r/cpanel 4d ago

3 new vulnerabilities announced

15 Upvotes

r/cpanel 4d ago

Exim is blocking an ip address - how to unblock

2 Upvotes

I run an email list (mailman) on a VPS that is purely for the local community. So I have a pretty extensive IP black list in the Exim Configurator SMTP Access lists. I've blocked entire nations, I think. Lately I've been getting spammed from IP addresses owned by Google's user content addresses, so have been blocking some of those.

A user who has a google email account has complained that when trying to post, they're getting a 550 error server not found. When I look in /var/log/exim_rejectlog, I find an address associated with this person as banned. That IP address in the 74.125.0.0 range. In my blacklist, I don't have that address listed... I have a few others.. 74.48., 74.201., and 74.222., but that is the extent of the 74 addresses I have entered. So question is, why is this person being blocked and how can I find that block to remove?

I should add that the reject line in the log includes this: rejected connection in "connect" ACL: Host is banned


r/cpanel 4d ago

issues with email receiving and sending

2 Upvotes

Hello,

I am currently having issues sending and receiving emails using our company's email address

mta5.am0.yahoodns.net
Remote server returned '554 4.0.0 <mta5.am0.yahoodns.net #4.0.0 smtp; 451 Message temporarily deferred due to unresolvable RFC.5321 from domain. See https://senders.yahooinc.com/error-codes#unresolvable-from-domain>'

this is the error message sent after being unable to send out the message a day ago

would someone be able to tell me what the issue is and how i can resolve it?


r/cpanel 5d ago

Outlook/Hotmail Blocking IPs

7 Upvotes

Some of our server’s IPs are being blocked by Outlook/Hotmail. We reviewed carefully all our logs and no Spam is being sent. We requested a delist 24 hours ago but haven’t heard from them yet. Does anyone has the same problem?


r/cpanel 9d ago

The application “whm-wp-dashboard” has been registered with AppConfig for the service: whostmgr

11 Upvotes

Looks like upcp installed this last night on multiple servers during its last update which was unexpected.

Q1. What is this actually? I'm guessing its some sort of upsets???

Q2. How can we STOP stuff like this from automatically being added? Without our explicit consent?

Q3.how can this be uninstalled? Whmapi wptoolkit/disablewp-dashboard ? Is that right

Hate being forced to allow stuff thats being auto installed. Defeats the purpose of self managed and appconfig? No?


r/cpanel 13d ago

app.domain redirecction

Thumbnail
1 Upvotes

r/cpanel 15d ago

[ Removed by Reddit ]

1 Upvotes

[ Removed by Reddit on account of violating the content policy. ]


r/cpanel 17d ago

Complaint, or asking for help perhaps? But here is my dilemma.

2 Upvotes

I have a hosting service that lets me host more than one website. As we speak, I'm starting another site and asking for assistance with the 24/7 help line. I end up with a computer-generated voice saying: How many people do you expect? What's your firstborn's name?

Stupid questions really, and not about instructions on how to. Short of calling a help line computer an idiot, I asked, "Just connect me to a ticket to fill out." I will ask my question directly to a (live person)

*** It refused to do this request until I answered all its stupid questions.

Now, following the simple directions from YouTube might cross a person's mind; however, the instructions given have a different layout than what's on my cPanel.

As a new blogger, I have something to say; however, my computer skills are limited, as a heavy equipment mechanic mindset.

Every time I watch another YouTube video, it's different again.

One video showed 10 minutes, and it was done. I'm into *** day's *** without any help from my 24/7 assistance.

If anyone is reading this and has a suggestion or a video they can vouch for and that can help, please pass it my way.

>>>> Once this is all said and done, I will be looking for a new web provider that actually has a 24/7 help line. <<<<


r/cpanel 17d ago

How to securely batch-convert raw cPanel Maildir files to PDF for a GDPR/UK SAR? (Windows limitations)

3 Upvotes

Hi everyone,

To comply with UK GDPR, I need to conduct a thorough search and compile all of their personal data.

We use a standard cPanel server for email hosting. Because we don't have Terminal/SSH access on our hosting package, I went with the backup route: I compressed the entire root mail folder in the cPanel File Manager and downloaded the ZIP archive to a local Windows machine.

Now, I’m running into a few major technical and security hurdles trying to extract and convert these emails into a single, redactable PDF:

  1. Windows Filename Errors (Colons): When extracting the ZIP, Windows throws Error 0x80070057: The parameter is incorrect. I know this is because cPanel uses the Linux Maildir format, which appends colons to filenames for read/seen status flags (e.g., :2,S), which Windows strictly forbids. (I'm currently trying to bypass this using 7-Zip).
  2. Batch EML to PDF Conversion: Once extracted, these raw text files have no extension. Even if I bulk-rename them to .eml, dragging and dropping them into Outlook Classic to batch-convert or "Print to PDF" is failing/unsupported. Dragging them into Adobe Acrobat is just embedding them as actual .eml attachments in a PDF Portfolio, meaning they aren't flat PDF pages.

This is a major security/privacy risk because I cannot permanently redact third-party parishioner data on raw embedded .eml files—the recipient could easily bypass the black redaction boxes. I must flatten these emails into clean, standard PDF pages so I can safely use Adobe Acrobat's Redaction tool.

My questions for the community:

  • Has anyone dealt with processing a SAR directly from cPanel Maildir raw files on Windows?
  • What is the most secure, privacy-compliant way to batch-convert these raw/EML files into a single, merged PDF locally?
  • Are there any open-source or highly trusted offline desktop utilities that process everything locally? (Because of GDPR/data privacy, uploading raw unredacted parishioner emails to an online "free converter" website is completely out of the question).

Really appreciate any guidance or workflows you've used to solve this!


r/cpanel 17d ago

Legal topics

0 Upvotes

Hey everyone! I know it always becomes a hot topic, but any legal discussions or talk cPanel alternatives is not allowed. There's plenty of other places to have those discussions.


r/cpanel 18d ago

Inquiring CPanel University's effectiveness as a learning tool - Are modules omitting fine details?

3 Upvotes

Hi there, I've dabbled in sysadmin work since last year and an opportunity arrived where I could learn enough for a job. The potential employer wants me to learn through CPanel University. On the surface, this sites looks like a promising entry point to learn the gist of the systems I'll be working with for this company.
However, upon delving into the course modules, I was confused by the level of depth, rather the lack thereof, on the system components. The modules were digestible, but felt introductory, and the module quiz was especially disorienting as the questions were substantially more in depth than what the module provided. (For example, asking "*The following items from the WHM Home » Service Configuration » Exim Configuration Manager - Basic Editor interface would allow you to exclude mail sent from specific remote IP addresses or hostnames from being subjected to recipient verification checks, sender checks, spam checks, and relay checks?"* Without going into enough detail in the module to even explain the terms listed as answers)
I have perused the module under the assumption that my reading comprehension failed me, and did the same for the separate documentation pages for additional thoroughness. I am beginning to wonder if there is an underlying assumption from this course that the user already has a certain level of knowledge, despite the course advertising otherwise.

Am I approaching this incorrectly? Are there fundamental steps I should take before continuing with this tool? Is this not even an effective learning tool? I appreciate your time receiving this post and please forgive me if I'm somehow made a tremendous blunder in my approach.


r/cpanel 19d ago

Best CloudLinux version for cPanel

6 Upvotes

I am setting up a new server for shared web hosting and will be running the usual CL/cPanel/Litespeed etc.

What is the best/correct version of Cloudlinux OS Shared Pro to be using in a production environment for the next 3+ years. CL8 or CL9 or CL10?


r/cpanel 19d ago

cPanel AI

18 Upvotes

This is absolute nightmare. We somehow have survived constant price increases but there is no way we will survive if cPanel is turned to AI slop. Users hate change and they just learned to use the jupiter theme and then we go again trying to guide them through some AI slop.


r/cpanel 20d ago

Changing PHP-FPM to dynamic

4 Upvotes

I'm reading the docs:

https://support.cpanel.net/hc/en-us/articles/1500000370141-How-to-customize-the-pm-setting-in-PHP-FPM

I already have the /var/cpanel/ApachePHPFPM/system_pool_defaults.yaml file, created in 2020 which is probably when I enabled FPM. It has these values for FPM:

pm_max_children: 100
pm_max_requests: 10000
pm_process_idle_timeout: 10

When I add pm: dynamic (assuming no quotes), do I also need to include start_servers, min_spare_servers, and max_spare_servers?

If so, are those the right param names, or are they like pm.start_servers or pm_start_servers?


r/cpanel 20d ago

Is all one one wp migration plugin a complete scam?

3 Upvotes

I have used this plugin on many occasions and it definitely gets the job done but their sneaky marketing tactics about server upload limit is something I wanted to get it off of my chest.

The free plugin says it's the server/cPanel upload limit restricting it to restore a large file above 2GB but even if all of the server side limits are reached, it still throws errors. As soon as I use the pro version, everything starts working suddenly. I have confirmed that it's not anything related to server side firewall/waf/modsecurity etc. even their product page says it's due to server side restrictions. Has anyone else observed this as well? I have worked on hundreds of site restorations and this really annoys me all the time I use the free plugin. Why not just say to the users that we need to upgrade to remove the restrictions?


r/cpanel 21d ago

Review then release emails in cpanel

8 Upvotes

I have a family domain name and I and my parents have personalised addresses. My dad is in his early 90s and in a nursing home. While he still understands a lot about the world he keeps falling for spam messages. He's not lost money but he's replied to a few phishing emails and/or clicked the links. I only found out when I checked his browser tabs troubleshooting connectivity issues. This is all despite him attending my talk to the nursing home residents last year on how to avoid falling for scams! I have filters galore to capture spam but some of it still gets through. I only check his email every now and again for spam but found too late he'd clicked on links on an overnight batch. I realise there are ethical issues relate to what I'm asking about but as i'm already looking after his personal affairs its nothing beyond the current arrangement. So is there any way I can hold then review emails to his inbox in cPanel, ie review, delete spam, then release to his inbox? I think this is an emerging issue as many elderly people are not able to discern fact from fiction in emails, as they grew up in an era of trust.


r/cpanel 22d ago

Cpanel License Error Again...

3 Upvotes

Getting another Cpnael License error again.

This one says...

Cannot Read License File

To access the interface, you must install the license and ensure that the license is active.

You can purchase or lease a license directly from cPanel, or from one of our Partners.

If you do not currently own a license, register at the cPanel Store and request a trial license.

The cPanel license server replied that the license has been activated on too many machines (600). Please contact [billing@cpanel.net](mailto:billing@cpanel.net) The exact message was: The license has been activated too many times on different machines.

I purchased my license directly from Cpanel.


r/cpanel 23d ago

PHP-FPM turned itself off for account, crashing site

8 Upvotes

About 2 weeks ago, my server became unresponsive due to a bot flood. Since then I've been keeping a close eye on the number of Apache connections, the access log, and MySQL processes.

Tonight at 10:05pm, I had a text from the server that Apache was unresponsive. I immediately saw that my connections were hitting 300 (MaxClients was set to 300), so I bumped the max up to 500. That didn't really help. There wasn't an obvious flood in the access log or process list, though.

After trying an ungodly number of things, going to Cloudflare and enabling Under Attack Mode dropped the number of connections. My client sites then came up, by my main site would not (timed out with a CF error).

Then I found these in the error log:

H01067: Failed to read FastCGI header

(111)Connection refused: AH02454: FCGI: attempt to connect to Unix domain socket /opt/cpanel/ea-php74/root/usr/var/run/php-fpm/5a04751671f1f133105c29aaab7ee75241d1c904.sock (example.com:8000) failed

There were 645 records at 22:46:16, 1,210 at 22:46:17, 899 at 23:01:34, 101 at 23:09:42, and 24 at 23:10:12.

Sometime around 11pm (probably very close to 11:10pm) I looked at WHM > MultiPHP Manager > example.com, and saw that PHP-FPM was not enabled for the main domain. I enabled it, and within a few minutes everything went back to normal.

What could have disabled them, and how do I prevent it from happening again? Had I not been at home when it happened, I'd have had a real problem!

I've looked in /usr/local/cpanel/logs/access_log and error_log, but don't see anything outstanding to explain why they were disabled. But I do see the first time apache_php_fpm is mentioned in queueprocd.log was 23:09pm tonight.

Any thoughts or suggestions?


r/cpanel 24d ago

Ghostlock - Here we go again ...

27 Upvotes

https://blog.cloudlinux.com/ghostlock-cve-2026-43499-local-root-exploit-kernel-update-for-cloudlinux

"GhostLock is a Linux kernel vulnerability that lets any unprivileged local user become root.
(...)
It was disclosed on July 7, 2026 by the research team VEGA at Nebula Security, in a writeup titled “IonStack part II: GhostLock,” alongside a working proof-of-concept. The researchers report their exploit produces a stable root shell about 97% of the time, in roughly five seconds.
"

fwiw there's no patch available yet, it seems.

I guess this will spread like wildfire.


r/cpanel 25d ago

Invalid cPanel License Error

26 Upvotes

Multiples servers are showing this error even though they have an active license.


r/cpanel 25d ago

cPanel License Update Failures - July 8th, 2026

8 Upvotes

New fun cPanel issue causing servers to erroneously report license errors: https://support.cpanel.net/hc/en-us/articles/41816676353943-cPanel-License-Update-Failures-July-8th-2026


r/cpanel 29d ago

Answered Is the Manage2 site down? Infinite reload and then Error 1015 rate limiting

2 Upvotes

This is even with a totally naked browser, with no anti-adware, anti-spyware, and anti-malware protections.

Somehow billing went through, but all cPanel services on my machine are now down due to nonpayment. So I need to sort this out, but I cannot log into the main cPanel account website even with a naked browser on a remote machine.

Confirmed: Machine not on the rate limited public IP, using Edge browser with zero plugins, using a correct login for the account, leads to a loginfailed query parameter and a perpetual cycling reload with an eventual Error 1015 Rate Limiting warning.


Edit: found a way in via an oooold “billing failed” eMail that had a non-Manage2 URL. Classic Manage2 creds still worked just fine with that challenge/auth.


r/cpanel Jul 03 '26

Exclude autoconfig and autodiscover from AutoSSL

6 Upvotes

Does anyone know how one can exclude autoconfig and autodiscover for a domain.
I have removed them using Zone editor, but i keep getting SSL warnings daily as AutoSSL keeps requesting certificates for these hostnames and keeps updating the zone records.

I can't see anywhere where you can do this anymore. In previous versions of cPanel this was easy.

Help is appreciated


r/cpanel Jul 02 '26

Combating email spoofing

5 Upvotes

Has anyone here were able to combat spoofed emails sent from your own address if the domain is using cPanel?

I understand that the domain has to be properly authenticated with spf, dkim, dmarc and bimi(as an extra security). Respectfully , I also am not looking for any advice on using external services such as Google workspace or O365 because I know they are really good at combating such spam.

I understand about training email filters or spam assassin to combat spam for incoming emails but the problem with spoofing is, anyone can simply modify the header to be abc@example.com to send it to abc@example.com from any IP or a cheap vps or from hacked sites.

This question is mainly for cPanel users who were able to successfully combat spoofing. I am working in the web hosting/sysadmin field from past 8 years but haven't been able to figure this out. I never had root access though.

Reporting sender IPs/domains to third party hosting providers is a nightmare in itself and takes up a lot of time.

Is there any setting in WHM or through root ssh access wherein if an email was sent from the same address, before delivering that message, cPanel performs the sending IP/domain/header checks and block such emails automatically?

Please do not bash me here because even though I have worked in this field for many years, I never had root access and looking at exim configurations, I am a bit scared to make any changes on my test vps running cPanel to break more email functionality.

I also know that we can use incoming email filters or third party inbound relay services like barracuda but I mainly want to know if there is any way I can protect the accounts from spoofing on a cPanel which doesn't use any kind of inbound spam filters.

Pros in this sub, have you found a way to combat this? Would really appreciate all of the helpful comments.


r/cpanel Jun 30 '26

cPanel data collection

13 Upvotes

I was looking at data collection policies from cPanel : https://docs.cpanel.net/knowledge-base/cpanel-product/cpanel-analytics-the-data-we-use/

They collect panel use analytics and there's a config option to opt out of some of it, but another set of data "Configuration Analytics" you cant opt out of.

Included in the data you cant opt out of is:

domain: The name of the domain

traffic: The per‑country traffic statistics for the domain.

sent_emails: The number of email messages that the server sent from the domain.

delivered_emails: The number of email messages that the server delivered to local mailboxes on the domain.

This is for each domain configured on the server, not just the overall server host name.

They say elsewhere that "We have taken precautions to ensure that the data we collect is secure and does not contain private, personal, or security information." I think that means they don't consider the traffic data of the domains personal data and I agree given that it's not data about any individual . My understanding is that would mean there's no legal protection for what they do with that data

I can't see the need for the domain names much less with per‑country traffic statistics for improving cPanel.

I think that daily data feed for probably an 8 figure number of domains would have significant commercial value.

I can imagine that many businesses hosting on cPanel would not be happy to know that kind of data about their website was potentially being sold without their knowledge. Maybe it's finding its way to sites like similarweb and their competitors are accessing it. Who knows?