Documentation

Everything you need to use NelcPanel — the control panel we sell to the public for any Ubuntu 26.04 server you own or rent. Covers the user panel, NelcWHM administration, Ubuntu 26.04 installation and the Billing API.

Quick start

Sign in to NelcPanel and find your way around in under five minutes.

1. Signing in

NelcPanel has two entry points: the user panel where your clients manage their hosting, and NelcWHM for admins and resellers. Accounts carry one of three roles — admin, reseller or user.

  1. Open your panel URL in a browser (for example https://panel.yourhost.com).
  2. Enter your username and password on the sign-in card.
  3. If you hold a reseller or admin role, choose the WHM area from the top navigation.
The first login uses the credentials shown by the installer. Admins must change the default password immediately — see Install on Ubuntu 26.04.

2. The dashboard

The dashboard gives an instant overview of your account: disk and bandwidth usage, the number of domains, databases, email accounts, FTP accounts and installed SSL certificates. Every metric links through to the tool that manages it.

3. What's in the sidebar

  • Web & Domains — file manager, domains, subdomains, SSL, PHP versions, apps, Git, redirects.
  • Email — accounts, forwarders, filters, autoresponders, spam, deliverability and backups.
  • DNS — the zone editor for every domain you manage.
  • Databases — MySQL databases, users, remote access and phpMyAdmin.
  • FTP — FTP accounts with per-account quotas.
  • Security — malware scanner, IP blocker, hotlink and leech protection, directory privacy.
  • Backups & Analytics — backups, disk usage, bandwidth, visitors and logs.

Web & Domains

Everything you need to publish and manage websites.

File manager

The browser-based file manager works over your entire home directory. Upload, download, edit, rename, copy, move and set permissions on files and folders — with zip/unzip, compression and directory privacy controls built in.

Domains, addon domains & subdomains

Every account has a primary domain and can add more. Subdomains get their DNS record and document root created automatically, and each subdomain can carry its own Let's Encrypt SSL certificate.

Redirects & error pages

Create HTTP redirects with a chosen status code, set custom 400/401/403/404/500 error pages, and toggle directory listing with the index manager — all managed through generated .htaccess rules.

PHP version selector

Switch any domain between the installed PHP versions (8.3, 8.4 and 8.5 by default). Per-domain .user.ini defaults come pre-configured with generous limits:

.user.ini
upload_max_filesize = 128M
memory_limit = 256M
max_execution_time = 300

1-Click app installer

Launch WordPress and more without touching a terminal. The wizard provisions a dedicated {user}_-prefixed database and user, downloads the software, writes the config and creates an admin account. Multiple installs per domain are supported.

Git manager

Create and manage repositories, view branches and check working-tree status — no SSH required.

SSL

Issue Let's Encrypt certificates for any domain or subdomain from the SSL section. Certificates are provisioned with Certbot and renew automatically. NelcWHM can also enable Auto SSL so new accounts are secured instantly.

Email

A complete mail stack — Postfix, Dovecot and OpenDKIM — with deliverability configured by default.

Email accounts

Create accounts per domain with individual quotas and a link to Roundcube webmail. Signing is handled with SHA-512-CRYPT passwords, and every account maps straight into the mail server.

Forwarders, filters & autoresponders

  • Forwarders — route one address to another, suspendable at any time.
  • Email filters — order-dependent Dovecot Sieve rules that match on subject, from, header and more.
  • Autoresponders — Sieve vacation replies, sent once per sender per day.

Spam controls

Per-account whitelists and blacklists, plus a global spam threshold (default 5.0) with a default action of moving mail to Junk.

Deliverability (SPF, DKIM, DMARC)

When a domain is created, NelcPanel publishes the correct SPF, DKIM (mail._domainkey) and DMARC (p=quarantine) records automatically via PowerDNS. OpenDKIM signs outbound mail, so your clients' messages land in the inbox instead of the spam folder.

Connecting a mail client

Client setup guides are built into the panel. The common settings are:

IMAP / SMTP
Incoming IMAP:  mail.yourdomain.com   port 993  SSL/TLS
Outgoing SMTP:  mail.yourdomain.com   port 465  SSL/TLS
            (or)                    port 587  STARTTLS

Email backup & restore

Export and import mailboxes from the panel — useful for migrations and archival.

DNS

Full DNS control backed by PowerDNS — the same engine the world's biggest registrars rely on.

The zone editor

Every domain has its own zone, created automatically when the account is provisioned. Zones are editable record-by-record, with support for:

  • A and AAAA — IPv4 and IPv6 records.
  • CNAME — aliases such as www.
  • MX — mail exchange with priority.
  • TXT — SPF, DKIM, DMARC and verification records.
  • NS — nameserver delegation.
  • SRV — priority / weight / port service records.
  • CAA — certificate authority authorization (issue, issuewild, iodef).

TTLs are fully configurable (300–86400 seconds), and any zone can be exported.

DNS slave servers

Add secondary nameservers from NelcWHM to run a resilient, redundant DNS setup across multiple servers and locations.

NelcPanel takes over port 53 on the server. If systemd-resolved or BIND is running, the installer disables it automatically to avoid conflicts.

Databases

Create and manage MySQL databases with the same workflow your clients already know.

Creating a database

  1. Open Databases and choose Add Database.
  2. Name your database — NelcPanel automatically prefixes it with your account username.
  3. Create a database user with a generated or custom password.
  4. Assign privileges (ALL PRIVILEGES by default) and you're done.

Remote MySQL

Allow specific IP addresses to connect to your databases from outside the server. Your host is the server's IP address on port 3306, and clients authenticate with their panel login password.

phpMyAdmin

Launch phpMyAdmin with a single click — the panel uses single sign-on, so there's no second password to remember or expose.

FTP

Create FTP accounts for your clients, contributors and agencies — all backed by Pure-FTPd.

Creating an FTP account

  1. Open FTP and choose Add Account.
  2. Pick a username and password.
  3. Set a quota in GB, or leave it unlimited.
  4. Choose the home directory for the account.

Accounts connect to your server's FTP address on port 21. The panel manages everything in MySQL, so accounts appear instantly and enforce their quotas server-side.

Security

Protect websites and mailboxes from malware, abuse and unwanted visitors.

Malware scanner

Scan your account with ClamAV and review the results in the panel. Detected files are moved to quarantine where they can be inspected, restored or deleted — with a full scan history.

IP blocker

Block specific IP addresses from accessing your sites, enforced at the server level.

Hotlink & leech protection

  • Hotlink protection — stop other sites from hotlinking your images and media.
  • Leech protection — rate-limit connections to protect bandwidth and CPU.

Directory privacy

Password-protect any folder with its own username and password, independent of the account login.

Server-side hardening

  • All stored database passwords are encrypted at rest with AES-256-GCM.
  • www-data has a restricted sudoers set and a whitelisted service wrapper — no arbitrary systemctl.
  • MySQL binds to 127.0.0.1 and port 3306 is blocked from the outside by default.
  • Binary logging is disabled to stop unmanaged log growth.

Backups

Keep websites and data safe with one-click backups.

Creating a backup

  1. Open Backups.
  2. Choose Full (files + MySQL databases) or Files only.
  3. Click Create Backup and download the archive.

Backups are stored in /home/{user}/backups/ with the newest 10 kept automatically.

Panel backups (NelcWHM)

Admins can back up the entire nelcpanel database — accounts, email, DNS, SSL and settings — from NelcWHM, with download, restore and delete options.

Analytics & Logs

Know exactly what your servers and sites are doing.

Resource usage

  • Disk usage — per-directory and per-mailbox consumption.
  • Bandwidth — 24h / 7d / 30d / monthly views with bytes, requests and top user agents per domain.
  • CPU & memory — live system load, memory and connection counts.

Traffic & logs

  • Visitors — per-domain visitor logs, 50 per page, filterable by IP.
  • Raw access logs — 24h / 7d / 30d downloads.
  • Error logs — 50 entries per page with date ranges.

NelcWHM — server administration

The admin and reseller side of NelcPanel, for people running the server.

Dashboard

Live gauges show CPU load, memory, disk and aggregate bandwidth — refreshed every 5 seconds — alongside stat cards for accounts, domains, databases, email, FTP, subdomains and SSL.

Creating an account

One form provisions everything at once:

  1. Enter the domain and package.
  2. NelcPanel generates a username and validates the password policy (8+ chars, upper, lower, number, special).
  3. The Linux user, home structure, MySQL user, PHP-FPM pool and vhost are created together.
  4. PowerDNS zone with SOA, NS, A, MX, SPF, DKIM and DMARC records is published automatically.
  5. A welcome page and hardened permissions are applied.

Packages

Define reusable plans with limits for disk, bandwidth, FTP accounts, email accounts, databases, database users, subdomains, cron jobs, addon domains and aliases. Compare packages side-by-side before assigning them to accounts.

Managing accounts

  • Upgrade / downgrade — change packages instantly.
  • Suspend / unsuspend — lock the account and its email, then restore in one click.
  • Terminate — full teardown: databases, users, DNS, SSL, mail, FPM pools and the Linux user (with optional home removal). Requires typing the username to confirm.

Service manager

Start, stop, restart, enable and disable Apache, MariaDB/MySQL, Pure-FTPd, OpenSSH, PowerDNS, Postfix, Dovecot and Cron. Essential services (Apache, MariaDB, SSH) are protected from being stopped, and every action is logged.

In-browser terminal

A full root shell (xterm.js) for admins, with sessions logged to /var/log/nelcpanel-terminal.log.

Mail administration

  • Mail tracker — search outbound and inbound mail with per-account daily counts.
  • Outbound relay — direct, or through Gmail, Office 365, SendGrid, Mailgun, Amazon SES, Postmark, Brevo, SparkPost or a custom SMTP relay.

SSL management

  • Hostname SSL — certificate provider and expiry for the server's own hostname.
  • Manage SSL hosts — per-user certificates with Certbot provisioning.
  • Auto SSL — enable or disable, with a log viewer for provision/renew/failed events.

Server configuration

Set the hostname, nameservers and public IP; change root passwords; monitor memory; schedule or cancel reboots (standard, immediate or emergency); update the panel via git; and back up the whole panel database.

Install on Ubuntu 26.04

Install the complete NelcPanel stack on a fresh Ubuntu 26.04 LTS server.

The installer performs a strictly fresh installation. Run it on a clean server (or a fresh VPS) — it does not clean up previous installs.

Requirements

  • Ubuntu 26.04 LTS server (not earlier, not a different distro).
  • Root access (sudo).
  • A public IP and a hostname pointing to it.
  • Open ports: 80, 443, 25, 587, 465, 143, 993, 110, 995, 21, 53 (UDP/TCP).

Step 1 — Download the installer

bash
git clone https://github.com/nelcbytecloud/nelcpanel.git
# or upload the NelcPanel source directory to the server

Step 2 — Run the installer

bash
cd nelcpanel
sudo bash install-26.04.sh

Or point the installer at a source path explicitly:

bash
sudo bash install-26.04.sh /home/me/nelcpanel

What the installer does

  1. System prep — disables interactive prompts, enables the universe repository and adds the PHP repo.
  2. Port & service cleanup — puts AppArmor into complain mode and stops conflicting web/mail/FTP/DNS services.
  3. Packages — Apache, PHP 8.5 FPM (plus 8.3/8.4), MySQL/MariaDB, Postfix, Dovecot, Roundcube, Pure-FTPd, phpMyAdmin, OpenDKIM, PowerDNS, Certbot and ClamAV tooling.
  4. vmail setup — creates the mail storage user and encrypted key store at /etc/nelcpanel/keys/.
  5. Sudoers — installs the restricted nelcpanel-ctl wrapper and locked-down sudo rules for www-data.
  6. Database — creates the nelcpanel database, imports the schema, generates credentials and seeds the admin account.
  7. Mail stack — configures Postfix virtual domains/aliases/mailboxes against MySQL, Dovecot IMAP/POP3/LMTP and OpenDKIM signing.
  8. DNS — wires PowerDNS to MySQL.

Step 3 — Sign in

Admin credentials are printed at the end of the install and saved to /etc/nelcpanel/admin_credentials.txt. Log in, then change the admin password immediately.

Typical fresh install completes in 10–20 minutes depending on your server's network speed.

Troubleshooting

  • journalctl -u mysql --no-pager -n 20 — if MySQL fails to start.
  • systemctl status php8.5-fpm — to confirm the panel's PHP-FPM pool is active.
  • Port conflicts — review installer warnings about ports 80/443/3306/25/587/143/993/110/995/21/53.

Billing API v1

Provision hosting accounts automatically from WHMCS, Blesta, ClientExec — or your own billing system.

Authentication

Send a token as a Bearer header or as the X-API-Key header. Tokens are stored as SHA-256 hashes, created with a name, shown only once, and revocable with last-used tracking.

bash
# Generate a token in NelcWHM → API Settings, then use it like this:
curl https://panel.example.com/api/account/list \
  -H "Authorization: Bearer $TOKEN"

Base URL

text
https://panel.example.com/api/v1/

Endpoints

POSTaccount/create

Create a fully provisioned hosting account (Linux user, home, DNS, MySQL, PHP-FPM, SSL-ready).

ParameterTypeRequiredDescription
domainstringYESPrimary domain (valid hostname).
packagestringYESPackage name from packages/list.
usernamestringYESLogin username, 8–16 chars.
passwordstringYES8+ chars with upper, lower, number & special.
contact_emailstringnoAccount contact email.
bash
curl -X POST https://panel.example.com/api/account/create \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "domain": "client.com",
    "package": "starter",
    "username": "client01",
    "password": "$SECURE_PASS"
  }'
POSTaccount/terminate

Permanently remove an account and all its resources.

ParameterTypeRequiredDescription
usernamestringYESAccount to terminate.
remove_homebooleannoAlso delete the home directory (true/false).
POSTaccount/suspend

Suspend an account and its email. Use account/unsuspend to restore.

ParameterTypeRequiredDescription
usernamestringYESAccount to suspend.
POSTaccount/unsuspend

Restore a suspended account.

ParameterTypeRequiredDescription
usernamestringYESAccount to restore.
POSTaccount/upgrade

Change an account's package (upgrade or downgrade).

ParameterTypeRequiredDescription
usernamestringYESAccount to change.
packagestringYESNew package name.
GETaccount/info

Fetch account details and resource usage.

ParameterTypeRequiredDescription
usernamestringYESAccount username.
GETaccount/list

List accounts, paged.

ParameterTypeRequiredDescription
pageintegernoPage number.
POSTaccount/login

Generate a one-time login URL so a client can reach their panel immediately after payment.

ParameterTypeRequiredDescription
usernamestringYESAccount username.
bash
curl -X POST https://panel.example.com/api/account/login \
  -H "Authorization: Bearer $TOKEN" \
  -H "Content-Type: application/json" \
  -d '{ "username": "client01" }'
POSTaccount/token/generate

Create a named API token. The token value is returned once. Manage with account/token/list and account/token/revoke.

ParameterTypeRequiredDescription
namestringYESHuman-readable token name.
GETpackages/list

List available hosting packages and their limits — the source of truth for billing integrations.

Error handling

Errors return a JSON body with a message describing the failure, and an appropriate HTTP status code (400 validation, 401 auth, 404 missing account). All account endpoints validate domains, usernames and password policy before touching the server.

Next steps

  • Generate a token in NelcWHM → API Settings.
  • Point your billing system's module at the base URL and your token.
  • Test with account/info before enabling automated provisioning.