cPanel and WHM
cPanel and WHM Setup Service
I install and configure cPanel and WHM on a fresh VPS or dedicated server, from license activation and hostname to mail authentication, AutoSSL, PHP, backups and the WHMCS connection. It is for hosting owners and agencies who want a server ready for real accounts, with every setting written down.
By Shahid Malla, WHMCS developer and hosting infrastructure engineer · Updated
What does a cPanel and WHM setup include?
A cPanel and WHM setup turns a blank Linux server into a hosting server that can safely hold customer accounts. The install is the short part. The value is in the choices made afterwards.
cPanel expects a clean machine: a supported operating system with nothing else serving websites or mail, a static IP address, a fully qualified hostname and a license bound to that IP. I verify all of that first. Then I run the official installer inside screen or tmux, so a dropped SSH session cannot stop it halfway, and finish the WHM setup wizard.
Which settings do I change on the first day, and why?
I change about a dozen settings on day one, because each is awkward to fix once customers depend on it. The table gives the reason for each.
| Setting | Where | Why it matters |
|---|---|---|
| Hostname | WHM, Networking Setup | It must be a fully qualified name that resolves to the server IP and is not a domain you host. Mail greetings and the certificates for panel, mail and web services all depend on it. |
| Reverse DNS | Your provider, not WHM | The PTR record should match the hostname. Receiving mail servers compare the two, and a mismatch pushes mail toward the spam folder. |
| Nameservers | WHM, Basic WebHost Manager Setup | ns1 and ns2 need glue records at the registrar before customer domains can use them. |
| Update preferences | WHM, Update Preferences | A stable or long-term-support release tier with automatic updates means security fixes arrive without a manual step. |
| Packages and feature lists | WHM, Packages | Packages set disk, inode, mail and database limits. Feature lists set what each plan can see. WHMCS products must name the package exactly. |
| AutoSSL | WHM, Manage AutoSSL | It issues and renews certificates for customer domains and server services, but each domain's validation request must reach this server. |
| Mail limits | WHM, Tweak Settings and Exim Configuration Manager | Caps on hourly mail and on failed deliveries per domain limit the damage from one hijacked mailbox. |
| PHP | EasyApache 4 and MultiPHP Manager | This decides which PHP versions exist, that PHP-FPM runs them, and which extensions load. |
| ModSecurity | WHM, Security Center | A rule set blocks common exploit probes. Rules cause false positives, so I read the audit log after a few days. |
| Backups | WHM, Backup Configuration | Backups enabled, retention set, and a remote destination added and validated. |
| Security Advisor and login protection | WHM, Security Center | A quick baseline report, plus brute-force protection on panel, SSH and mail logins. |
I do not name a firewall product here on purpose. We choose one together after I see what you already run and what your provider offers. Whichever it is, I close every port the server does not need and, unless resellers must reach WHM, limit port 2087 to known addresses.
How is mail set up so it reaches the inbox?
Mail on cPanel is sent by Exim and stored by Dovecot, and it reaches inboxes when the server proves its identity with matching PTR, SPF, DKIM and DMARC records.
cPanel publishes SPF and DKIM records for domains whose DNS it hosts, and WHM's Email Deliverability page shows whether they are valid. If DNS lives elsewhere, I give you the exact records to paste. I add DMARC at p=none first, read the reports and tighten the policy only after every legitimate sender passes. I also check the IP against public blocklists, since a new address can inherit a bad history. For testing, I send to the large mailbox providers and read the headers for spf=pass, dkim=pass and dmarc=pass. When something is wrong, exim -bpc gives the queue length and /var/log/exim_mainlog gives the reason.
How do I connect the new server to WHMCS?
You connect it by creating an API token in WHM, adding that token to the server record in WHMCS and then restricting who can reach the WHM port.
- In WHM, open Manage API Tokens and create a token with only the privileges WHMCS needs to create, suspend, unsuspend, terminate and change accounts.
- In WHMCS, add a server of type cPanel with the hostname, the token in the field WHMCS provides for it, the secure connection enabled and port 2087.
- Allow the WHMCS server's IP address through the firewall to port 2087 and keep that port closed to everyone else, apart from your own administrator addresses and any resellers who use WHM.
- Press Test Connection, then push a real order through create, suspend and terminate.
Package names must match between WHM and the WHMCS product, or provisioning fails because the package cannot be found. The WHMCS side is covered in WHMCS installation and setup, and custom automation is under WHMCS API integration.
How do reseller accounts and resource limits work?
A reseller account is a WHM user who creates and manages their own cPanel accounts within limits and privileges that you set. I build reseller packages with an account cap, a disk and bandwidth allowance and a privilege (ACL) list that exposes only what a reseller needs.
Each customer account is capped by its package, and per-domain PHP-FPM settings in MultiPHP Manager, such as maximum children, limit how much CPU and memory one site can claim. Plain cPanel cannot enforce hard CPU, memory and disk I/O limits per account. A commercial isolation product such as CloudLinux is the usual add-on, and whether it is worth the license depends on how many accounts share the machine.
What I leave alone on a cPanel server
I leave generated configuration files alone, I do not install unlicensed software and I do not touch hardware. cPanel regenerates files such as /etc/exim.conf on update, so hand edits vanish. Custom Exim rules go into the Exim Configuration Manager or /etc/exim.conf.local instead. I do not use unlicensed cPanel or nulled WHMCS, and I do not buy your license for you. After the two weeks of support, running the server is your job unless we agree otherwise.
One disclosure: I am CTO at ElySpace, a hosting company, Technical Lead at Fada.cloud and a backend developer for Nuco Cloud, so weigh my views on panels and add-ons with that in mind. A fixed quote follows the scoping call, or I bill $55 to $65 per hour. Natural next steps are server hardening, monitoring and the wider server setup overview.
Who this is for
- Hosting startups building their first cPanel server
- Resellers moving from a shared reseller plan to their own VPS
- Agencies consolidating client sites onto one managed server
- Owners whose existing install was done quickly and never reviewed
What is included
- Pre-install checks on operating system, static IP, clean system, open ports and license
- cPanel installation and WHM initial setup with each choice documented
- Hostname, reverse DNS check, nameservers and glue-record guidance
- Packages, feature lists, reseller accounts and privilege lists
- AutoSSL, Exim and Dovecot settings, SPF, DKIM and DMARC
- EasyApache profile, MultiPHP with PHP-FPM, and ModSecurity
- Backup configuration with an off-site destination and a test restore
- WHMCS server connection through an API token with an IP allow-list
How the work runs
-
1
Check
Before installing I confirm the operating system, IP address, hostname and open ports, because cPanel expects a clean machine and a license bound to the server IP.
-
2
Install
I run the installer inside a terminal multiplexer so a dropped connection cannot kill it, then complete the WHM setup wizard and activate the license.
-
3
Configure
I work through the first-day settings in the table below and record each choice and its reason in your handover notes.
-
4
Connect and test
I link the server to WHMCS and run a test account through create, suspend and terminate. I also send test mail and restore a backup.
-
5
Hand over
You receive the written notes, a daily update while work runs, and two weeks of support afterwards for anything that surfaces.
Frequently asked questions
How long does a cPanel and WHM setup take?
A single fresh server usually takes one to two working days, including tests of mail, SSL and the WHMCS connection. The installer itself runs largely on its own, so most of the time goes into configuration and testing. Servers with many packages, reseller tiers or unusual mail needs take longer, and I give you a date after scoping.
Do I need to buy the cPanel license first?
Yes. A cPanel license is bound to the server's IP address and is bought from cPanel or an authorized partner. A short trial exists for testing, but production needs a paid license. I check the IP and activation with you before installing, so the license is ready when the installer finishes.
Can you install cPanel on a server that already hosts websites?
I advise against it. The installer expects a clean operating system, and an existing web and mail stack can conflict with it. The safer path is a fresh server, then a move of the sites using the Transfer Tool. If the old server must stay, I review it and tell you the risks first.
Will you set up the firewall?
Yes. I review which ports the server exposes, close the ones it does not need and restrict WHM to known addresses where resellers do not need it. The firewall tool is a choice we make together, based on what you already run and what your provider offers. I do not push a single product.
Why does mail from a new cPanel server go to spam?
The usual causes are a reverse DNS record that does not match the hostname, missing or failing SPF and DKIM, no DMARC record, or an IP address with a poor history. I check each of these, test delivery to the main mailbox providers and read the message headers to confirm the results.
Will the server work with my existing WHMCS?
Yes. I add the server to WHMCS with an API token, restrict WHM to the WHMCS server's IP address and run a real create, suspend and terminate cycle. If your WHMCS has custom provisioning code or hooks, I review them first so they behave correctly against the new server.
Related services
-
WHMCS Installation and Setup Service
I install and configure WHMCS so it can take real orders: requirements, cron, SSL, cPanel link, billing rules,...
-
Server Hardening Service for Linux and cPanel Servers
I harden Linux and cPanel servers with SSH keys, firewall review, patching, PHP isolation and protected backup...
-
cPanel Server Migration and Backup Setup
I move cPanel accounts, mail and DNS to a new server with a tested cutover, then set up local and off-site bac...
-
Server Monitoring and Performance Optimization
I set up server monitoring with alerts that reach the right person, then tune the web server, PHP-FPM and MySQ...
Ready to talk about your project?
Send the details and I reply within one business day with questions, an estimate and a plan.