cPanelOps · Hosting guides for site operators
cPanelOpsv2.2.0
Plain-English cPanel help from the team behind FirstResponderHost
26 guides live
CpanelOps / PageOps

Home › Guides

Reliability

Backups on cPanel hosting, and how to test a restore

What your host's backup does and does not cover, which cPanel backups you can restore yourself, and a safe way to prove one works.

A backup you have never restored is a guess. Plenty of site owners find out during an emergency that the host's copy is a week old, or that the file they downloaded cannot be restored without a support ticket. Fifteen minutes now removes both surprises.

Know what your host keeps

Most cPanel hosts run their own backups, but the details differ: how often, how many days are kept, whether you can restore them yourself, and whether a restore costs money. Read the plan details or ask. Treat the answer as a convenience, not as your only copy. The host's backup usually lives with the same company, and often in the same data centre, as the site it protects.

The backups you can make yourself

cPanel's Backup page offers two kinds, and the difference matters.

  • Full account backup. One archive of everything: files, databases, email, settings. It is the right thing to keep off-site and the right thing to hand to a new host when you move. You cannot restore it yourself through cPanel; a host has to do that from the server side.
  • Partial backups. The home directory (your files), each MySQL database, and email forwarders and filters, each as its own download. These you can restore yourself from the same page.

For a typical website the two partial backups that matter are the home directory and the database. Download both on the same day so they match.

Keep a copy somewhere else

A sound, simple routine is three copies in two places: the live site, a copy at the host, and a copy that is not at the host, such as your own computer or a cloud drive. Date the files in their names and keep a few generations, because a problem is not always noticed the day it happens.

AT YOUR HOSTING COMPANY1. The live sitefiles + database2. Host's backuptheir schedule, their rulesSOMEWHERE ELSE3. Your copycomputer or cloud drivedownload
Three copies, two places. The third copy is the one that survives a problem at the host.

Prove it works: a restore test that cannot hurt the live site

  1. Create a subdomain such as restore-test.yourdomain.com with its own folder.
  2. Upload the files from your backup into that folder.
  3. Create a new, empty database and database user with MySQL Database Wizard.
  4. Open phpMyAdmin, select the new database, and import the database backup file.
  5. Edit the site's configuration file in the test folder so it uses the new database name, user and password.
  6. Open the subdomain. If the site depends on its address, as WordPress does, update the address in the test database first.

If the test copy comes up and looks right, you know three things: the backup is complete, you know the steps, and you know roughly how long a real restore would take. Password-protect the test folder while it exists and delete it, and its database, when you are done.

What to check in the test copy

  • Recent content is there, not just old pages.
  • Images and uploads load, which shows the files and the database are from the same day.
  • You can sign in to the admin area.
  • Special characters and emoji in text survived the trip. If they turned into question marks, the export or import used the wrong character set.

Making it routine

Pick a schedule you will actually keep. For a site that changes daily, a weekly download and a restore test every few months is a reasonable floor. Always take a fresh backup immediately before anything risky: updating a content system, changing PHP version, editing .htaccess, or moving hosts.

If you automate database exports with a scheduled job, do not put the database password in the command itself, where it can show up in logs and emails. Store it in a .my.cnf file in your home directory with permissions set to 600, and the export tool will read it from there.

Common questions

How big will the backup be, and will it count against my disk space?

A backup generated in cPanel is saved into your home directory before you download it, so for a moment you need free space roughly equal to the site's size. Download it and then delete it from the server. Leaving old backups in the account is one of the most common reasons an account runs out of space.

Is a backup plugin enough?

A plugin that sends copies to cloud storage is a good third copy. A plugin that stores backups inside the site's own folder is not: those files are lost along with the site, and if the folder is public they can be downloaded by anyone who guesses the name.

How long should I keep old backups?

Long enough to reach back past a problem you did not notice straight away. A reasonable pattern for a small site is the last few weekly copies plus one from each of the last few months.

Do I need to back up email as well?

If mail for your domain is stored on the hosting account, yes. It is included in a full account backup and in the home directory backup. If your mail is with a separate provider, it is not on the hosting account at all.

Spotted a mistake, or a step that has changed?

cPanel's screens differ a little between versions and hosts. Tell us at info@firstresponderhost.com and we will correct the guide.

More guides