivalent panel. That reading reports what PHP is genuinely enforcing.
## How post\_max\_size and upload\_max\_filesize Work Together
These two directives are not alternatives, and they do not do the same job. Getting the relationship right is most of the work.
- **`upload_max_filesize` caps each individual file.** One file larger than this figure is rejected, even if the request as a whole is small.
- **`post_max_size` caps the whole request.** Every file plus every form field plus the encoding overhead, added together.
- **The effective ceiling for a single-file upload is the lower of the two.** Setting `upload_max_filesize` to `256M` while `post_max_size` stays at `8M` gives you an 8 MB limit, not a 256 MB one. This is exactly why raising one alone changes nothing.
- **Always keep `post_max_size` comfortably larger than `upload_max_filesize`.** A useful rule of thumb is a few megabytes of headroom, or roughly a quarter more for forms that carry a lot of text. For a 64 MB file limit, `post_max_size` of `96M` or `128M` is a sensible pairing.
- **Multiple files in one submission are added together.** A gallery uploader sending six 20 MB images in a single request needs `post_max_size` above 120 MB, even though no single file comes near `upload_max_filesize`. Uploaders that send each file as its own separate request, as the WordPress media library does by default, do not have this problem.
- **The figure your application advertises is derived, not configured.** When a CMS displays a maximum upload size, it is normally reporting the lower of these two directives back to you. If that displayed number will not move, you have changed one of the pair and not the other.
## What Happens When a Request Exceeds post\_max\_size
This behaviour is the reason `post_max_size` problems are so much harder to diagnose than `upload_max_filesize` problems, and it is worth understanding before you start guessing at values.
When a request body is larger than `post_max_size`, PHP discards the *entire* body. `$_POST` and `$_FILES` both arrive empty. Your application is not told that a file was too large, because from its point of view nothing was submitted at all. Nothing is shown in the browser and no upload error code is set, so the only trace is usually a line in the PHP error log noting that the POST content length exceeded the limit. That log entry is the quickest way to confirm you are looking at this failure rather than another one.
The practical symptoms are distinctive once you know them:
- The form appears to submit, then simply reloads itself blank, with no message and no saved record.
- The file "vanishes" with no upload error shown anywhere.
- An AJAX uploader shows a generic HTTP error, or hangs at 100 per cent and never completes.
- Small files work perfectly and only large ones fail silently.
Contrast that with an over-large *single file* under `upload_max_filesize`: the request still arrives, `$_FILES` is populated, and the entry carries error code `1` (`UPLOAD_ERR_INI_SIZE`), which is why applications can show a tidy "file exceeds the maximum upload size" message in that case. **A clear error message points at `upload_max_filesize`. Silence points at `post_max_size`.**
## Choosing a Sensible Value
- **Start from the largest file you genuinely need to accept**, then add headroom for the rest of the form. Do not start from the largest figure the drop-down offers.
- **Raise in steps.** Move up one or two increments, retest with a real file, and stop when it works. Jumping to the maximum removes the diagnostic signal you were using.
- **Bigger is not free.** A very high limit lets a single request tie up a PHP worker, disk space in the temporary upload directory and account bandwidth for a long time. On a site with a public upload form it also widens the surface for abuse, so cap it at what your workload actually needs.
- **Do not choose `0` if the option appears.** Zero means no limit at all, which removes a genuinely useful safety valve.
- **Very large files are usually the wrong tool for a web form.** Multi-gigabyte transfers belong in FTP, SFTP or the cPanel File Manager rather than a browser upload, which has to survive the whole transfer inside one HTTP request.
## Things That Catch People Out
- **The value is stored per PHP version.** Each version keeps its own set of Options values. If you later change your PHP version, the new version starts on its own defaults and your tuned `post_max_size` does not follow it across. Re-check the Options tab immediately after any version change.
- **The setting is account-wide, not per-domain.** The CloudLinux Selector applies one configuration to the whole cPanel account, so every domain, subdomain and add-on domain in it shares the value. Sites needing genuinely different limits belong in separate cPanel accounts.
- **`memory_limit` can undercut it.** Historically PHP expected `memory_limit` to be larger than `post_max_size`, which in turn is larger than `upload_max_filesize`. Modern PHP streams uploads to a temporary file rather than holding them in memory, so a large upload no longer requires a matching memory allowance by itself. What does still consume memory is whatever your application does with the file afterwards, such as resizing an image or parsing a spreadsheet. If large uploads arrive intact and then fail during processing, the constraint is memory, not this directive. See [How to Increase or Decrease PHP Memory Limit via CloudLinux Selector in cPanel](/server-administration/how-to-increase-or-decrease-php-memory-limit-via-cloudlinux-selector-in-cpanel/).
- **Time limits bite before size limits on slow connections.** A 200 MB upload over a modest domestic uplink can take several minutes. If `max_execution_time` or `max_input_time` expires first, the upload fails regardless of how generous `post_max_size` is. Both appear on the same **Options** tab.
- **Some applications impose their own cap on top.** Content management systems, form plugins and file manager plugins frequently carry a separate maximum of their own, set in their admin screens or in a configuration file. If PHP now allows 128 MB and the application still refuses at 32 MB, the remaining limit is in the application.
- **A custom `php.ini` or `.htaccess` entry may be doing nothing.** Under the PHP handlers used with the CloudLinux Selector, `php_value post_max_size` lines in `.htaccess` are typically ignored, and a stray `php.ini` in your web root may be ignored or may conflict with the Selector. Set the value in one place, in the Selector, and remove the leftovers.
- **`max_file_uploads` is a separate ceiling.** It limits how many files one request may contain, commonly 20. A bulk upload of 50 small files can fail on the count while sitting far below every size limit.
- **Command-line and cron runs are separate.** A script run through cron or PHP CLI does not necessarily inherit the same values as a web request. If a scheduled import behaves differently from the same task in the browser, that difference is the first thing to check.
- **The drop-down offers fixed choices, not free text.** If the exact figure you want is not listed, pick the next value up. If the option is greyed out or missing entirely, the value is locked at plan level, and only Noiz support can change it.
## Troubleshooting
- **Symptom: the upload form submits and returns to a blank or empty page, with nothing saved and no error.** This is the classic `post_max_size` failure. The whole POST body was discarded. Raise `post_max_size` above the total size of the request, not just the file.
- **Symptom: a clear "file is too large" message naming a size.** That is `upload_max_filesize` rejecting the individual file, and the message usually names the current limit. Raise that directive, then confirm `post_max_size` is still comfortably above it. See [How to Increase PHP's upload\_max\_filesize Value Using CloudLinux Selector in cPanel](/server-administration/how-to-increase-phps-upload-max-filesize-value-using-cloudlinux-selector-in-cpan/).
- **Symptom: the advertised maximum upload size in the application will not change.** You have raised one of the pair and not the other. The displayed figure is the lower of `post_max_size` and `upload_max_filesize`.
- **Symptom: the change saved but the site still reports the old value.** Confirm the account is on the PHP version you edited, not a different one, and clear any full-page or object cache in the application before re-reading the figure.
- **Symptom: the Options tab is empty or shows an error.** The account is on the **native** PHP build. Switch to a numbered version first, then return to Options.
- **Symptom: the upload runs for a while, then times out or drops near the end.** That is a time limit or a connection problem rather than a size limit. Check `max_execution_time` and `max_input_time`, and test the same file over a faster connection before raising sizes further.
- **Symptom: the file uploads, then the page errors or dies during processing.** The upload succeeded and the application ran out of memory or time handling it. Raise `memory_limit` rather than `post_max_size`.
## Related Guides
- [How to Increase PHP's upload\_max\_filesize Value Using CloudLinux Selector in cPanel](/server-administration/how-to-increase-phps-upload-max-filesize-value-using-cloudlinux-selector-in-cpan/)
- [How to Increase or Decrease PHP Memory Limit via CloudLinux Selector in cPanel](/server-administration/how-to-increase-or-decrease-php-memory-limit-via-cloudlinux-selector-in-cpanel/)
- [How to Change the PHP Version via CloudLinux Selector in cPanel](/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/)
If large uploads still fail after raising both directives, open a ticket with Noiz support. Include your domain name, the values you set, the size of the file you are uploading and the exact behaviour you see, including whether an error message appears at all. On managed plans, Noiz will identify which limit is actually being reached and tune it for you.
# How to Increase PHP's upload_max_filesize Value Using CloudLinux Selector in cPanel
Source: https://docs.noiz.ie/server-administration/how-to-increase-phps-upload-max-filesize-value-using-cloudlinux-selector-in-cpan/
On Noiz cPanel hosting that runs CloudLinux, the **Select PHP Version** tool (commonly called the CloudLinux PHP Selector) lets you raise `upload_max_filesize` yourself, without editing a `php.ini` file or opening a support ticket. This guide shows you where the setting lives, what it genuinely controls, and the companion setting that silently caps it if you leave it behind.
`upload_max_filesize` is the largest size a *single* uploaded file may be in one HTTP request. It is not your disk quota, it is not a monthly transfer allowance, and it is not the total size of the request. If a visitor or an editor tries to upload a file bigger than this figure, PHP discards it before your application ever sees it, which is why the failure so often shows up as a vague browser error rather than a useful message.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the *stable* and *LTS* tier in cPanel's own wording) with the Jupiter interface, and against the current CloudLinux PHP Selector. This guide is written for Noiz hosting and is kept current against cPanel and CloudLinux. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [PHP Manual: upload\_max\_filesize](https://www.php.net/manual/en/ini.core.php#ini.upload-max-filesize): the authoritative definition of the directive and its shorthand notation (`64M`, `1G`).
- [PHP Manual: POST method uploads](https://www.php.net/manual/en/features.file-upload.post-method.php): how PHP receives, buffers and hands over an uploaded file, and which directives take part.
- [PHP Manual: Common file upload pitfalls](https://www.php.net/manual/en/features.file-upload.common-pitfalls.php): the interaction between `upload_max_filesize`, `post_max_size` and the execution time limits.
- [CloudLinux OS Components: PHP Selector](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#php-selector): how the Selector stores per-version settings and where its limitations lie.
- [cPanel: MultiPHP INI Editor](https://docs.cpanel.net/cpanel/software/multiphp-ini-editor-for-cpanel/): the separate cPanel-native editor that some accounts have instead of, or alongside, the CloudLinux Selector.
## Prerequisites
- A Noiz cPanel hosting account and its login details.
- The actual size of the largest file you need to accept. Check it on your own machine first, because "about 50 MB" is usually 60-something.
- A note of the current `upload_max_filesize` and `post_max_size` values before you change them, so you can put them back.
## Raise upload\_max\_filesize
### 1. Open Select PHP Version
Log in to your cPanel account, scroll to the **Software** section, and click **Select PHP Version**. If you cannot see it, type `PHP` into the search box at the top of the cPanel home page.

### 2. Open the Options tab
Click **Options**. This tab lists the PHP directives you are allowed to change for the version currently selected on your account.

**Note:** if the **Options** tab shows an error mentioning the native PHP version, switch to a numbered (alt-php) version first. The **native** build is managed by the server, so the Selector cannot edit its directives. See [How to Change the PHP Version Using the CloudLinux Selector in cPanel](/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/).
### 3. Set upload\_max\_filesize
Find **upload\_max\_filesize** in the list and open the drop-down beside it, then choose the value you need. The change saves as soon as you select it and applies to new PHP requests immediately. There is no restart to perform and no confirmation button to press.

### 4. Raise post\_max\_size in the same visit
This is the step that gets skipped, and it is the reason most people conclude the setting "did not work". Stay on the **Options** tab, find **post\_max\_size**, and set it at least as high as the figure you just chose. The detail is explained in full below.
### 5. Confirm it took effect
Reload the page you were troubleshooting. In WordPress, **Media** then **Add New** prints the effective ceiling directly on the screen as *Maximum upload file size*, and **Tools** then **Site Health** then **Info** then **Server** shows both *Upload max filesize* and *Max size of post data allowed*. Most other platforms have an equivalent system information panel. That reading is the one that matters, because it reports what PHP is genuinely enforcing rather than what the drop-down displays.
## upload\_max\_filesize and post\_max\_size Move Together
These two directives are not alternatives and they are not independent. They describe different things, and **the lower of the two wins**.
- `upload_max_filesize` limits *one file*.
- `post_max_size` limits the *entire POST request*: every file in it, plus the form fields, plus the multipart encoding overhead.
Setting `upload_max_filesize` to `256M` while `post_max_size` stays at `64M` gives you a 64 MB ceiling. The browser will still start the upload, the server will still accept the connection, and the request will still fail, which is precisely why the symptom is so confusing. Set `post_max_size` **higher** than `upload_max_filesize`, not merely equal to it: a comfortable margin, say `upload_max_filesize` of `128M` with `post_max_size` at `160M`, leaves room for the form fields travelling alongside the file and for the encoding overhead, which typically adds a few per cent.
If a form accepts several files at once, `post_max_size` has to cover their combined size, not just the biggest one. A gallery uploader taking ten 20 MB images needs a `post_max_size` above 200 MB even though no single file comes close to it.
The full walkthrough for the companion setting is in [How to Increase PHP's post\_max\_size Value Using CloudLinux's Selector in cPanel](/server-administration/how-to-increase-phps-post-max-size-value-using-cloudlinux-selector-in-cpanel/).
## The Other Limits in the Chain
An upload has to survive several separate ceilings. Raising the one you have heard of does nothing if a different one is the actual constraint.
- **`memory_limit`** matters when your application does something with the file after it arrives, such as resizing an image or parsing a spreadsheet. The upload itself is written to a temporary file on disk rather than held in memory, so a large upload does not automatically need matching memory, but the processing step frequently does. See [How to Increase or Decrease PHP Memory Limit via CloudLinux Selector in cPanel](/server-administration/how-to-increase-or-decrease-php-memory-limit-via-cloudlinux-selector-in-cpanel/).
- **`max_file_uploads`** caps how many files a single request may carry, commonly at 20. Select forty images in one go and the excess is dropped silently, with no error to explain the missing files.
- **`max_execution_time` and `max_input_time`** decide how long the request may take. A 500 MB file over a slow domestic upstream connection can exceed a time limit long before it exceeds a size limit, which produces a timeout rather than a size complaint.
- **The web server in front of PHP** enforces its own request body limit. On shared hosting this is usually set generously and is not the thing stopping you, but if you have raised every PHP directive and still get a `413 Request Entity Too Large`, that is the layer to ask Noiz support about.
- **Your disk quota** stops an upload just as effectively as any directive. The file has to fit twice for a moment: once in the temporary location and once at its destination. An account close to its quota fails uploads with errors that look nothing like a quota problem.
- **Your application's own limit** sits on top of all of this. WordPress Multisite has a network-level *Max upload file size* in megabytes that overrides the PHP figure downwards, and many forms, plugins and themes impose their own cap.
## Choosing a Sensible Value
- **Size it to the job, not to the maximum available.** Photographs and documents rarely need more than `64M`. Video, design source files, database dumps and full-site backup archives are the usual reasons to go higher.
- **A high limit is a security and stability consideration on public forms.** Any upload field open to unauthenticated visitors becomes a way to fill your disk. Raise the PHP limit for your editors by all means, then keep the public-facing form restricted at application level.
- **Large uploads through a browser fail more often than they succeed.** Beyond a few hundred megabytes, a dropped connection near the end means starting from zero. Use FTP or the cPanel **File Manager** for one-off transfers of big archives, and reserve the HTTP upload path for the sizes it handles reliably.
- **The drop-down offers fixed choices, not free text.** If the exact figure you want is not listed, pick the next value up. If the option is greyed out or missing, the value is locked at plan level and only Noiz support can change it.
## Things That Catch People Out
- **The value is stored per PHP version.** Each version keeps its own set of Options values. If you later change your PHP version, the new version starts on its own defaults and your tuned figures do not follow it across. Re-check the Options tab immediately after any version change.
- **The setting is account-wide, not per-domain.** The CloudLinux Selector applies one configuration to the whole cPanel account, so every domain, subdomain and add-on domain in it shares the value. Sites needing genuinely different limits belong in separate cPanel accounts.
- **A custom `php.ini` or `.htaccess` entry may be doing nothing.** Under the PHP handlers used with the CloudLinux Selector, `php_value upload_max_filesize` lines in `.htaccess` are typically ignored, and a stray `php.ini` in your web root may be ignored or may conflict with the Selector. Set the value in one place, in the Selector, and remove the leftovers.
- **Units are required and are not decimal-friendly.** PHP reads `64M` as 64 megabytes; a bare number is interpreted as bytes, and fractional values such as `1.5G` are not reliably parsed. The Selector's drop-down keeps you out of this trap, which is a good reason to use it rather than hand-editing a file.
- **Browsers report the failure badly.** Exceeding the limit usually surfaces as a stalled progress bar, a generic "HTTP error" in the WordPress media library, or a page that simply reloads empty. Do not read those as a broken site before you have checked the numbers.
## Troubleshooting
- **Symptom: `The uploaded file exceeds the upload_max_filesize directive in php.ini`.** The clean case, and the one this guide fixes. Raise the drop-down, then raise `post_max_size` above it.
- **Symptom: you raised `upload_max_filesize` but the reported maximum did not move.** `post_max_size` is lower and is now the binding limit. Raise it too.
- **Symptom: the upload fails with an empty `$_POST` and `$_FILES`, or the form submits as though no data was sent.** The request exceeded `post_max_size`, so PHP discarded the whole body including the ordinary form fields. This is why an over-sized upload can look like a broken form rather than a rejected file.
- **Symptom: `413 Request Entity Too Large`.** The request was stopped by the web server before PHP was involved. PHP settings will not change this. Contact Noiz support with the domain and the file size you are attempting.
- **Symptom: the upload runs for a while, then stops with a timeout or a 5xx error.** A time limit rather than a size limit. Check `max_execution_time` and `max_input_time`, and consider FTP for files of this size.
- **Symptom: several files were selected but only some arrived, with no error.** You hit `max_file_uploads`. Upload in smaller batches or raise that directive.
- **Symptom: the change saved but the site still reports the old value.** Confirm the account is on the PHP version you actually edited, not a different one, and clear any full-page or object cache in the application before re-reading the figure.
- **Symptom: the Options tab is empty or shows an error.** The account is on the **native** PHP build. Switch to a numbered version first, then return to Options.
## Related Guides
- [How to Increase PHP's post\_max\_size Value Using CloudLinux's Selector in cPanel](/server-administration/how-to-increase-phps-post-max-size-value-using-cloudlinux-selector-in-cpanel/)
- [How to Increase or Decrease PHP Memory Limit via CloudLinux Selector in cPanel](/server-administration/how-to-increase-or-decrease-php-memory-limit-via-cloudlinux-selector-in-cpanel/)
- [How to Change the PHP Version Using the CloudLinux Selector in cPanel](/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/)
If uploads still fail after raising both values, open a ticket with Noiz support. Include your domain name, the two figures you set, the size and type of the file, and the exact error text or the URL that fails. On managed plans, Noiz will identify which limit in the chain is actually being reached and either tune it or advise on the plan that fits your workload.
# How to Increase or Decrease PHP Memory Limit via CloudLinux Selector in cPanel
Source: https://docs.noiz.ie/server-administration/how-to-increase-or-decrease-php-memory-limit-via-cloudlinux-selector-in-cpanel/
On Noiz cPanel hosting that runs CloudLinux, the **Select PHP Version** tool (commonly called the CloudLinux PHP Selector) lets you raise or lower `memory_limit` yourself, without editing a `php.ini` file or opening a support ticket. This guide shows you where the setting lives, what the value actually controls, and the ceiling that quietly caps whatever you choose.
`memory_limit` is the maximum amount of memory a *single* PHP script may allocate while it runs. It is not your account's total memory allowance, and it is not the amount of memory your site will use. It is a safety valve: when one script tries to exceed the figure, PHP kills that script with a fatal `Allowed memory size ... exhausted` error rather than letting it consume the server.
**Last reviewed:** 27 July 2026, against cPanel & WHM **version 134** (the *stable* and *LTS* tier in cPanel's own wording) with the Jupiter interface, and against the current CloudLinux PHP Selector. This guide is written for Noiz hosting and is kept current against cPanel and CloudLinux. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [PHP Manual: memory\_limit](https://www.php.net/manual/en/ini.core.php#ini.memory-limit): the authoritative definition of the directive, its accepted shorthand notation (`128M`, `1G`) and its default.
- [CloudLinux OS Components: PHP Selector](https://docs.cloudlinux.com/cloudlinuxos/cloudlinux_os_components/#php-selector): how the Selector stores per-version settings and where its limitations lie.
- [CloudLinux OS: Limits](https://docs.cloudlinux.com/cloudlinuxos/limits/): how per-account physical memory (PMEM) and virtual memory limits work, and why they override anything set in PHP.
- [cPanel: MultiPHP INI Editor](https://docs.cpanel.net/cpanel/software/multiphp-ini-editor-for-cpanel/): the separate cPanel-native editor that some accounts have instead of, or alongside, the CloudLinux Selector.
## Prerequisites
- A Noiz cPanel hosting account and its login details.
- A note of the current value before you change it, so you can put it back.
- The figure your application actually asks for. Most CMS documentation states a minimum; use that as your starting point rather than guessing.
## Change the PHP Memory Limit
### 1. Open Select PHP Version
Log in to your cPanel account, scroll to the **Software** section, and click **Select PHP Version**. If you cannot see it, type `PHP` into the search box at the top of the cPanel home page.

### 2. Open the Options tab
Click **Options**. This tab lists the PHP directives you are allowed to change for the version currently selected on your account.

**Note:** if the **Options** tab shows an error mentioning the native PHP version, switch to a numbered (alt-php) version first. The **native** build is managed by the server, so the Selector cannot edit its directives. See [How to Change the PHP Version via CloudLinux Selector in cPanel](/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/).
### 3. Set memory\_limit
Find **memory\_limit** in the list and open the drop-down beside it, then choose the value you need. The change saves as soon as you select it, and applies to new PHP requests immediately. There is no restart to perform and no confirmation button to press.

### 4. Confirm it took effect
Reload the page you were troubleshooting. If your application has a system information screen, check the value there: WordPress shows it under **Tools** then **Site Health** then **Info** then **Server**, and most other CMS platforms have an equivalent panel. That reading is the one that matters, because it reports what PHP is genuinely enforcing rather than what the drop-down displays.
## The Ceiling You Cannot Raise From Here
This is the single most important thing to understand about the setting, and it is the reason most follow-up tickets get opened.
Your hosting plan carries a hard per-account memory ceiling enforced by CloudLinux at the operating system level. The Selector's drop-down does not know about that ceiling and will happily offer you figures above it. **The lower of the two values wins.** Selecting `2048M` on a plan whose ceiling sits well below that does not give your scripts 2 GB. It simply means PHP stops policing the script itself, and the account limit stops it instead, usually with a harder-to-read failure than a clean PHP error.
- **Symptoms of hitting the account ceiling rather than `memory_limit`** tend to be a **508 Resource Limit Is Reached** page, a blank white screen, an abruptly terminated request, or a process that dies with no useful message in the PHP error log.
- **Raising the drop-down further will not fix those.** Once the PHP figure is already at or above the account ceiling, the remaining fix is either to reduce what the application is trying to do in one request, or to move to a plan with more memory. Open a ticket with Noiz support and ask for your account's current memory ceiling and utilisation before you spend an afternoon tuning a value that is not the constraint.
- **If your account has a resource usage page** in cPanel, it will show you when the ceiling was last reached and how often. That history is far more useful than a single failed page load.
## Choosing a Sensible Value
- **Start from the application's stated requirement.** Many PHP applications run comfortably in `128M` or `256M`. Image processing, PDF generation, large imports and exports, and heavyweight page builders are the usual reasons to need more.
- **Raise in steps, not to the maximum.** Move from `128M` to `256M`, retest, then to `512M` if the error persists. Jumping straight to the largest available figure removes the diagnostic signal you were using.
- **A very high limit hides bugs rather than fixing them.** A well-behaved page should not need hundreds of megabytes. If yours does, the usual causes are a plugin loading an entire database table into an array, an unbounded loop, or an import script processing every row at once instead of in batches. Fixing that is cheaper than paying for memory to absorb it.
- **Do not set it to `-1`, even if the option appears.** That removes the limit entirely, so a single runaway script will consume the whole account allowance and take every other site in the account down with it.
- **Lowering it is a legitimate move too.** A deliberately modest limit makes a memory leak fail fast and visibly, on one page, instead of intermittently starving the whole account.
## Things That Catch People Out
- **The value is stored per PHP version.** Each version keeps its own set of Options values. If you later change your PHP version, the new version starts on its own defaults and your tuned `memory_limit` does not follow it across. Re-check the Options tab immediately after any version change.
- **The setting is account-wide, not per-domain.** The CloudLinux Selector applies one configuration to the whole cPanel account, so every domain, subdomain and add-on domain in it shares the value. Sites needing genuinely different limits belong in separate cPanel accounts.
- **Your application can override it downwards.** WordPress in particular sets its own figures through `WP_MEMORY_LIMIT` and `WP_MAX_MEMORY_LIMIT` in `wp-config.php`. If the server allows 512M but `wp-config.php` asks for 128M, your admin pages get 128M. Check that file before assuming the Selector change did not work.
- **A custom `php.ini` or `.htaccess` entry may be doing nothing.** Under the PHP handlers used with the CloudLinux Selector, `php_value memory_limit` lines in `.htaccess` are typically ignored, and a stray `php.ini` in your web root may be ignored or may conflict with the Selector. Set the value in one place, in the Selector, and remove the leftovers.
- **Command-line and cron runs are separate.** A script run through cron or PHP CLI does not necessarily inherit the same `memory_limit` as a web request. If a scheduled import fails while the same task succeeds in the browser, that difference is the first thing to check.
- **The drop-down offers fixed choices, not free text.** If the exact figure you want is not listed, pick the next value up. If the option is greyed out or missing entirely, the value is locked at plan level, and only Noiz support can change it.
## Troubleshooting
- **Symptom: `Fatal error: Allowed memory size of X bytes exhausted`.** This is the clean case, and the one this guide fixes. The number in the message tells you the limit PHP is currently enforcing. If it does not match the drop-down, something is overriding it: check `wp-config.php`, then any custom `php.ini`, then confirm which PHP version the site is actually running.
- **Symptom: a 508 error, or the page simply dies with nothing in the PHP error log.** You are hitting the account memory ceiling rather than `memory_limit`. Raising the drop-down will not help. Contact Noiz support for your account's ceiling and recent usage.
- **Symptom: the change saved but the site still reports the old value.** Confirm the account is on the PHP version you edited, not a different one, and clear any full-page or object cache in the application before re-reading the figure.
- **Symptom: the Options tab is empty or shows an error.** The account is on the **native** PHP build. Switch to a numbered version first, then return to Options.
- **Symptom: only one particular page or import fails, everything else is fine.** That is a workload problem rather than a configuration problem. Split the import into smaller batches, or reduce the number of records processed per request, before raising memory again.
## Related Guides
- [How to Change the PHP Version via CloudLinux Selector in cPanel](/server-administration/how-to-change-the-php-version-using-the-cloudlinux-selector-in-cpanel/)
- [How to Enable or Disable PHP's display\_errors via CloudLinux Selector in cPanel](/server-administration/how-to-enable-or-disable-phps-display-errors-via-cloudlinux-selector-in-cpanel/)
If raising the limit does not clear the error, or you are not sure whether you are hitting PHP's limit or your plan's ceiling, open a ticket with Noiz support. Include your domain name, the value you set, and the exact error text or the URL that fails. On managed plans, Noiz will identify which limit is actually being reached and either tune it or advise on the plan that fits your workload.
# How to Install FileZilla on Windows
Source: https://docs.noiz.ie/server-administration/how-to-install-filezilla-on-windows/
FileZilla Client is a free, open source file transfer program for Windows that speaks FTP, FTPS (FTP over TLS) and SFTP (SSH file transfer). It is the tool most Noiz customers use to upload a website, pull a backup down to their PC or fix a single file without going through a control panel file manager. This guide walks you through installing it cleanly on Windows, including the bundled software offers that appear inside the installer and how to refuse them.
**Last reviewed:** 27 July 2026, against FileZilla Client **3.70.6** (latest stable). This guide is written for Noiz hosting and is kept current against FileZilla. It complements, and does not replace, the official FileZilla documentation linked below.
The screenshots in this article were captured on an earlier 3.x release. The installer wording and button positions are effectively unchanged in the current version, so the flow you see on screen will match.
### Official Documentation Reference
- [FileZilla Client download page](https://filezilla-project.org/download.php?type=client) (the only download source you should use)
- [FileZilla wiki: Client Installation](https://wiki.filezilla-project.org/Client_Installation)
- [FileZilla wiki: Documentation index](https://wiki.filezilla-project.org/Documentation)
- [FileZilla changelog](https://filezilla-project.org/changelog.php) (check what changed before upgrading)
## Prerequisites
- A Windows PC you can install software on. Standard user accounts will trigger a prompt for administrator credentials.
- Windows 10 or Windows 11 for the current release. Older Windows versions need an older FileZilla build, covered under Troubleshooting.
- Your Noiz FTP details (host, username, password, port). You do not need them to install FileZilla, only to connect afterwards.
## Step 1: Download the Installer
1. Go to the [official FileZilla Client download page](https://filezilla-project.org/download.php?type=client).
2. Choose the **Windows (64bit x86)** package unless you are on a genuinely 32-bit machine.
3. Pick the plain **FileZilla** download, not FileZilla Pro. The free client does everything you need for Noiz hosting; Pro is a paid product that adds cloud storage protocols such as S3 and Google Drive.
**Download from the project site only.** FileZilla is one of the most heavily repackaged applications on the internet, and third-party download portals routinely wrap it in adware installers. If a search result is not on `filezilla-project.org`, close it.
## Step 2: Run the Setup File
1. Double click the downloaded setup file, which is named along the lines of `FileZilla_3.70.6_win64-setup.exe`. 
2. Windows may show a **User Account Control** prompt, or a SmartScreen warning if the file is newly released. Read it, confirm the file is the one you just downloaded from the project site, then allow it to run.
## Step 3: Accept the Licence
FileZilla is released under the GNU General Public Licence. The first setup screen shows the licence text. Read it and click **I Agree** to continue.

## Step 4: Refuse the Bundled Offers
This is the step that catches people out, so slow down here. The official installer is funded partly by sponsored offers, and it presents one or more screens advertising unrelated software (browser add-ons, system utilities, download managers). Those screens are deliberately styled to look like part of the FileZilla setup.
How to spot and refuse them:
- An offer screen names a product that is **not** FileZilla. If the title bar or heading mentions anything else, it is an advert.
- Offer screens usually carry **Decline** and **Accept** buttons rather than the standard **Back** and **Next** pair. Click **Decline**, **Skip** or **Nope**. Declining does not cancel the FileZilla installation.
- Never click through setup on autopilot. Read each screen before clicking.
- Watch for pre-ticked boxes offering to change your browser home page or default search engine, and untick them.
The number and content of these screens changes over time, so what you see may not match any screenshot exactly. The rule stays the same: if it is not FileZilla, decline it.
## Step 5: Choose the Install Options
1. **Install for all users** or **only for me**: choose all users on a shared machine, or only for you if you do not have administrator rights.
2. **Components**: the defaults are correct. The icon sets and language files are optional extras you can safely leave selected or clear.
3. **Destination folder** and **Start Menu folder**: accept the defaults unless you have a reason not to.
4. Click **Install**.
## Step 6: Finish the Installation
Installation normally takes a few seconds, though a slower machine or an active antivirus scanner can stretch that out. When the completion screen appears, leave **Start FileZilla now** ticked and click **Finish**.

FileZilla opens with a welcome dialog listing links to the project forums and documentation. Close it with **OK**. The main window is split into a local file pane on the left, a remote file pane on the right, a message log across the top and a transfer queue along the bottom.

To confirm which version you installed, open **Help** then **About FileZilla**.
## Before You Connect: Two Settings Worth Knowing
- **Password storage.** The first time you save a connection, FileZilla asks how to handle passwords. Choosing **Save passwords protected by a master password** encrypts your stored hosting credentials so they are not sitting in a plain text file on your PC. On a shared or laptop machine, take that option. If you forget the master password there is no recovery, so record it in your password manager.
- **Updates.** FileZilla checks for new versions on its own and prompts you to install them. Keep this on. FTP clients handle credentials and network connections, so running an outdated build is a genuine risk rather than a cosmetic one.
## Next Step: Connect to Your Hosting
With FileZilla installed, the next job is adding your Noiz account to the Site Manager and connecting. That is covered in [How to Access or Connect to the FTP via FileZilla](/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/).
Use an encrypted connection wherever possible. Plain FTP sends your username and password across the network unencrypted, so prefer FTPS (explicit FTP over TLS) or SFTP on your Noiz hosting account.
## Troubleshooting
**Symptom: Windows says "Windows protected your PC" and refuses to run the installer.** This is SmartScreen reacting to a file it has not seen often yet, which is normal for a freshly published release. Click **More info**, check the publisher, then **Run anyway**. Only do this for a file you downloaded yourself from `filezilla-project.org`.
**Symptom: your antivirus flags the installer.** Detections on FileZilla installers almost always relate to the bundled offer component, not to FileZilla itself. Re-download from the project site, and if the warning persists, use your antivirus vendor's submission form to check the file rather than disabling protection.
**Symptom: setup asks for an administrator password you do not have.** Re-run the installer and select the option to install for the current user only, which writes into your own profile instead of Program Files.
**Symptom: the current version will not install on an older Windows PC.** Recent FileZilla releases drop support for end of life Windows versions. Older builds are published on the project's download servers, but an unsupported operating system is itself the bigger problem. Where you can, move the transfer work onto a supported machine.
**Symptom: FileZilla installed but there is no desktop shortcut.** Search the Start menu for `FileZilla`, right click the result and choose **Pin to Start** or **Open file location** to create a shortcut yourself.
**Symptom: FileZilla opens but nothing connects.** That is a connection issue rather than an installation issue. Check your host, username, port and encryption settings against the details on your Noiz account, and see the connection guide linked above.
## Getting Help
If FileZilla installs but will not reach your hosting account, open a ticket from the Noiz client area with the exact text from the FileZilla message log. The log lines tell Noiz support straight away whether the problem is credentials, encryption settings, a firewall on your side or something on the server, which usually saves a round of back and forth.
# How to Install FileZilla on macOS
Source: https://docs.noiz.ie/server-administration/how-to-install-filezilla-on-macos/
FileZilla Client is a free, open source file transfer program that speaks FTP, FTPS (FTP over TLS) and SFTP (SSH file transfer). It is the tool most Noiz customers reach for when they need to upload a site, pull a backup down, or fix one file without going through a control panel file manager.
Installing it on a Mac is not the same job as installing it on Windows, and the differences are where people get stuck. There is no setup wizard on macOS. What you download is an application archive, not an installer, so the steps that matter are moving the app to the right place and getting past the Gatekeeper warning on first launch without doing something reckless to your Mac's security settings. This guide covers those macOS specifics and the decisions you have to make along the way.
**Last reviewed:** 27 July 2026, against the current FileZilla release. This guide is written for Noiz hosting and is kept current against FileZilla. It complements, and does not replace, the official FileZilla documentation linked below.
### Official Documentation Reference
- [FileZilla Client download page](https://filezilla-project.org/download.php?type=client) (the only download source you should use)
- [FileZilla wiki: Client Installation](https://wiki.filezilla-project.org/Client_Installation)
- [FileZilla wiki: Documentation index](https://wiki.filezilla-project.org/Documentation)
- [FileZilla changelog](https://filezilla-project.org/changelog.php) (check what changed before upgrading)
- [Apple: Safely open apps on your Mac](https://support.apple.com/en-za/102445) (what Gatekeeper is doing and why)
- [Apple: Open a Mac app from an unknown developer](https://support.apple.com/en-za/guide/mac-help/mh40616/mac) (the current click path for the override)
- [Apple: Using Intel-based apps on a Mac with Apple silicon](https://support.apple.com/en-za/102527) (Rosetta 2)
## Prerequisites
- A Mac running a currently supported version of macOS.
- Your macOS account password. You need it to move an app into the system Applications folder and to approve the first launch.
- Administrator rights on the Mac. Without them you can still install FileZilla, into your own home folder instead, as described below.
- Your Noiz FTP details (host, username, password, port), which are in your welcome email and in the Noiz client area. You do not need them to install FileZilla, only to connect afterwards.
## Step 1: Download From the Project Site, Not From a Search Result
Go to the [official FileZilla Client download page](https://filezilla-project.org/download.php?type=client) and take the button labelled **Download FileZilla Client**.
Four things on this page trip Mac users up:
- **The sponsored adverts look like download buttons.** The page carries large advert blocks styled to resemble the real thing. The genuine button names FileZilla. If a button says *Download Now*, *Start Download* or similar without naming FileZilla, it is an advert.
- **FileZilla Pro is a different, paid product.** It adds cloud storage protocols such as S3 and Google Drive. Nothing on a Noiz hosting account needs it. Take the plain FileZilla download.
- **The Mac App Store is not a shortcut.** Searching the Mac App Store for FileZilla returns FileZilla Pro and a related Pro utility, not the free client. The free FileZilla Client is not distributed through the App Store.
- **Homebrew does not carry it either.** There is no FileZilla cask in Homebrew's cask index, so `brew install --cask filezilla` will not find anything. Use the project download page.
**Never download FileZilla for Mac from a third-party download portal.** FileZilla is one of the most heavily repackaged applications on the internet. Portal sites wrap it in their own `.dmg` installer that carries adware, browser hijackers or worse, and they buy search advertising so they outrank the real project. If the address bar does not say `filezilla-project.org`, close the tab. Nothing about the file being "the same FileZilla" is true once someone else has rebuilt the package.
### Intel Build and Apple Silicon
At the time of review the project publishes the macOS client as an Intel build, labelled **macOS (Intel)** on the download page. On an Apple silicon Mac (M-series) it runs through Rosetta 2, Apple's translation layer. If Rosetta 2 is not already installed, macOS offers to install it the first time you open an Intel application; accept the prompt and let it finish. There is nothing to configure afterwards, and FileZilla's performance under Rosetta is irrelevant for file transfer work, which is bound by your line speed rather than the CPU.
## Step 2: Understand What You Actually Downloaded
This is the biggest difference from Windows. The macOS download is a compressed archive containing the finished application, named along the lines of `FileZilla_3.x.x_macos-x86.app.tar.bz2`. It is not a `.dmg` disc image and not a `.pkg` installer.
- **In Safari**, with the default *Open "safe" files after downloading* setting on, the archive is expanded automatically. You may never see the `.tar.bz2` file at all, only `FileZilla.app` sitting in your Downloads folder.
- **In Chrome, Firefox or Edge**, the archive stays as it is. Double-click it and macOS Archive Utility expands it into `FileZilla.app` beside it.
**There is no setup wizard, so there are no bundled offer screens.** The sponsored offers that the Windows installer presents are a function of that installer, and macOS has no equivalent step here. Use that as a test: if something claiming to be a FileZilla installer for Mac opens a wizard with licence screens and third-party offers, it did not come from the project. Quit it, delete it, and download again from the project site.
## Step 3: Move It Into Applications Before You Open It
Drag `FileZilla.app` out of Downloads and into your **Applications** folder. macOS may ask for your password to authorise the move.
Do this before the first launch rather than after. Because the download is an archive rather than a disc image, there is no drag-to-Applications window nudging you to do it, so it is easy to leave the app in Downloads and forget. That causes two real problems:
- **App translocation.** When you run a quarantined app straight from Downloads, macOS may execute it from a randomised, read-only location instead of where you think it is. The symptom is an app that behaves oddly, most often settings or saved sites that do not persist between launches. Moving the app to Applications and launching it from there stops it happening.
- **Accidental deletion.** Downloads is the folder people clear out. An application living there gets thrown away by a tidy-up months later, taking nothing with it but leaving you wondering where FileZilla went.
If you do not have administrator rights on the Mac, create a folder named `Applications` inside your home folder and put FileZilla there instead. It works exactly the same way and needs no password.
## Step 4: Get Past the Gatekeeper Warning Safely
The first time you open FileZilla, macOS will very likely block it and show a warning that it cannot verify the developer, or that the app was downloaded from the internet and Apple cannot check it for malicious software.
This is Gatekeeper reacting to the quarantine flag that macOS attaches to anything downloaded by a browser. It is a statement about where the file came from, not a verdict on FileZilla. Handle it like this:
### What Not to Do
- Do not run `sudo spctl --master-disable` or any similar command from a forum post. That switches Gatekeeper off for every application you download from now on, not just this one, and people forget they did it.
- Do not strip the quarantine flag with `xattr` as a reflex. It skips the check you actually want the next time you download something less trustworthy.
- Do not click through the warning on an app you did not download yourself, from a source you did not choose.
### What to Do
1. Dismiss the warning dialogue.
2. Open **System Settings** and go to **Privacy & Security**. On older macOS releases this is **System Preferences** then **Security & Privacy**.
3. Scroll to the security section. A message names the app that was just blocked, with a button to open it anyway.
4. Confirm with Touch ID or your account password. The app opens, and macOS remembers the decision, so this is a one-off.
Apple moves the exact wording and placement of this control between macOS releases, so if what you see does not match, follow Apple's own [Open a Mac app from an unknown developer](https://support.apple.com/en-za/guide/mac-help/mh40616/mac) page for the current path.
**The rule that matters:** only ever approve an app you downloaded yourself, from a source you chose deliberately. This same dialogue, and this same override, is exactly how a repackaged copy of FileZilla from a download portal gets waved onto a Mac. The click is safe here because you know the file came from `filezilla-project.org`. That is the only reason it is safe.
## Step 5: Confirm the Install Worked
FileZilla opens with a welcome dialogue listing links to the project forums and documentation. Close it. The main window is split into a local file pane on the left, a remote file pane on the right, a message log across the top and a transfer queue along the bottom.
To check which version you installed, open the **FileZilla** menu in the menu bar and choose **About FileZilla**. On macOS this sits under the application menu, not under a Help menu as it does on Windows.
If the window opens and About shows a version number, the installation is finished. Everything after this point is configuration, not installation.
## Where FileZilla Lives on Your Mac
Worth knowing before you need it:
- **The application** is `/Applications/FileZilla.app`, a self-contained bundle. There is no installer receipt, no background helper, no login item and nothing added to your system folders. Uninstalling is dragging that one item to the Bin.
- **Your settings and saved sites** are not inside the app. They live in a hidden folder in your home directory. In Finder choose **Go** then **Go to Folder** and enter `~/.config/filezilla`. If that is not there, try `~/.filezilla`, which older builds used. Pressing `Shift` + `Command` + `.` in any Finder window toggles hidden items on and off.
Two consequences follow from that split. First, dragging the app to the Bin does not remove your saved connections or stored passwords; delete the settings folder as well if you want a genuinely clean removal. Second, that folder is what you copy across when you move to a new Mac, which saves you rebuilding every site entry by hand.
## Two Settings Worth Handling Before You Connect
- **Password storage.** FileZilla keeps its own credential store rather than using the macOS Keychain, so anything you save sits in that settings folder. The first time you save a connection, FileZilla asks how to handle passwords. Choose the option to protect saved passwords with a master password, which encrypts them at rest. There is no recovery if you forget that master password, so record it in your password manager at the same time you set it.
- **Updates.** FileZilla checks for new releases itself and prompts you. Leave that on. An FTP client handles credentials and opens network connections, so running an old build is a real exposure rather than a cosmetic one.
When you do connect, prefer an encrypted method. Plain FTP sends your username and password across the network in the clear. Use FTPS (explicit FTP over TLS) or SFTP on your Noiz hosting account.
## Next Steps
With FileZilla installed, the next job is adding your Noiz account to the Site Manager:
- [How to Connect to Your FTP Account Using FileZilla](/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/)
- [How to Upload the Index File to Your Website via FileZilla](/server-administration/how-to-upload-the-index-file-to-your-website-via-filezilla/)
- [How to Create or Delete a Directory Using FileZilla](/server-administration/how-to-create-or-delete-a-directory-using-filezilla/)
- [How to Download Files and Directories to Your Computer via FileZilla](/server-administration/how-to-download-files-and-directories-to-your-computer-via-filezilla/)
Setting the same thing up on a PC as well? See [How to Install FileZilla on Windows](/server-administration/how-to-install-filezilla-on-windows/), where the installer does present bundled offer screens you need to refuse.
## Troubleshooting
**Symptom: "FileZilla is damaged and can't be opened. You should move it to the Bin."** Despite the wording, this is almost never a corrupted app. It usually means the download was truncated, or the archive came from somewhere that altered it. Delete the app and the archive, empty the Bin, and download again from the project site over a stable connection. Do not disable Gatekeeper to work around this message; a genuinely incomplete download will misbehave later anyway.
**Symptom: macOS says the application is not supported on this type of Mac, or asks to install Rosetta.** You are on an Apple silicon Mac and the Intel translation layer is not installed yet. Accept the prompt to install Rosetta 2 and let it complete, then open FileZilla again. Apple's [Using Intel-based apps on a Mac with Apple silicon](https://support.apple.com/en-za/102527) page covers it.
**Symptom: the download finishes but the archive will not expand.** Check the file size against the project page. A file noticeably smaller than expected is a partial download. Some corporate networks and endpoint security tools interfere with compressed archives in transit, so try a different browser or a different network before assuming the file is at fault.
**Symptom: `brew install --cask filezilla` reports no such cask.** That is correct behaviour, not a broken Homebrew. FileZilla is not published as a Homebrew cask. Download it from the project page instead.
**Symptom: the Mac App Store only offers FileZilla Pro.** Different product. Pro is the paid edition and the free client is not distributed through the App Store, so the download page is the route.
**Symptom: macOS refuses to let you move the app into Applications.** Your account does not have administrator rights on that Mac. Create an `Applications` folder inside your home folder and put FileZilla there. It runs identically.
**Symptom: settings or saved sites do not survive a restart of the app.** Check whether you are launching FileZilla from Downloads rather than Applications. Move the app properly, then launch it from its new location, and the problem goes away.
**Symptom: FileZilla opens but nothing connects.** That is a connection problem, not an installation problem. Check your host, username, port and encryption setting against the details in your welcome email or the Noiz client area, and work through the connection guide linked above.
**Symptom: the current release will not run on an older Mac.** Recent FileZilla builds require a supported macOS version. Older FileZilla builds exist, but an unsupported macOS is the bigger problem, since it stops receiving security updates. Where you can, move the transfer work onto a Mac that is still supported.
## Getting Help
If FileZilla installs cleanly but will not reach your hosting account, open a ticket from the Noiz client area and paste in the exact text from the FileZilla message log. Those log lines tell Noiz support immediately whether the issue is credentials, an encryption mismatch, something filtering the connection on your side, or something on the server, which normally removes a full round of back and forth.
# How to Redirect a Page or Website Using .htaccess
Source: https://docs.noiz.ie/server-administration/how-to-redirect-a-page-or-website-using-htaccess/
When a page moves or a whole site changes address, a redirect sends visitors (and search engines) straight to the new location instead of showing a broken link or a 404 error. On Apache-based Noiz hosting you set redirects in a `.htaccess` file placed in your site's document root. This guide shows you how to redirect a single page, a page to another domain, and an entire website, and it clears up a common mistake that stops redirects from behaving as expected.
**Last reviewed:** 27 July 2026, against Apache httpd **2.4** (current stable series). This guide is written for Noiz hosting and is kept current against Apache. It complements, and does not replace, the official Apache documentation linked below.
### Official Documentation Reference
- [Apache `mod_alias` module](https://httpd.apache.org/docs/2.4/mod/mod_alias.html) (the `Redirect` and `RedirectMatch` directives)
- [Apache `mod_rewrite` module](https://httpd.apache.org/docs/2.4/mod/mod_rewrite.html) (the `RewriteEngine` and `RewriteRule` directives)
- [Apache redirecting and remapping guide](https://httpd.apache.org/docs/2.4/rewrite/remapping.html)
- [Apache `.htaccess` howto](https://httpd.apache.org/docs/2.4/howto/htaccess.html)
## Prerequisites
- A hosting plan served by Apache (all Noiz shared and reseller plans qualify).
- Access to your site's files through your control panel's **File Manager**, or over FTP/SFTP.
- The redirect rules go in a file named exactly `.htaccess` (note the leading dot, no file extension) in the folder you want to affect, usually your document root.
## Two ways to redirect, and why one line trips people up
Apache offers two separate modules that can perform redirects, and mixing their directives is the single most common cause of confusion:
- **mod\_alias** provides the simple `Redirect` and `RedirectMatch` directives. Use these for straightforward "this address goes to that address" rules. They do *not* need `RewriteEngine on`.
- **mod\_rewrite** provides `RewriteRule` and `RewriteCond` for pattern-based, conditional rewriting. These *do* require `RewriteEngine on` to be switched on first.
Older guides often show `RewriteEngine on` sitting above a `Redirect 301` line. That line belongs to mod\_rewrite and has no effect on a mod\_alias `Redirect`. It is harmless clutter, but it misleads readers into thinking the two must go together. For a plain `Redirect`, leave `RewriteEngine on` out.
## Redirect one page to another page on the same site
Add this to the `.htaccess` in your document root:
```
# Redirect a single page to another page on the same site
Redirect 301 /oldpage.html /newpage.html
```
Now opening `yourdomain.com/oldpage.html` sends the visitor to `yourdomain.com/newpage.html`. The first path is the old location and must start with a `/`; the second is where you want visitors to land.
## Redirect a page to another domain
```
# Redirect a single page to a different domain
Redirect 301 /mypage.html https://example.com/
```
Always write the target as a full `https://` URL when it points to another site. Serve the secure address, not `http://`: every Noiz plan includes a free SSL certificate, so pointing visitors at the plaintext version only adds an extra hop and a security warning risk. Replace `example.com` with the real destination.
## Redirect an entire website to a new domain
To move a whole site while keeping the rest of each address intact, one mod\_alias line is enough. Apache appends whatever followed the matched prefix, so paths carry across automatically:
```
# Redirect every request to a new domain, preserving the path
Redirect 301 / https://newdomain.com/
```
A request for `olddomain.com/blog/post-1` then lands on `newdomain.com/blog/post-1`. Place this rule only in the old site's `.htaccess`. Do not add it to the new domain's document root, or you will create a redirect loop.
## Permanent (301) versus temporary (302)
The number after `Redirect` is the HTTP status code:
- **301** means "moved permanently". Search engines transfer ranking to the new address, and browsers cache the redirect aggressively. Use it once the move is final.
- **302** means "found / moved temporarily". Nothing is cached long term and search rankings stay with the original address. Use it for short-lived redirects, or while you test.
Because browsers cache a 301 hard, test a new rule with `302` first. If you publish a wrong 301 and then fix it, your own browser may keep following the old target until you clear its cache or test in a private window.
## Matching a page exactly
The mod\_alias `Redirect` directive matches by *prefix*. `Redirect 301 /old /new` also catches `/older`, `/old/page` and anything else starting with `/old`, which is often a surprise. When you need to match one exact path and nothing else, use `RedirectMatch` with an anchored expression:
```
# Match /oldpage.html exactly and nothing else
RedirectMatch 301 ^/oldpage\.html$ /newpage.html
```
## When you genuinely need mod\_rewrite
Reach for mod\_rewrite only when a simple `Redirect` cannot express the rule, for example redirecting based on query strings, hostnames or conditions. This is the case where `RewriteEngine on` is required:
```
# Redirect an entire domain with mod_rewrite (path preserved)
RewriteEngine on
RewriteRule ^(.*)$ https://newdomain.com/$1 [R=301,L]
```
Here `RewriteEngine on` switches the module on, `R=301` issues a permanent redirect, and `L` stops rule processing at that point. For plain address-to-address moves the mod\_alias examples above are simpler and easier to maintain.
## Troubleshooting
- **The redirect does not happen:** confirm the file is named exactly `.htaccess` and sits in the correct folder. Some File Managers hide dotfiles, so enable "show hidden files".
- **Old target keeps loading after you fixed a 301:** your browser cached the permanent redirect. Clear the cache or retest in a private window.
- **"Too many redirects" error:** a rule is pointing a site at itself, or the same rule exists on both the old and new domain. Remove the redirect from the destination.
- **500 Internal Server Error after editing:** a typo in the `.htaccess` syntax. Undo the last change and add rules back one at a time. No server restart is needed, as Apache reads `.htaccess` on every request.
If a redirect will not take effect or you would rather Noiz set it up for you, contact Noiz support with your domain and the old and new addresses, and the team will apply it for you.
# How to Redirect a Page to Another Page or Website Using .htaccess
Source: https://docs.noiz.ie/server-administration/how-to-redirect-a-page-to-another-page-or-website-using-htaccess/
When a page on your website moves or is retired, sending visitors and search engines to the replacement URL is far better than leaving a `404 Not Found` behind. On Apache hosting you do this with a `.htaccess` file placed in your website's document root. This guide shows you how to redirect a single page, a directory, or an entire site to a new location, which of the two Apache methods to use, and the mistakes that quietly break redirects.
**Last reviewed:** 27 July 2026, against Apache HTTP Server **2.4** (current stable series). This guide is written for Noiz hosting and is kept current against Apache. It complements, and does not replace, the official Apache documentation linked below.
### Official Documentation Reference
- [Apache HTTP Server Tutorial: .htaccess files](https://httpd.apache.org/docs/2.4/howto/htaccess.html)
- [mod\_alias: the `Redirect` directive](https://httpd.apache.org/docs/2.4/mod/mod_alias.html#redirect)
- [mod\_alias: the `RedirectMatch` directive](https://httpd.apache.org/docs/2.4/mod/mod_alias.html#redirectmatch)
- [mod\_rewrite directive reference](https://httpd.apache.org/docs/2.4/mod/mod_rewrite.html)
- [Apache rewrite guide: redirecting and remapping URLs](https://httpd.apache.org/docs/2.4/rewrite/remapping.html)
## Prerequisites
- A hosting account served by Apache. All Noiz shared and reseller hosting serves sites through Apache, so `.htaccess` directives are honoured.
- Access to your website files, either through the File Manager in your control panel, or over SFTP/FTP.
- The exact old URL path you want to redirect, and the exact destination URL.
## Where the .htaccess File Belongs
The file must sit in the document root of the site (or in the subdirectory you want the rules to apply to). The document root folder name depends on the control panel your hosting uses:
- **Plesk**: `httpdocs`
- **cPanel** and **DirectAdmin**: `public_html`
- **ISPConfig**: `web`
The filename is exactly `.htaccess`, with a leading dot and no extension. It is a hidden file, so switch on **Show hidden files** (or **dotfiles**) in your File Manager or FTP client before you go looking for it. If no `.htaccess` exists yet, create one; an empty document root is perfectly normal for a fresh site.
**Always download a copy of the existing file before you edit it.** A single mistyped directive takes the whole site offline with a `500 Internal Server Error`, and having the original to restore turns a crisis into a thirty second fix.
## Redirect a Single Page
The simplest and most readable method uses the `Redirect` directive, provided by Apache's `mod_alias` module. Add this to `.htaccess`:
```
# Send one retired page to its replacement on the same site
Redirect 301 /oldpage.html /newpage.html
```
Now a request for `https://yourdomain.com/oldpage.html` arrives at `https://yourdomain.com/newpage.html`, and the `301` tells search engines the move is permanent so ranking signals follow the new URL.
Replace `yourdomain.com`, `oldpage.html` and `newpage.html` with your own values throughout this guide; they are examples only.
### The Rules for Writing the Two Arguments
- The **first argument is a URL path, never a full URL**. Apache is explicit that it is a path beginning with a forward slash and that a relative path is not allowed, so write `/oldpage.html` and not `https://yourdomain.com/oldpage.html`. Get this wrong and the redirect will not fire; an invalid directive in `.htaccess` can take the site down with a `500 Internal Server Error` instead.
- The **second argument may be either** a path on the same site (`/newpage.html`) or a complete URL on any site (`https://example.com/newpage.html`).
- Any query string on the incoming request is carried across automatically, so `/oldpage.html?ref=news` lands on `/newpage.html?ref=news`.
## Redirect a Page to Another Website
To send a page to a different domain, give the full destination URL, and use `https://` rather than `http://`:
```
# Send one page to an external site
Redirect 301 /mypage.html https://example.com/
```
Pointing a redirect at `http://` is a common legacy habit worth breaking. The destination site will almost certainly bounce the visitor again from HTTP to HTTPS, which costs an extra round trip, loses the referrer in some browsers, and briefly exposes the request over plain text. Write the final HTTPS URL and be done in one hop.
## Redirect an Entire Site to a New Domain
When you have moved a whole site and the page paths are unchanged, you want every URL to carry its path across, not to dump every visitor on the new homepage:
```
# Move the whole site, preserving the path of every request
RedirectMatch 301 ^/(.*)$ https://newdomain.com/$1
```
A request for `/about/team.html` then lands on `https://newdomain.com/about/team.html`.
**Never point a whole-site redirect back at the same hostname.** A rule such as `Redirect 301 / https://yourdomain.com/` matches its own destination and the browser loops until it gives up with a "too many redirects" error. The old domain and the new domain must be genuinely different hostnames.
## The Directory Matching Gotcha
`Redirect` matches the beginning of the path rather than the whole of it, and it appends whatever remains to the destination. That behaviour is useful for moving a directory:
```
# Move a whole directory; /old/guide.html becomes /new/guide.html
Redirect 301 /old /new
```
It is also the single most common surprise in this article, because that one line does not move only `/old`. Everything beneath it travels too, so `/old/guide.html` and `/old/2019/archive.html` are redirected as well. Matching is done on complete path segments, which is the saving grace here: a sibling file such as `/oldsitemap.xml` is left alone, and a rule written with a trailing slash as `Redirect 301 /old/ /new/` will not catch a bare request for `/old`. When you want one URL and one URL only, use `RedirectMatch` with a regular expression anchored at both ends:
```
# Match this exact path and nothing else
RedirectMatch 301 ^/old$ /new
```
The `^` anchors the match to the start of the path and the `$` to the end, so nothing longer can match. Note that in `RedirectMatch` the pattern is a regular expression, so a literal dot should be escaped: `^/oldpage\.html$`.
## When to Use mod\_rewrite Instead
Older guides very often show `RewriteEngine on` immediately above a `Redirect 301` line. That combination is harmless but meaningless: `RewriteEngine` belongs to the `mod_rewrite` module and has no effect whatsoever on `mod_alias` directives such as `Redirect` and `RedirectMatch`. Use one module or the other, and do not mix them in a single rule.
Reach for `mod_rewrite` when the redirect depends on something other than the path alone, such as the hostname, the query string, the request method, or whether a file exists. The equivalent of the first example looks like this:
```
RewriteEngine On
# Same redirect, expressed with mod_rewrite
RewriteRule ^oldpage\.html$ /newpage.html [R=301,L]
```
Two differences catch people out. First, inside `.htaccess` the leading slash is stripped from the path before matching, so the pattern is `^oldpage\.html$` and not `^/oldpage\.html$`. Second, the flags do real work: `R=301` issues a permanent redirect rather than an invisible internal rewrite, and `L` stops processing so later rules cannot fire as well.
### Redirect All Traffic to HTTPS
This is the classic case that genuinely needs `mod_rewrite`, because the decision depends on the protocol rather than the path:
```
RewriteEngine On
# Force every request onto HTTPS
RewriteCond %{HTTPS} !=on
RewriteRule ^(.*)$ https://%{HTTP_HOST}/$1 [R=301,L]
```
Only add this once a valid SSL certificate is issued and working for the domain, otherwise you redirect every visitor into a certificate warning.
## Where to Place Rules in the File
Apache reads `.htaccess` from the top down, and the first redirect that matches wins. Two placement rules save a lot of confusion:
- **Put your redirects above any application block.** WordPress, Joomla and similar systems install a front controller block that routes anything not found on disk into the application. A redirect placed below it can be swallowed before it is ever reached.
- **Never edit inside the managed markers.** Anything between `# BEGIN WordPress` and `# END WordPress` is regenerated by the application and your changes will vanish on the next permalink save or plugin update. Add your rules above the `# BEGIN` line.
## Test the Redirect Properly
Browsers cache `301` responses aggressively and often for a very long time, which is exactly why a wrong permanent redirect is so painful to undo. Test in a way the cache cannot fool you:
1. Check the raw response from the command line, which ignores browser caching entirely: `curl -I https://yourdomain.com/oldpage.html` Look for `HTTP/2 301` (or `HTTP/1.1 301 Moved Permanently`) and a `Location:` header holding the destination you expect.
2. Confirm the destination returns `200 OK`, not another redirect. Chains of redirects are slow and search engines discount them.
3. Only then test in a browser, using a private or incognito window.
If you are still experimenting, use `302` instead of `301` while you work. A `302` is temporary, is not cached in the same aggressive way, and can be changed freely. Switch it to `301` once the destination is confirmed correct.
## Troubleshooting
**Symptom**: the whole site returns `500 Internal Server Error` straight after saving. The file contains a syntax error or a directive the server does not permit in `.htaccess`. Restore your backup to bring the site straight back up, then reintroduce the rules one line at a time until the culprit shows itself.
**Symptom**: nothing happens at all and the old page still loads. The most likely causes are a first argument that is not a path beginning with a slash, the file saved with a trailing extension such as `.htaccess.txt` by a text editor, or the file sitting one directory above or below the real document root.
**Symptom**: the browser reports "too many redirects" or `ERR_TOO_MANY_REDIRECTS`. The destination matches the same rule that produced it. Check for a whole-site redirect pointing at its own hostname, or two rules that send traffic back and forth between each other.
**Symptom**: pages below the one you meant to move are redirecting as well. This is the directory matching behaviour described above, where `Redirect` carries everything under the path across with it. Swap `Redirect` for an anchored `RedirectMatch` when a single URL is all you want.
**Symptom**: the redirect works, but the browser keeps going to the old destination after you corrected the rule. The earlier `301` is cached. Verify the fix with `curl -I` first, then clear the browser cache or test in a private window.
**Symptom**: the rules disappeared by themselves. They were written inside an application-managed block. Move them above the `# BEGIN` marker.
## Getting Help
If a redirect will not behave and the checks above have not found it, open a ticket from the Noiz client area with the domain name, the exact old and new URLs, and the `.htaccess` block you added. Noiz support can read the Apache error log for your site, which records the precise line that failed, and confirm whether the rule is being reached at all. On managed plans Noiz will apply and test the redirect for you.
# How to Reduce the Number of Inodes Your Account Uses
Source: https://docs.noiz.ie/server-administration/how-to-reduce-the-number-of-inodes-your-account-uses/
An inode is a filesystem record that stores the metadata for a single file or folder. In practical terms, your inode count is the total number of files and folders in your hosting account, and most shared hosting plans include an inode allowance alongside the disk-space allowance. If you reach the inode limit you can be blocked from creating new files even when you still have disk space free. That usually shows up as failed uploads, broken login sessions, a site that stops saving changes, or email that will not deliver.
This guide shows you how to see what is using your inodes and how to safely bring the count down. It applies to any Noiz hosting account, whatever software you run.
**Last reviewed:** 27 July 2026. This is general file and disk housekeeping guidance for Noiz hosting and applies regardless of which control panel your plan uses.
## How to access your files
You need a way to see and delete files in your account. Any of the following works:
- **File Manager** in your Noiz hosting control panel (Plesk on South African shared hosting). This is the quickest option for a browse-and-delete cleanup and needs nothing installed.
- **FTP or SFTP** with a client such as FileZilla, using the connection details from your control panel.
- **SSH**, where your plan includes shell access. SSH is the fastest way to count files and remove large directories in bulk.
### Find out what is using your inodes first
Before you delete anything, work out where the files actually are so you spend your effort in the right place. Over SSH, from your account's home directory, this lists your top-level folders ordered by how many files each one contains:
```
for d in */; do echo "$(find "$d" | wc -l) $d"; done | sort -n
```
The folders at the bottom of the list are your biggest inode consumers. To see the total number of files in the current folder and everything beneath it, use:
```
find . | wc -l
```
In the control panel File Manager you can achieve the same thing by opening your largest directories to see what is inside them. Once you know where the bulk of your files live, work through the sections below.
## Safe ways to reduce your inode count
The most reliable way to reduce inodes is to remove files and folders you no longer need. The cases below are the ones that most often account for a bloated inode count. Keep a copy of anything you are unsure about before you delete it.
### 1. Remove old backups and staging sites
Scheduled backups, or backups created by third-party tools such as auto-installers, often fill all the available space on an account if they are left unchecked. A single backup can contain a full second copy of your site and its files, doubling that part of your inode count. Download the backup files to your own computer, then delete them from your hosting account. Do the same with any staging or development copies of your site that you no longer need, which frees a large number of inodes in one go.
### 2. Delete inactive plugins and themes
If you run WordPress, delete any plugins and themes that are not in use rather than only deactivating them. Deactivating leaves all of the code in your directory, so it still counts against your inode quota. Removing unused plugins and themes also reduces your attack surface, because dormant code is a common route in for attackers, and it keeps the WordPress admin lighter to load.
### 3. Remove unused image sizes
Many WordPress themes and plugins generate several resized copies of every image you upload, and it is unlikely that all of them are actually shown on the front end. Each generated size is a separate file and therefore a separate inode. Review your theme and media settings, keep only the sizes you use, then regenerate the thumbnails to purge the rest. A plugin such as Regenerate Thumbnails does this cleanly and removes the orphaned sizes for you.
### 4. Clear cached files
Nearly all modern web applications cache content to disk by default, which can quietly build up a very large number of small cache files. Clear your application's cache folder regularly. Most applications offer a purge option in their administrative area, which is safer than deleting files by hand because it lets the software rebuild only what it needs. For WordPress, look inside the `wp-content` folder for directories named `cache` and clear them.
### 5. Remove development dependency folders
Folders such as `node_modules` (from Node.js and npm) and `vendor` (from PHP Composer) are among the heaviest inode consumers there are, often holding tens of thousands of files each. If a project has been built and deployed, these folders are frequently no longer needed in your live web directory and can be removed. Over SSH:
```
rm -rf node_modules
```
Only delete a dependency folder once you are certain the running site does not need it, and never run `rm -rf` against a path unless you are sure of it, because it deletes without asking.
### 6. Delete the .opcache folder
If you have an `.opcache` folder in your web directory, it can accumulate cached PHP files that are safe to clear. Delete it over SSH or in the File Manager. It will be rebuilt automatically the next time your site runs.
### 7. Clear old logs and session files
Application logs, error logs, and PHP session files build up steadily and are rarely needed once they are more than a few days old. Look for large numbers of files in folders named `logs`, `tmp`, or a PHP sessions directory, and clear out anything old. These files regenerate on their own, so removing them is low risk.
### 8. Clean up your email accounts
Email adds a lot to your inode count because each message is stored as an individual file, so a mailbox with thousands of messages uses thousands of inodes on its own. Empty the Junk and Spam folders, which tend to accumulate quickly, and empty the Trash or Bin folders, which often hold large numbers of deleted messages. Archiving very old mail to your own computer can save a meaningful number of inodes if you are on a tight quota, but download and verify that archive before you delete anything from the server, so you do not lose data you still need.
## Still running low?
If you have worked through this list and still need more headroom, upgrading to a plan with a higher inode allowance is the cleanest fix. Noiz support can confirm your current usage and recommend the right plan for your site; open a ticket from your client area and the team will help.
# How to Set File and Directory Permissions Recursively in Linux
Source: https://docs.noiz.ie/server-administration/how-to-set-file-and-directory-permissions-recursively-in-linux/
Incorrect permissions on your directories or files will often cause unexpected behaviour, and can leave your site insecure.
Web servers commonly return a **500 Internal Server Error** when the permissions on your web directories and files are set incorrectly, so getting them right is one of the first things to check when a site stops loading.
This guide explains how to recursively set the correct permissions on your directories and files, using three different methods so you can pick whichever suits your setup.
***Note:** This is also the procedure to follow if you need to reset the permissions on a WordPress site, for example after a migration or a botched plugin install.*
**Last reviewed:** 27 July 2026. This guide is written for Noiz hosting and is kept current against the Plesk and ISPConfig 3 control panels and the FileZilla FTP client. It complements, and does not replace, the official documentation linked below.
### Official Documentation Reference
- [WordPress: Changing File Permissions](https://developer.wordpress.org/advanced-administration/server/file-permissions/) (the authoritative reference for the values a WordPress site expects).
- [Plesk Obsidian Customer Guide](https://docs.plesk.com/en-US/obsidian/customer-guide/) (File Manager, under Websites & Domains).
## Which permissions should you use?
On a standard Linux web server, the safe baseline is:
- **755** for directories (the owner can read, write and enter the directory; everyone else can read and enter it, but not write to it), and
- **644** for files (the owner can read and write; everyone else can only read).
These are the values a default WordPress installation expects, and they work for almost every PHP application. The important thing is that directories and files need *different* values, so any method that sets both to the same number will break something.
**Never** set a file or directory to **777**. It grants write access to every user on the server and is the single most common cause of a hacked WordPress site. If a tutorial elsewhere tells you to use 777 to fix an upload problem, the real issue is almost always file ownership, not permissions.
**Table of contents**
- [Set permissions using FileZilla](#filezilla),
- [Set permissions using Plesk](#plesk), and
- [Set permissions using the Linux command line](#command-line).
## Set permissions using FileZilla
If you are hosted on one of the Noiz ISPConfig 3 servers, or you have a managed server with Noiz, or you simply prefer working in a graphical FTP client, this is the method for you. [FileZilla](https://filezilla-project.org/) is a free, open-source FTP client for Windows, macOS and Linux.
Follow these steps to recursively set permissions on directories, files, or both.
1. Connect to your hosting over FTP with FileZilla. On the Noiz ISPConfig 3 servers, your website lives in the `/web` directory.
2. Navigate into the root directory of your application. In this example, you are resetting the permissions on a WordPress installation.
3. Right-click the directory you want to change and select the **File permissions** option.
4. To set the directories first, enter `755` in the **Numeric value** field, tick **Recurse into subdirectories**, and choose **Apply to directories only**. Click **OK**.
FileZilla will now walk through every directory and sub-directory, setting each one to 755.
5. Repeat the process to set the files. Right-click the same top-level directory, choose **File permissions** again, enter `644` in the **Numeric value** field, tick **Recurse into subdirectories**, and this time choose **Apply to files only**. Click **OK**.
Because FileZilla lets you apply the change to directories or files separately, you can set both correct values in two passes without breaking anything. That is what makes it a better choice than a panel-based file manager for this task.
## Set permissions using Plesk
Plesk includes a full-featured file manager that can set directory permissions from within the control panel, without any FTP client.
Follow these steps to reset the permissions on your web space. The example below uses a domain called `yourdomain.com` (replace this with your own domain) running a WordPress installation.
1. Log in to the Plesk control panel for the subscription that holds your web application.
2. Open the **Websites & Domains** section from the left-hand navigation bar.
3. Choose your subscription from the dashboard to open the management page for that domain.

4. Click **File Manager**, found in the **Files & Databases** group on the dashboard. This opens the file manager at the root directory for the web space.

5. To the left of the directory you want to change, open the row menu and choose **Change Permissions**.

6. Set the permissions to **755**. Graphically, that means:
- **Read** is ticked for Owner, Group and Others,
- **Write** is ticked for Owner only, and
- **Execute/Search** is ticked for Owner, Group and Others.
7. Tick **Change permissions of enclosed files and subdirectories** (labelled **Change permissions recursively** in some Plesk versions) so the whole tree is updated.
8. Click the blue **OK** (or **Save**) button at the bottom to apply the change.

**Important gotcha:** Plesk does *not* let you set files separately from directories. If you recurse a directory with 755, every file inside it is also set to 755, which is the wrong value for files and will leave them world-executable. For that reason, if you are resetting a real application such as WordPress, use the FileZilla method above or the command-line method below instead, both of which handle directories and files separately.
## Set permissions using the Linux command line
The command line is the fastest and most precise method, and the only one that resets directories and files in one go while keeping them correct. If you have SSH access, or you are on a managed or cloud server, this is the recommended approach.
Connect to your server over SSH and identify your web root. On the Noiz ISPConfig 3 servers this is the `/web` directory inside your site's home folder; on a Plesk subscription it is the `httpdocs` directory.
Set every directory (and sub-directory) to 755:
```
find /path/to/webroot -type d -exec chmod 755 {} \;
```
Set every file to 644:
```
find /path/to/webroot -type f -exec chmod 644 {} \;
```
Replace `/path/to/webroot` with the real path to your site. The `find` command walks the entire tree; the `-type d` and `-type f` tests are what let you target directories and files separately, which is exactly what a panel file manager cannot do.
### WordPress: protect wp-config.php
Once a WordPress site is back to 755/644, tighten the one file that holds your database credentials. Restricting `wp-config.php` to **640** (or **600**) stops other users on a shared server from reading your database password:
```
chmod 640 /path/to/webroot/wp-config.php
```
The official [WordPress documentation](https://developer.wordpress.org/advanced-administration/server/file-permissions/) confirms these values for a suexec setup, which is how Noiz shared hosting runs.
## Troubleshooting
**Symptom:** The site still shows a 500 error after resetting permissions. Check that no directory or the site root has been left at 777, and that a security file such as `.htaccess` is set to 644, not 640 or 600, so the web server can read it.
**Symptom:** Permissions look correct but the site still will not load, or you see permission-denied errors in the logs. The problem is usually file *ownership* (the user and group that own the files), not permissions. This commonly happens after a migration or after editing files as `root`. Ownership cannot be fixed from FileZilla or the Plesk file manager, so on a managed Noiz plan the quickest fix is to raise a support ticket and Noiz will correct it for you.
If you are on a managed or shared plan and would rather not touch permissions yourself, [contact Noiz support](https://www.noiz.co.za/submitticket.php) and the correct permissions and ownership will be set for you.
# How to Upload the Index File to Your Website via FileZilla
Source: https://docs.noiz.ie/server-administration/how-to-upload-the-index-file-to-your-website-via-filezilla/
Once FileZilla is connected to your Noiz hosting account, uploading is a matter of dragging files from your computer into the right folder on the server. This guide shows you how to do that reliably: where the files have to land, how to avoid the silent mistakes that leave your site showing the wrong page, and how to confirm the upload actually worked. The worked example throughout is the one most people need first, which is getting an `index` file live so your domain stops showing a placeholder page, but the same steps apply to any file or folder you upload.
The steps below apply to any Noiz hosting account, whichever control panel your account uses. FTP is a server-level service, so what matters is the FTP user and the folder you upload into rather than any particular panel screen.
**Last reviewed:** 27 July 2026, against FileZilla Client **3.x** (current stable series). This guide is written for Noiz hosting and is kept current against FileZilla. It complements, and does not replace, the official FileZilla documentation linked below.
### Official Documentation Reference
- [FileZilla Client Tutorial](https://wiki.filezilla-project.org/FileZilla_Client_Tutorial_(en)): the vendor walkthrough of the interface and a first transfer.
- [Using FileZilla](https://wiki.filezilla-project.org/Using): the transfer queue, directory comparison and synchronised browsing.
- [FileZilla Data Type](https://wiki.filezilla-project.org/Data_Type): how ASCII and binary transfer types are chosen, and when to override them.
## Prerequisites
- FileZilla Client installed on your computer. See [How to Install FileZilla on Windows](/server-administration/how-to-install-filezilla-on-windows/).
- A working FTP connection to your hosting account. See [How to Connect to Your FTP Account Using FileZilla](/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/).
- The files you want to upload, already saved somewhere you can find on your own computer.
## Step 1: Connect to Your Hosting Account
Open FileZilla and enter your FTP **Host**, **Username** and **Password** in the Quick Connect bar across the top of the window, then click **Quickconnect**. The host is normally `ftp.yourdomain.com` or `yourdomain.com`, replacing `yourdomain.com` with your own domain.
Use the FTP username and password that belong to your hosting account. These are the credentials created for the FTP user in your hosting control panel, not your Noiz client area login and not your email password. If you have never created an FTP user, the main hosting account username usually doubles as one; if you are unsure, check your Noiz welcome email or your control panel's FTP section.

Leave **Port** blank unless Noiz has given you a specific port. For anything beyond a quick test, set the connection up in the Site Manager with encryption required, as described in the FTP connection article linked above, so your password is never sent in clear text.
## Step 2: Open Your Web Root Folder
This is the step that catches most people out. When you log in, FileZilla usually drops you into the home directory of the FTP user, not into the folder your website is actually served from. Files left in the home directory are invisible to visitors.
In the right pane, which is the server side, find and double-click your web root folder. Its name depends on the platform your account runs on, and is commonly `public_html`, `httpdocs` or `web`. If you are not sure which folder is yours, the one already containing site files or a placeholder page is almost always it.

If your account hosts more than one domain, each add-on or additional domain has its own folder, often nested inside the main web root or under a `domains` directory. Upload into the folder belonging to the domain you are working on, otherwise your files go live on the wrong site. If the FTP user was created and scoped to a single site, you may land straight in that site's web root and see your existing files immediately.
## Step 3: Find the Files on Your Computer
In the left pane, which is the local side, browse to the folder holding the files you want to upload. The upper part of the left pane is a directory tree and the lower part lists the files in the selected folder.
If you are uploading a website you downloaded or exported, make sure you are pointing at the folder that contains `index.html` or `index.php` directly, not at a parent folder that contains a single subfolder. Uploading the wrapper folder is a common cause of a site that loads a directory listing instead of a homepage.
## Step 4: Upload
Select the file or files you want, right-click the selection and choose **Upload**. Dragging the selection from the left pane into the right pane does exactly the same thing.

A few practical points:
- **Multiple files**: hold `Ctrl` to pick individual files or `Shift` to select a range, then upload them in one action.
- **Whole folders**: uploading a folder recreates it, with everything inside it, in whichever remote directory the right pane is currently showing. Confirm the right pane is where you want the folder to land before you start.
- **Hidden files**: files whose names begin with a dot, such as `.htaccess`, are not shown by default. Turn on **Server** then **Force showing hidden files** so you can see and manage them.
- **Archives do not extract**: uploading a `.zip` file leaves it on the server as a `.zip` file. FTP has no extract command, so either upload the extracted files or extract the archive using the file manager in your control panel.
## Step 5: Watch the Queue and Confirm the Result
The panes along the bottom of the FileZilla window show the transfer progress. Three tabs matter:
- **Queued files**: still waiting to transfer.
- **Failed transfers**: anything that did not complete. Right-click here and choose **Reset and requeue all** to retry.
- **Successful transfers**: the confirmed uploads.
Do not close FileZilla while the queue is still running. A quiet progress bar is not the same as an empty queue, so check the **Failed transfers** tab before you walk away. Once the queue is empty and nothing has failed, the file should be visible in the right pane with the size it has locally.
Then load your domain in a browser. If you have just replaced a homepage, force a hard refresh so you are not looking at a cached copy: `Ctrl` + `F5` on Windows or `Cmd` + `Shift` + `R` on macOS.
## Gotchas Worth Knowing Before You Upload
**Filenames are case sensitive on the server.** Linux treats `Index.html`, `INDEX.HTML` and `index.html` as three different files, and only the lowercase one is served as a default document. Windows hides this from you locally, so a site that worked perfectly on your own machine can break the moment it is uploaded. The same applies to every image and stylesheet your pages link to.
**An old index file will keep winning.** Web servers look for default documents in a set order, and `index.html` is normally checked before `index.php`. If you upload a new PHP site into a folder that still contains an old `index.html`, visitors carry on seeing the old page. Delete or rename the file you no longer want.
**Placeholder pages need replacing, not adding to.** A new hosting account often ships with a default holding page. Uploading your own `index.html` alongside it usually replaces it, and FileZilla will prompt you to confirm the overwrite. If your own file is named differently, remove the placeholder so it stops being served.
**Leave the transfer type on automatic.** FileZilla decides per file extension whether to transfer as text or as binary, and its defaults are correct. Forcing ASCII mode on images, fonts, PDFs or archives corrupts them in transit, producing files that upload without error and then refuse to open.
**Overwrite prompts are worth reading.** When a file already exists, FileZilla shows both versions with their sizes and dates so you can choose. Be careful with **Always use this action**, because it applies to every remaining file in the queue and is an easy way to overwrite work you meant to keep.
**Permissions are not carried over.** Uploaded files inherit server defaults rather than whatever permissions they had on your computer. The normal targets are `644` for files and `755` for directories. If something is unreadable to visitors, right-click it in the right pane, choose **File permissions** and set it there.
**Many small files are slow over FTP.** Each file costs a round trip, so a few thousand small files can take far longer than a single large one of the same total size. For a full site migration, compress the site locally, upload the single archive, and extract it with the file manager in your control panel.
## Troubleshooting
**Symptom**: the upload succeeds but the site still shows the old page. Hard refresh the browser first, then check that you uploaded into the web root of the correct domain and that no older default document is still present in that folder.
**Symptom**: `553 Could not create file` or `550 Permission denied`. The FTP user cannot write to that folder. Confirm you are inside a directory the user owns, and check whether your account is out of disk space, which produces the same error.
**Symptom**: the browser shows `403 Forbidden` or an empty directory listing after uploading. There is no valid default document in the folder, or the file permissions are too restrictive. Confirm the file is named `index.html` or `index.php` in lowercase, and set it to `644`.
**Symptom**: transfers stall at 100 percent, or the connection drops partway through a large batch. This is usually a passive mode or firewall issue. In the Site Manager, open the **Transfer Settings** tab and set **Transfer mode** to **Passive**, then reset and requeue the failed transfers.
**Symptom**: uploaded images or archives are corrupt and will not open. The file was transferred in ASCII mode. Go to **Transfer** then **Transfer type** and set it back to **Auto**, then upload the affected files again.
**Symptom**: `.htaccess` uploaded but appears to be missing. It is hidden by default. Enable **Server** then **Force showing hidden files** to display it.
## Related Articles
- [How to Install FileZilla on Windows](/server-administration/how-to-install-filezilla-on-windows/)
- [How to Connect to Your FTP Account Using FileZilla](/server-administration/how-to-connect-to-your-ftp-account-using-filezilla/)
- [How to Create or Delete a Directory Using FileZilla](/server-administration/how-to-create-or-delete-a-directory-using-filezilla/)
- [How to Download Files and Directories to Your Computer via FileZilla](/server-administration/how-to-download-files-and-directories-to-your-computer-via-filezilla/)
## Need a Hand?
If your files are on the server but the site still is not loading as expected, open a ticket from your Noiz client area with your domain name, the exact path you uploaded to, and the filename of your homepage. The Noiz support team can confirm the web root for your account and check the server-side permissions for you.
# PHP Error: Allowed Memory Size of X Bytes Exhausted
Source: https://docs.noiz.ie/server-administration/php-error-allowed-memory-size-of-x-bytes-exhausted/
A PHP script stops dead and the page goes blank or shows a fatal error like this:
```
Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 20480 bytes) in /home/example/public_html/wp-content/plugins/example/import.php on line 512
```
This is PHP's `memory_limit` doing exactly what it was configured to do. The script asked for more memory than it is permitted to use, so PHP halted it rather than letting it consume the server. This guide explains what the numbers in that message mean, how to raise the limit correctly on Noiz hosting, and how to tell whether raising it is the right fix at all.
It also corrects a piece of advice that circulates widely and does not work. If you have been told to put `RLimitMem max` in your `.htaccess` file, see the section below on why that directive has nothing to do with this error.
**Last reviewed:** 27 July 2026, against PHP **8** (every currently supported branch behaves identically for this setting). This guide is written for Noiz hosting and is kept current against PHP. It complements, and does not replace, the official PHP documentation linked below.
### Official Documentation Reference
- [PHP Manual: the `memory_limit` directive](https://www.php.net/manual/en/ini.core.php#ini.memory-limit)
- [PHP Manual: per-directory `.user.ini` files](https://www.php.net/manual/en/configuration.file.per-user.php)
- [PHP Manual: where and how configuration settings can be changed](https://www.php.net/manual/en/configuration.changes.php)
- [PHP Manual: setting a value at runtime with `ini_set()`](https://www.php.net/manual/en/function.ini-set.php)
- [Apache Manual: the `RLimitMem` directive (for comparison)](https://httpd.apache.org/docs/2.4/mod/core.html#rlimitmem)
## Prerequisites
- Access to your hosting control panel, or to your site files through File Manager or SFTP.
- The full error message, including the file path and line number it names. That path tells you which application is at fault and where a per-directory fix belongs.
- A backup copy of any configuration file you are about to edit, particularly `.htaccess`, since a single bad line there takes the whole site offline until it is corrected.
## What the error is actually telling you
Every part of the message is useful, so read it before changing anything:
- **Allowed memory size of 134217728 bytes** is your current limit expressed in bytes. Divide by 1048576 to get megabytes, so 134217728 is `128M`, 268435456 is `256M`, and 536870912 is `512M`. This number is the value you are about to change.
- **Tried to allocate 20480 bytes** is the request that pushed the script over the edge. It is rarely the culprit. In this example the script needed a further 20 KB and could not get it, which means the previous 128 MB had already been consumed by something else.
- **In /path/to/file.php on line 512** is simply where the ceiling was hit, not necessarily where the memory was wasted. Treat it as a strong hint about which plugin, theme, or component to investigate, rather than as a confirmed diagnosis.
One further point that saves a lot of confusion: `memory_limit` applies to a single PHP request, not to your account as a whole. Setting it to `512M` does not reserve half a gigabyte permanently. It means any one script is allowed to grow to that size before PHP stops it.
## Why "RLimitMem max" does not fix this
Older articles, including an earlier version of this one, recommended adding `RLimitMem max` to `.htaccess`. Do not use it for this problem.
`RLimitMem` is an Apache directive. It sets the operating-system memory limit for processes that Apache itself launches as child helpers, historically CGI scripts. It never touches PHP's own `memory_limit` value, so the number in your error message will not budge. Where the server accepts the directive in `.htaccess` at all, it does nothing on a site running PHP-FPM or FastCGI, because those PHP processes are not started by Apache. Where the server does not accept it, the line returns a 500 Internal Server Error and leaves the situation looking worse than it was.
PHP's memory ceiling is a PHP setting and has to be changed in a place PHP reads. That means your control panel, a `.user.ini` file, a `php_value` line where PHP runs as an Apache module, or the script itself. Those four methods are covered below.
## Decide whether to raise the limit at all
The PHP default is `128M`, which is comfortable for the great majority of sites. A memory error is often a symptom rather than the illness, so it is worth thirty seconds of thought before reaching for a bigger number:
- **Did it start suddenly?** If the site was fine yesterday and the only change was a plugin update or a new extension, suspect that change first. A runaway loop or a query that loads an entire database table into an array will exhaust any limit you set.
- **Is the failed allocation tiny?** A script that dies while asking for a few kilobytes has already burned through everything it was given. Raising the limit may buy a few seconds and then fail again slightly later.
- **Is the task genuinely heavy?** Resizing large images, importing or exporting sizeable datasets, generating PDFs, running Composer, or operating a busy WordPress site with a page builder are all legitimate reasons to need more than `128M`. Here, raising the limit is the correct answer.
Where raising it is justified, `256M` is the usual first step and `512M` is a reasonable ceiling for a shared site. Avoid `-1`, which means unlimited: on shared hosting a single faulty script would then be free to consume everything available. If `512M` is still not enough, that is evidence of a code fault, not of a limit set too low.
## How to raise the limit
The right method depends on how PHP runs on your account. The methods below are ordered from most reliable to most situational. If you are unsure which applies, start with the control panel, which works in every case.
### Method 1: Your hosting control panel (recommended)
Setting the value in the panel applies it at account or subscription level, so it takes effect regardless of whether PHP runs as FPM, FastCGI, or a module, and it survives changes to your site files.
- **Plesk:** open **Websites & Domains**, select the domain, click **PHP Settings**, set **memory\_limit** to your chosen value, and click **Apply** or **OK**.
- **DirectAdmin:** open the PHP configuration for the domain and edit **memory\_limit** for the PHP version the site is actually using. If more than one version is installed, changing the wrong one is the most common reason nothing happens.
- **cPanel:** open **MultiPHP INI Editor**, select the domain, and set **memory\_limit** there.
- **ISPConfig:** open the website under **Sites**, go to the **Options** tab, and add the value to the custom PHP settings field for the site.
Where an account uses the CloudLinux PHP Selector, that is the correct place to make the change instead. Step-by-step instructions are in [How to Increase or Decrease PHP Memory Limit via CloudLinux Selector in cPanel](/server-administration/how-to-increase-or-decrease-php-memory-limit-via-cloudlinux-selector-in-cpanel/) and [the DirectAdmin equivalent](/directadmin/how-to-increase-or-decrease-php-memory-limit-via-cloudlinux-selector-in-directad/).
### Method 2: A .user.ini file (PHP-FPM and FastCGI)
Most current hosting runs PHP as FPM or FastCGI rather than as an Apache module. On those setups the correct file-based approach is a `.user.ini` file, and `.htaccess` will not work at all.
1. Using File Manager or SFTP, open the folder your site runs from, normally the document root such as `httpdocs`, `public_html`, or `web`.
2. Create a plain-text file named exactly `.user.ini`, noting the leading dot. Enable **Show hidden files** in your File Manager if you cannot see it afterwards.
3. Add this single line and save: `memory_limit = 256M`
**Allow a few minutes.** PHP caches `.user.ini` files, by default for 300 seconds, so a change can take up to five minutes to appear. Reloading the page repeatedly in the first minute and concluding that the file does not work is the classic mistake here.
Note the syntax difference between the two file types. A `.user.ini` file uses `ini` syntax with an equals sign, while `.htaccess` uses Apache syntax with a space. Mixing them up produces a file that is silently ignored, or a 500 error, depending on which way round you get it wrong.
### Method 3: .htaccess (only where PHP runs as an Apache module)
The classic `.htaccess` method works only when PHP is loaded as an Apache module, commonly called mod\_php. On that kind of setup, add this line to the `.htaccess` file in your document root:
```
php_value memory_limit 256M
```
If the error persists on one particular area of the site, add the same line to an `.htaccess` file inside the folder named in the error message, for example `yourdomain.com/wp-admin/.htaccess`. Settings in a subfolder override the parent for requests served from that folder.
**If the site returns a 500 error the moment you save, your server is not running mod\_php.** Remove the line immediately and the site will recover, then use Method 1 or Method 2 instead. This is the expected outcome on most modern hosting and is not a sign that anything is broken. If you need a walkthrough of editing the file itself, see [How to Edit the .htaccess File in the cPanel File Manager](/cpanel/how-to-edit-the-htaccess-file-in-the-cpanel-file-manager/).
### Method 4: Inside the script (targeted and temporary)
If only one script needs the extra headroom and you are able to edit it, raise the limit at the top of the file, before any heavy work begins:
```
Manage Credit Card** (or **Payment Methods**) in the client area.
## Prefer to Pay With Monero?
Stripe is convenient, but Noiz also advocates for **Monero**. If you pay using the **Cryptocurrency** gateway option with Monero, you receive a **10% discount on all services**, and your invoice updates automatically at checkout to reflect the discounted total.
## Need Help?
If you have any questions or run into trouble at checkout, contact Noiz support:
- **Email:** [support@noiz.co.za](mailto:support@noiz.co.za)
- **Signal:** [Contact Noiz on Signal](https://signal.me/#eu/nlpV6nV8oyZBdAPth6XDZRPWwDy6WQstSUROfEGo9Hey9pJywNNJx7fgXyDkficb)
**[noiz]** ยท disrupt the signal
# How to Save (and Make) Money on Your Web Hosting
Source: https://docs.noiz.ie/billing/how-to-save-and-make-money-on-your-web-hosting/
Everyone likes to keep more of their money, and with the cost of living rising, recurring bills like web hosting are a sensible place to look for savings. A few small choices can add up over a year. This guide explains the main ways you may be able to reduce what you spend on your Noiz hosting, and one way you might even turn your hosting into a small source of income.
**Before you start:** the exact discounts, incentives and programmes described below change from time to time, and some may not be running at any given moment. Always confirm the current pricing and promotions on the [Noiz website](https://www.noiz.co.za), or ask the Noiz support team, before you make a decision based on this article.
## Ways to save on your hosting
### Pay annually instead of monthly
Most hosting subscriptions, including shared hosting and managed WordPress plans, can be billed annually rather than monthly. Where Noiz runs an annual-billing discount, paying up front for the year works out cheaper than twelve separate monthly payments. Committing a larger amount in one go can feel daunting, but the saving accrues across the whole year, and you also avoid the small monthly admin of approving each invoice.
To find out whether annual billing currently carries a discount, and how much, check your plan on the [Noiz website](https://www.noiz.co.za). If you want to move an existing service from monthly to annual, ask Noiz support to change your billing cycle for you.
### Pay with cryptocurrency
Noiz accepts cryptocurrency payments in the client area, alongside card and bank transfer. Some clients prefer crypto for its privacy and its peer-to-peer, borderless nature. From time to time Noiz offers an incentive for settling invoices with cryptocurrency, so it is worth checking whether a discount currently applies to your account.
If you are new to it, see [Pay with Monero (XMR)](/billing/pay-with-monero-xmr/) for a step-by-step walk-through of paying a Noiz invoice with privacy-focused digital cash. For vendor-neutral background on how Monero works, [getmonero.org](https://getmonero.org) is a good place to start. Contact Noiz support to confirm which currencies are accepted and whether any promotion is running.
## A way to make money from your hosting
### Join the affiliate or referral programme
If Noiz is running an affiliate or referral programme, you can earn credit, or even income, by recommending Noiz to other people. The usual pattern is that you receive a unique link to share with friends, family, clients, or on your website and social media. When someone signs up for a hosting account through your link, you earn a share of what they spend each month. Those earnings are typically added to your account as hosting credit, or paid out to you once they reach a set threshold.
Referral terms and rates change over time, so check the current programme details on the [Noiz website](https://www.noiz.co.za), or ask support how to get your referral link.
## Putting it together
Used together, an annual billing cycle, a payment method that carries an incentive, and referral credit can meaningfully reduce your yearly hosting cost. An active referrer can eventually cover much, or even all, of their own hosting, and the effect compounds if you run several services with Noiz. The right combination depends on the offers Noiz has in place at the time, so treat this guide as a starting point rather than a fixed price list.
Even if paying up front is not comfortable right now, it can still be worth comparing the total cost of the options: if the combined saving is larger than the cost of spreading the payment, the maths can work in your favour. When in doubt, run the numbers for your own plan before you commit.
## Confirm the current offers
To check the latest pricing and promotions, change your billing cycle, set up cryptocurrency payments, or join a referral programme, see the [Noiz website](https://www.noiz.co.za) or get in touch with the Noiz support team. If you are on a managed plan, support can make most of these changes on your behalf.
# Pay with Monero (XMR)
Source: https://docs.noiz.ie/billing/pay-with-monero-xmr/
Monero is private digital cash: fast, low-cost payments anywhere in the world, with every transaction untraceable by design. Unlike Bitcoin, Monero hides the sender, recipient, and amount by default, making it ideal for those who value financial privacy.
---
## Getting Started
### 1. Set Up a Wallet
Before you can pay with Monero, you need a wallet. Noiz recommends [Cake Wallet](https://cakewallet.com/), a free, open-source mobile wallet available for iOS and Android. Download it and follow the in-app instructions to create your Monero wallet.
### 2. Acquire Monero
The simplest method is to create a Bitcoin wallet within Cake Wallet, purchase Bitcoin using Apple Pay or a card, then exchange it for Monero directly in the app.
Alternatively, you can buy Monero directly from exchanges that support it, or receive it from another Monero user.
### 3. Pay Your Invoice
Select **"Crypto Payments"** as your payment method on any outstanding invoice. You'll see a wallet address and the XMR amount due. In Cake Wallet, tap **Send**, paste the address, enter the amount, and confirm.
---
## The Noiz Monero Address
Send XMR payments to the following address:
```
44BtMn9izxH8mK2yFbSdY6Di7TNobkLbnHdZ6gZQjukCME5vsNhtPRtH4TcVkDHKHLhSpAJbsjv8gCdYuSZVMpXgMkUC1hV
```
**After sending payment:** please email the **Transaction ID** and **Invoice Number** to [support@noiz.co.za](mailto:support@noiz.co.za) so that Noiz can confirm receipt and apply it to your account.
---
## Why Monero?
- **Private by default**: sender, recipient, and amount are hidden on every transaction
- **Fast settlement**: transactions confirm in minutes, not hours
- **Low fees**: a fraction of a cent regardless of amount
- **Borderless**: works anywhere, no bank required
---
For more information about Monero, visit [getmonero.org](https://www.getmonero.org/).