To start a web hosting business with WHMCS, choose a model you can run yourself (a reseller plan, a VPS or a dedicated server), register the business and publish your terms, connect a control panel to WHMCS, build products and automation, then push a paid test order through payment and provisioning before you sell anything. This guide follows the order I build these setups in.
Last reviewed 10 October 2026. Disclosure: I sell hosting business setup and WHMCS installation as a service, so I am not a neutral source. I am also CTO at ElySpace, a hosting company, and founder of WHMCSPilot.com, which sells WHMCS modules and themes. I name no hosting provider and quote no third-party prices here. I work mainly with cPanel and WHM, so the panel steps assume them.
Which model should you start with: a reseller plan, a VPS or a dedicated server?
Start with the model whose failures you can handle on your own. WHMCS can bill and provision all three, so the choice comes down to how much of the server becomes your job and which problem reaches you first.
| Model | Who it suits | What you manage | What breaks first |
|---|---|---|---|
| Reseller plan | A first-time owner, designer or agency that wants to sell accounts without running a server | Customers, packages, prices, billing and first-line support. The upstream provider runs the machine. | The upstream's limits: a CPU, I/O or account cap you cannot raise, or one abusive customer who puts the whole reseller account at risk. |
| VPS | An owner who can administer Linux, or pays someone who can, and wants root access | All of the above, plus the operating system, the panel and its license, the firewall, mail reputation and backups | Memory and disk I/O on an undersized machine, then mail reputation after the first hacked mailbox. |
| Dedicated server | A host with steady paying customers and many accounts that need predictable resources | All of the above, plus hardware faults (through the data center) and capacity planning | The single machine. One failed disk or bad update reaches every customer at once, and a full restore is slow. |
For a first business I usually suggest a reseller plan or one VPS, then moving up once customers are paying. A normal shared hosting account is not on the list, because it cannot create separate customer accounts. The reseller route has its own walkthrough in reseller hosting with WHMCS, and my start a hosting business page compares the business trade-offs.
What legal and money basics do you need before you sell hosting?
You need a business that is allowed to trade, published policies and a payment account that accepts hosting. The requirements depend on your country, and this is not legal advice. In practice you register the business in whatever form your country uses, publish terms of service, an acceptable use policy and a privacy policy, and open a payment account in the business name. I can speak only to the parts that touch the systems. The terms must say when an unpaid service is suspended and when its data is deleted, because WHMCS will do both on schedule. The acceptable use policy must let you suspend an abusive account at once. The privacy policy must cover the customer data that WHMCS and the servers hold. Payment providers often review a new business before releasing funds, so apply early. Tax on sales abroad is a question for an accountant.
What technical stack does a hosting business need?
A hosting business needs seven parts: a domain with nameservers, a control panel, WHMCS, a payment gateway, a support desk, backups and monitoring.
- Domain and nameservers. Register the brand domain in a registrar account you own. Decide now whether customers will use nameservers under your name, such as
ns1.yourbrand.com, because changing them later means updating every customer domain. - Control panel. The panel creates the hosting accounts that WHMCS sells. A reseller plan includes it. On your own VPS or dedicated server you buy a license tied to the server's IP address and install the panel on a clean, supported operating system. See cPanel and WHM setup for the first-day settings.
- WHMCS license and install. WHMCS is the billing and automation system: orders, invoices, payments, provisioning and tickets. It needs a license key, a supported PHP version with ionCube Loader and a MySQL database. Where the budget allows, I keep it off the server that hosts customer sites, so billing and support stay reachable during a hosting outage. The install is in how to set up WHMCS.
- Payment gateway. Pick one that operates in your country and accepts hosting businesses. Use hosted checkout or stored-card tokens, so card numbers never sit on your server.
- Support desk. WHMCS has a ticket system built in. Create departments and connect the support mailbox, so email becomes tickets.
- Backups. Two separate jobs: customer accounts on the hosting server, and the WHMCS database plus
configuration.php. Each needs a copy off the server it protects. - Monitoring. An external check on the website, the client area and the panel login, plus an alert when the WHMCS cron stops.
How do you set up WHMCS for a hosting business, in order?
Set it up in six steps: products and pricing, the server connection, automation and the cron, email templates, tax, then a paid test order. Menu names follow the current WHMCS admin area; check the WHMCS documentation if yours differs.
- Products and pricing. Under Configuration > System Settings > Products/Services, create a product group and one product per plan, with the type Shared Hosting. Price every billing cycle you will sell and leave the others disabled. Three plans are enough to launch.
- Server connection and package mapping. Create an API token in WHM, add the server under Configuration > System Settings > Servers with the type cPanel, and click Test Connection. Then open each product's Module Settings tab, choose the cPanel module and select the WHM package. The name must match WHM exactly, and on a reseller account it carries your username as a prefix. On the same tab I choose to set the product up as soon as the first payment is received, so unpaid orders never get an account.
- Automation settings and the cron. Open Configuration > System Settings > Automation Settings, copy the cron command shown there and schedule it every five minutes. It runs
crons/cron.php, and invoices, reminders, suspensions and terminations all stop without it. Then set the suspension and termination days to match your terms. - Email templates. In Configuration > System Settings > Email Templates, edit the welcome email your products use, so it gives your nameservers, the panel login address and how to reach support. Read the invoice and overdue notices as a customer would. Send WHMCS mail through authenticated SMTP, not PHP mail.
- Tax settings. Under Configuration > System Settings > Tax Configuration, choose whether prices include tax and add a rule for each country or state where you must charge it. WHMCS applies the rules you enter and cannot know which ones apply to you, so get the rates from your accountant.
- A full test order. Order from the public order form as a new customer and pay, in the gateway's test mode or with a small real payment that you refund. Confirm that the invoice shows Paid, the service shows Active, the account exists in WHM, the welcome email reaches the inbox and the panel login works. Then suspend, unsuspend and terminate the test service. If provisioning fails, the Module Log (with logging switched on) shows what the panel answered.
I also do this as a service: WHMCS installation and setup.
What should you prepare before the first customer?
Prepare four things that have nothing to do with selling: an abuse process, a restore you have actually run, mail authentication records and a status page.
- Abuse process. Create an
abuse@mailbox that a person reads, and write the steps down: confirm the report, suspend the account, tell the customer, record what happened. Decide who does this when you are asleep. - Backup restore test. Restore one hosting account to a scratch location and time it. Restore the WHMCS database to a test copy too, with its
configuration.php, because that file holds the encryption hash for the stored data. - Mail deliverability records. The server IP needs a reverse DNS (PTR) record that matches its hostname, and your brand domain needs SPF, DKIM and DMARC records. Send a test message to a large mailbox provider and read the headers for
spf=passanddkim=pass. When welcome emails land in spam, customers think the order failed. - Status page. Host it somewhere other than your own servers, so you can post an update while they are down.
What does it cost to start a web hosting business?
It costs a set of monthly bills, a few one-off items and several costs that grow with every customer. I give no amounts, because they differ by country, provider and plan.
| Cost bucket | Paid | Grows with customers? | Notes |
|---|---|---|---|
| Business registration and policy documents | Once, plus any renewals your country requires | No | Varies by country. Include a lawyer's review of your terms. |
| Brand domain | Yearly | No | Keep it in a registrar account you own. |
| Reseller plan, VPS or dedicated server | Monthly | In steps | You move up a plan or add a server when the current one fills. |
| Control panel license | Monthly, on your own server only | Yes | cPanel prices its licenses by the number of accounts on the server. |
| WHMCS license | Monthly | Yes | Tiered by active clients. Prices are on whmcs.com, and my WHMCS pricing guide explains the tiers. |
| Payment gateway fees | Per transaction | Yes | Taken from each payment. Disputes usually carry a separate fee. |
| Registrar balance, if you sell domains | Prepaid and topped up | Yes | Registrations fail when the balance runs out. |
| Off-server backup storage | Monthly | Yes | Grows with disk used and retention. |
| Monitoring and status page | Monthly | Hardly | Usually priced by the number of checks. |
| Setup work | Once | No | Your time or a contractor's. Mine is a fixed quote per scope, or $55-$65 per hour. |
| Support time | Ongoing | Yes | The bucket most plans forget. It costs hours, even when they are yours. |
To price a plan, add up the monthly buckets, divide the shared ones by the number of accounts you can really host, then add the per-customer ones and support time. If the price does not cover that, change it before launch, not after.
Which ten mistakes do I see most in new hosting businesses?
These ten come up again and again in the setups I am asked to repair.
- Prices copied from a large competitor. Their costs are not yours.
- "Unlimited" plans with no written limits. Put inode, CPU and hourly mail limits in the package and the terms.
- A cron that is not running. Nothing looks wrong until renewal day, when no invoices go out.
- Package names that do not match. The first real order is paid and then fails to provision.
- Accounts created before payment. Fraudulent orders get working hosting and use it to send spam.
- A gateway tested only in sandbox. Nobody checks the live callback, so a customer pays and the invoice stays unpaid.
- Backups that were never restored. A job that reports success is not a restore.
- Billing on the same server as customers, with no outside copy. One outage takes down the sites, the support desk and the place you would announce it.
- No reverse DNS, SPF or DKIM. Welcome emails and invoices land in spam from the first day.
- Terms that disagree with the automation settings. WHMCS terminates on one day while the terms promise another, and the data is already gone.
What should be on your launch checklist?
Launch when every line below is true. Nothing on this list gets easier with customers watching.
- The business is registered and the payment account is approved for live payments.
- Terms of service, acceptable use policy and privacy policy are published and linked from the order form.
- Nameservers resolve, and the website, client area and panel load over HTTPS.
- WHMCS is licensed, the
installfolder is deleted and admin logins use two-factor authentication. - The cron has run on schedule for a day, with no cron warning in System Health.
- A paid test order created an account with no manual step, and suspend, unsuspend and terminate work.
- Welcome, invoice and overdue emails read correctly and reach the inbox.
- Tax rules match what your accountant told you.
- One hosting account and the WHMCS database have been restored from backup.
- The abuse mailbox, status page and external monitoring are live, and alerts reach a named person.
- Test customers, orders and invoices are removed.
What should you do next?
Choose the model, then start the business registration and the payment account application, because those two wait on other people. For a second opinion on the model, the servers or the mail setup before you spend money, see my work as a web hosting expert. To have the whole stack built, tested and documented, see hosting business setup. The scoping call is free and takes about 30 minutes.