Sites and domains
Creating a site
Section titled “Creating a site”From Sites → New site, choose a type:
| Type | For |
|---|---|
| WordPress | A fresh WordPress install, ready to log into in a couple of minutes |
| PHP | A general PHP application — Laravel and other front-controller apps are supported presets |
| Static | HTML, or a site built by a static site generator |
Give it a name and, if you have one ready, its primary domain. Your hosting panel provisions the site immediately: its own user, its own PHP runtime (for PHP and WordPress sites) and its own sandbox, isolated from every other site on the server.
Domains
Section titled “Domains”A site can carry several domains:
- Primary domain — the site’s canonical address.
- Aliases — additional domains or subdomains that serve the same site.
- Redirects — domains that redirect to another domain of the site (useful for
wwwand non-wwwvariants, or old domains you’re retiring).
Each domain can have its own document root within the site, useful for serving a subdomain from a different folder.
DNS verification
Section titled “DNS verification”After adding a domain, the site’s domain page shows the exact A/AAAA records to create. Most domains are served as soon as they resolve to your panel’s address; a domain gets checked again automatically every couple of minutes at first, then less often, and you can always recheck it by hand. Some domains — a wildcard whose base domain isn’t verified yet, or one that shares a registrable domain with another customer’s verified domain — need a TXT record instead, which lets you prove control before you switch DNS at all.
HTTPS and HSTS
Section titled “HTTPS and HSTS”Once a domain resolves, an HTTPS certificate is issued for it automatically — no action needed. HTTP requests redirect to HTTPS. HSTS is on by default to keep browsers from ever falling back to plain HTTP for the domain.
Web application firewall
Section titled “Web application firewall”Each site has its own firewall mode, if your plan allows changing it:
| Mode | Behavior |
|---|---|
| Off | No inspection |
| Detect | Suspicious requests are logged, nothing is blocked |
| Block | Suspicious requests get a 403 page |
Block mode protects against common web attacks (SQL injection attempts, path traversal, known exploit patterns) but inspects only the first 13 MiB of a request body — a site that regularly receives large uploads through its web forms should use detect mode instead, or accept large files over SFTP.
Site status
Section titled “Site status”A site’s status reflects whether it’s actually serving as configured: Ready means everything applied cleanly; Degraded or Error point at a problem (with a plain-language reason) your provider’s operators can see too. A suspended site (from a billing issue) shows a suspended page to visitors while keeping its data intact.