WHM and cPanel
This document outlines the best practices, technical guidelines, and usage rules for accounts hosted on servers managed through WHM and cPanel.
The objective is to maintain stability, security, and optimal performance for all hosted websites.
- General Service Usage
The server must be used strictly for lawful purposes and for the normal operation of websites, email services, and domain-related applications.
The following activities are strictly prohibited:
- Hosting illegal content
- Conducting cyberattacks
- Distributing malware or malicious files
- Engaging in fraudulent activities
- Running cryptocurrency mining processes
- Using scripts that negatively impact server performance
If an account poses a risk to overall system stability, it may be temporarily limited while the issue is being resolved.
- Email Account Usage
Permitted Use
Email accounts may be used for:
- Legitimate business or personal communication
- Sending information to clients who have provided consent
- Access via Webmail or email clients such as Outlook, Thunderbird, or mobile devices
Prohibited Use
To protect the server’s IP reputation, the following is not allowed:
- Sending unsolicited bulk email (SPAM)
- Using purchased mailing lists
- Uncontrolled automated email sending
- Phishing or distribution of malicious links
- Sharing SMTP credentials with third parties without supervision
Abuse of email services may result in temporary suspension of outgoing mail functionality.
Recommended Best Practices
- Properly configure SPF, DKIM, and DMARC records
- Use strong passwords
- Avoid reusing passwords across multiple services
- Respect hourly sending limits
- cPanel Security
Each user is responsible for maintaining the security of their account.
It is recommended to:
- Activate and maintain a valid SSL certificate (HTTPS)
- Enforce HTTPS redirection
- Maintain proper file permissions (755 for directories, 644 for files)
- Remove unused FTP accounts
- Change passwords periodically
Attempting to modify server configurations outside the assigned hosting environment is strictly prohibited.
- SSL Certificate Usage
All websites must operate under HTTPS.
The following SSL options may be used:
- AutoSSL
- Let’s Encrypt
- Commercial SSL certificates
Maintaining HTTPS improves both security and search engine ranking.
- Installation of Themes and Web Software
Permitted
- Use of properly licensed themes and plugins
- Installation of reputable visual builders
- Customization of original templates
Not Permitted
- Use of nulled or pirated themes/plugins
- Software downloaded from untrusted sources
- Cracked versions of premium extensions
The use of pirated software is one of the primary causes of website compromise.
- Security for WordPress, Joomla, or Other CMS Platforms
If a CMS is installed, the user is responsible for maintaining its security.
Mandatory recommendations:
- Keep core, plugins, and themes updated
- Remove inactive plugins
- Avoid using the default “admin” username
- Limit login attempts
- Install a security plugin
- Perform regular backups
If a website is compromised due to lack of maintenance, it may be temporarily isolated to prevent impact on other users.
- Resource Usage
To maintain optimal server performance:
- Avoid poorly optimized scripts
- Do not run background processes
- Do not use hosting as external mass storage
- Do not host systems that generate excessive resource consumption without prior evaluation
Accounts exceeding allocated limits may be temporarily adjusted.
- Backups
Each user is strongly encouraged to maintain their own backups of website files and email accounts.
Server-side backups, when available, function as an additional preventive measure and do not replace the user’s responsibility.
- Server Maintenance
The following actions may be performed periodically:
- Security updates
- Scheduled reboots
- Performance optimizations
These processes may result in brief service interruptions.
- Purpose of These Policies
These policies are not intended to restrict service usage, but to:
- Maintain stability
- Prevent SPAM-related blocking
- Reduce hacking risks
- Protect server reputation
- Ensure optimal performance for all users

3 Comments
Id vim facilis ceteros percipit, altera phaedrum sea at, te alia novum praesent sit. Ne justo mazim delenit eam, pri ex brute interpretaris, invenire.
Praesent finibus congue euismod. Nullam scelerisque massa vel augue placerat, a tempor sem egestas. Curabitur placerat finibus lacus.
Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit.