Quick start
Sign in to NelcPanel and find your way around in under five minutes.
1. Signing in
NelcPanel has two entry points: the user panel where your clients manage their hosting, and NelcWHM for admins and resellers. Accounts carry one of three roles — admin, reseller or user.
- Open your panel URL in a browser (for example
https://panel.yourhost.com). - Enter your username and password on the sign-in card.
- If you hold a reseller or admin role, choose the WHM area from the top navigation.
2. The dashboard
The dashboard gives an instant overview of your account: disk and bandwidth usage, the number of domains, databases, email accounts, FTP accounts and installed SSL certificates. Every metric links through to the tool that manages it.
3. What's in the sidebar
- Web & Domains — file manager, domains, subdomains, SSL, PHP versions, apps, Git, redirects.
- Email — accounts, forwarders, filters, autoresponders, spam, deliverability and backups.
- DNS — the zone editor for every domain you manage.
- Databases — MySQL databases, users, remote access and phpMyAdmin.
- FTP — FTP accounts with per-account quotas.
- Security — malware scanner, IP blocker, hotlink and leech protection, directory privacy.
- Backups & Analytics — backups, disk usage, bandwidth, visitors and logs.
Web & Domains
Everything you need to publish and manage websites.
File manager
The browser-based file manager works over your entire home directory. Upload, download, edit, rename, copy, move and set permissions on files and folders — with zip/unzip, compression and directory privacy controls built in.
Domains, addon domains & subdomains
Every account has a primary domain and can add more. Subdomains get their DNS record and document root created automatically, and each subdomain can carry its own Let's Encrypt SSL certificate.
Redirects & error pages
Create HTTP redirects with a chosen status code, set custom 400/401/403/404/500 error pages,
and toggle directory listing with the index manager — all managed through generated
.htaccess rules.
PHP version selector
Switch any domain between the installed PHP versions (8.3, 8.4 and 8.5 by default). Per-domain
.user.ini defaults come pre-configured with generous limits:
upload_max_filesize = 128M
memory_limit = 256M
max_execution_time = 300
1-Click app installer
Launch WordPress and more without touching a terminal. The wizard provisions a dedicated
{user}_-prefixed database and user, downloads the software, writes the config and
creates an admin account. Multiple installs per domain are supported.
Git manager
Create and manage repositories, view branches and check working-tree status — no SSH required.
SSL
Issue Let's Encrypt certificates for any domain or subdomain from the SSL section. Certificates are provisioned with Certbot and renew automatically. NelcWHM can also enable Auto SSL so new accounts are secured instantly.
A complete mail stack — Postfix, Dovecot and OpenDKIM — with deliverability configured by default.
Email accounts
Create accounts per domain with individual quotas and a link to Roundcube webmail. Signing is handled with SHA-512-CRYPT passwords, and every account maps straight into the mail server.
Forwarders, filters & autoresponders
- Forwarders — route one address to another, suspendable at any time.
- Email filters — order-dependent Dovecot Sieve rules that match on subject, from, header and more.
- Autoresponders — Sieve vacation replies, sent once per sender per day.
Spam controls
Per-account whitelists and blacklists, plus a global spam threshold (default 5.0) with a default action of moving mail to Junk.
Deliverability (SPF, DKIM, DMARC)
When a domain is created, NelcPanel publishes the correct SPF, DKIM (mail._domainkey)
and DMARC (p=quarantine) records automatically via PowerDNS. OpenDKIM signs outbound
mail, so your clients' messages land in the inbox instead of the spam folder.
Connecting a mail client
Client setup guides are built into the panel. The common settings are:
Incoming IMAP: mail.yourdomain.com port 993 SSL/TLS
Outgoing SMTP: mail.yourdomain.com port 465 SSL/TLS
(or) port 587 STARTTLS
Email backup & restore
Export and import mailboxes from the panel — useful for migrations and archival.
DNS
Full DNS control backed by PowerDNS — the same engine the world's biggest registrars rely on.
The zone editor
Every domain has its own zone, created automatically when the account is provisioned. Zones are editable record-by-record, with support for:
- A and AAAA — IPv4 and IPv6 records.
- CNAME — aliases such as
www. - MX — mail exchange with priority.
- TXT — SPF, DKIM, DMARC and verification records.
- NS — nameserver delegation.
- SRV — priority / weight / port service records.
- CAA — certificate authority authorization (issue, issuewild, iodef).
TTLs are fully configurable (300–86400 seconds), and any zone can be exported.
DNS slave servers
Add secondary nameservers from NelcWHM to run a resilient, redundant DNS setup across multiple servers and locations.
systemd-resolved or BIND is running, the installer disables it automatically to avoid conflicts.Databases
Create and manage MySQL databases with the same workflow your clients already know.
Creating a database
- Open Databases and choose Add Database.
- Name your database — NelcPanel automatically prefixes it with your account username.
- Create a database user with a generated or custom password.
- Assign privileges (ALL PRIVILEGES by default) and you're done.
Remote MySQL
Allow specific IP addresses to connect to your databases from outside the server. Your host is the server's IP address on port 3306, and clients authenticate with their panel login password.
phpMyAdmin
Launch phpMyAdmin with a single click — the panel uses single sign-on, so there's no second password to remember or expose.
FTP
Create FTP accounts for your clients, contributors and agencies — all backed by Pure-FTPd.
Creating an FTP account
- Open FTP and choose Add Account.
- Pick a username and password.
- Set a quota in GB, or leave it unlimited.
- Choose the home directory for the account.
Accounts connect to your server's FTP address on port 21. The panel manages everything in MySQL, so accounts appear instantly and enforce their quotas server-side.
Security
Protect websites and mailboxes from malware, abuse and unwanted visitors.
Malware scanner
Scan your account with ClamAV and review the results in the panel. Detected files are moved to quarantine where they can be inspected, restored or deleted — with a full scan history.
IP blocker
Block specific IP addresses from accessing your sites, enforced at the server level.
Hotlink & leech protection
- Hotlink protection — stop other sites from hotlinking your images and media.
- Leech protection — rate-limit connections to protect bandwidth and CPU.
Directory privacy
Password-protect any folder with its own username and password, independent of the account login.
Server-side hardening
- All stored database passwords are encrypted at rest with AES-256-GCM.
www-datahas a restricted sudoers set and a whitelisted service wrapper — no arbitrary systemctl.- MySQL binds to 127.0.0.1 and port 3306 is blocked from the outside by default.
- Binary logging is disabled to stop unmanaged log growth.
Backups
Keep websites and data safe with one-click backups.
Creating a backup
- Open Backups.
- Choose Full (files + MySQL databases) or Files only.
- Click Create Backup and download the archive.
Backups are stored in /home/{user}/backups/ with the newest 10 kept automatically.
Panel backups (NelcWHM)
Admins can back up the entire nelcpanel database — accounts, email, DNS, SSL and
settings — from NelcWHM, with download, restore and delete options.
Analytics & Logs
Know exactly what your servers and sites are doing.
Resource usage
- Disk usage — per-directory and per-mailbox consumption.
- Bandwidth — 24h / 7d / 30d / monthly views with bytes, requests and top user agents per domain.
- CPU & memory — live system load, memory and connection counts.
Traffic & logs
- Visitors — per-domain visitor logs, 50 per page, filterable by IP.
- Raw access logs — 24h / 7d / 30d downloads.
- Error logs — 50 entries per page with date ranges.
NelcWHM — server administration
The admin and reseller side of NelcPanel, for people running the server.
Dashboard
Live gauges show CPU load, memory, disk and aggregate bandwidth — refreshed every 5 seconds — alongside stat cards for accounts, domains, databases, email, FTP, subdomains and SSL.
Creating an account
One form provisions everything at once:
- Enter the domain and package.
- NelcPanel generates a username and validates the password policy (8+ chars, upper, lower, number, special).
- The Linux user, home structure, MySQL user, PHP-FPM pool and vhost are created together.
- PowerDNS zone with SOA, NS, A, MX, SPF, DKIM and DMARC records is published automatically.
- A welcome page and hardened permissions are applied.
Packages
Define reusable plans with limits for disk, bandwidth, FTP accounts, email accounts, databases, database users, subdomains, cron jobs, addon domains and aliases. Compare packages side-by-side before assigning them to accounts.
Managing accounts
- Upgrade / downgrade — change packages instantly.
- Suspend / unsuspend — lock the account and its email, then restore in one click.
- Terminate — full teardown: databases, users, DNS, SSL, mail, FPM pools and the Linux user (with optional home removal). Requires typing the username to confirm.
Service manager
Start, stop, restart, enable and disable Apache, MariaDB/MySQL, Pure-FTPd, OpenSSH, PowerDNS, Postfix, Dovecot and Cron. Essential services (Apache, MariaDB, SSH) are protected from being stopped, and every action is logged.
In-browser terminal
A full root shell (xterm.js) for admins, with sessions logged to /var/log/nelcpanel-terminal.log.
Mail administration
- Mail tracker — search outbound and inbound mail with per-account daily counts.
- Outbound relay — direct, or through Gmail, Office 365, SendGrid, Mailgun, Amazon SES, Postmark, Brevo, SparkPost or a custom SMTP relay.
SSL management
- Hostname SSL — certificate provider and expiry for the server's own hostname.
- Manage SSL hosts — per-user certificates with Certbot provisioning.
- Auto SSL — enable or disable, with a log viewer for provision/renew/failed events.
Server configuration
Set the hostname, nameservers and public IP; change root passwords; monitor memory; schedule or cancel reboots (standard, immediate or emergency); update the panel via git; and back up the whole panel database.
Install on Ubuntu 26.04
Install the complete NelcPanel stack on a fresh Ubuntu 26.04 LTS server.
Requirements
- Ubuntu 26.04 LTS server (not earlier, not a different distro).
- Root access (
sudo). - A public IP and a hostname pointing to it.
- Open ports: 80, 443, 25, 587, 465, 143, 993, 110, 995, 21, 53 (UDP/TCP).
Step 1 — Download the installer
git clone https://github.com/nelcbytecloud/nelcpanel.git
# or upload the NelcPanel source directory to the server
Step 2 — Run the installer
cd nelcpanel
sudo bash install-26.04.sh
Or point the installer at a source path explicitly:
sudo bash install-26.04.sh /home/me/nelcpanel
What the installer does
- System prep — disables interactive prompts, enables the universe repository and adds the PHP repo.
- Port & service cleanup — puts AppArmor into complain mode and stops conflicting web/mail/FTP/DNS services.
- Packages — Apache, PHP 8.5 FPM (plus 8.3/8.4), MySQL/MariaDB, Postfix, Dovecot, Roundcube, Pure-FTPd, phpMyAdmin, OpenDKIM, PowerDNS, Certbot and ClamAV tooling.
- vmail setup — creates the mail storage user and encrypted key store at
/etc/nelcpanel/keys/. - Sudoers — installs the restricted
nelcpanel-ctlwrapper and locked-down sudo rules forwww-data. - Database — creates the
nelcpaneldatabase, imports the schema, generates credentials and seeds the admin account. - Mail stack — configures Postfix virtual domains/aliases/mailboxes against MySQL, Dovecot IMAP/POP3/LMTP and OpenDKIM signing.
- DNS — wires PowerDNS to MySQL.
Step 3 — Sign in
Admin credentials are printed at the end of the install and saved to
/etc/nelcpanel/admin_credentials.txt. Log in, then
change the admin password immediately.
Troubleshooting
journalctl -u mysql --no-pager -n 20— if MySQL fails to start.systemctl status php8.5-fpm— to confirm the panel's PHP-FPM pool is active.- Port conflicts — review installer warnings about ports 80/443/3306/25/587/143/993/110/995/21/53.
Billing API v1
Provision hosting accounts automatically from WHMCS, Blesta, ClientExec — or your own billing system.
Authentication
Send a token as a Bearer header or as the X-API-Key header. Tokens are
stored as SHA-256 hashes, created with a name, shown only once, and revocable with last-used tracking.
# Generate a token in NelcWHM → API Settings, then use it like this:
curl https://panel.example.com/api/account/list \
-H "Authorization: Bearer $TOKEN"
Base URL
https://panel.example.com/api/v1/
Endpoints
account/createCreate a fully provisioned hosting account (Linux user, home, DNS, MySQL, PHP-FPM, SSL-ready).
| Parameter | Type | Required | Description |
|---|---|---|---|
domain | string | YES | Primary domain (valid hostname). |
package | string | YES | Package name from packages/list. |
username | string | YES | Login username, 8–16 chars. |
password | string | YES | 8+ chars with upper, lower, number & special. |
contact_email | string | no | Account contact email. |
curl -X POST https://panel.example.com/api/account/create \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{
"domain": "client.com",
"package": "starter",
"username": "client01",
"password": "$SECURE_PASS"
}'
account/terminatePermanently remove an account and all its resources.
| Parameter | Type | Required | Description |
|---|---|---|---|
username | string | YES | Account to terminate. |
remove_home | boolean | no | Also delete the home directory (true/false). |
account/suspendSuspend an account and its email. Use account/unsuspend to restore.
| Parameter | Type | Required | Description |
|---|---|---|---|
username | string | YES | Account to suspend. |
account/unsuspendRestore a suspended account.
| Parameter | Type | Required | Description |
|---|---|---|---|
username | string | YES | Account to restore. |
account/upgradeChange an account's package (upgrade or downgrade).
| Parameter | Type | Required | Description |
|---|---|---|---|
username | string | YES | Account to change. |
package | string | YES | New package name. |
account/infoFetch account details and resource usage.
| Parameter | Type | Required | Description |
|---|---|---|---|
username | string | YES | Account username. |
account/listList accounts, paged.
| Parameter | Type | Required | Description |
|---|---|---|---|
page | integer | no | Page number. |
account/loginGenerate a one-time login URL so a client can reach their panel immediately after payment.
| Parameter | Type | Required | Description |
|---|---|---|---|
username | string | YES | Account username. |
curl -X POST https://panel.example.com/api/account/login \
-H "Authorization: Bearer $TOKEN" \
-H "Content-Type: application/json" \
-d '{ "username": "client01" }'
account/token/generateCreate a named API token. The token value is returned once. Manage with account/token/list and account/token/revoke.
| Parameter | Type | Required | Description |
|---|---|---|---|
name | string | YES | Human-readable token name. |
packages/listList available hosting packages and their limits — the source of truth for billing integrations.
Error handling
Errors return a JSON body with a message describing the failure, and an appropriate
HTTP status code (400 validation, 401 auth, 404 missing account). All account endpoints validate
domains, usernames and password policy before touching the server.
Next steps
- Generate a token in NelcWHM → API Settings.
- Point your billing system's module at the base URL and your token.
- Test with
account/infobefore enabling automated provisioning.