cPanel & WHM for Resellers: What You Actually Need to Know

Picture of Bogdan

Bogdan

Buy a reseller hosting plan and you get handed two control panels, a set of nameservers, and very little explanation of which parts of the interface you’re allowed to touch.

The gap between “you get WHM” and knowing what WHM actually does for you is where most new resellers lose their first month. This guide covers the real division of labour: what you administer, what your clients see, and what stays locked behind root access that you will never have on a reseller plan. If you’re still deciding whether to resell at all, start with our guide to starting a reseller hosting business and come back here once you’re pricing plans.

The short version: a reseller account gives you genuine control over accounts, packages, DNS and branding, and no control at all over the server itself. Whether that’s a limitation or a feature depends entirely on what your clients need.

cPanel vs WHM: the difference that actually matters

cPanel is the interface for a single hosting account. WHM is the interface for administering many hosting accounts. Your clients log into cPanel and see one website. You log into WHM and see all of them.

There are three layers, and knowing which one you occupy explains almost every “why can’t I do this?” moment.

cPanel: what your clients see

One cPanel account is one hosting account. Inside it, the account holder manages files, email addresses, databases, subdomains, SSL, cron jobs and backups for their own sites. They access it at yourdomain.com:2083 or through whatever branded URL you set up.

cPanel Interface

Clients never see WHM. As far as they’re concerned, cPanel is the hosting.

Check out a cPanel demo

WHM: what you see

WHM (Web Host Manager) runs on port 2087. It’s where you create accounts, assign them to packages, suspend them for non-payment, reset passwords, edit DNS and pull sites in from other hosts.

WHM Interface

Here’s the part that catches people out: the WHM you get as a reseller is the same application the server administrator uses, with most of it removed. A root-level WHM exposes over 200 interfaces. A reseller WHM exposes roughly thirty. This is why generic WHM tutorials mislead so badly. You’ll follow along, hit a menu that isn’t in your sidebar, and assume you’ve broken something.

You haven’t. You just don’t have root.

Check out a WHM demo

Root: the layer above you

Root is the server administrator’s account, held by your hosting provider. Root configures Apache, compiles PHP, installs system packages, sets firewall rules, tunes MySQL and decides the backup policy.

You are a tenant with administrative rights over your own portion of the server. Your provider is the landlord. That relationship defines everything below.

Three layers of hosting access: cPanel controls one website, reseller WHM controls all your client accounts, and root WHM controls the server and is held by your hosting provider.

What you can do in a reseller WHM

Your exact permissions depend on the ACLs (access control lists) your provider enables, and they vary between hosts. This is close to the standard set.

CapabilityWhat it covers
Create accountsNew cPanel accounts, assigned to a package, with their own domain and login
Modify accountsChange domain, contact email, package, quotas, shell access
Suspend & unsuspendNon-payment, abuse, or holding an account during a dispute
Terminate accountsWith or without keeping the DNS zone
Change passwordsReset a client’s cPanel password without needing the old one
Log in as any accountEnter any client’s cPanel directly from WHM, no password required
Build packagesDefine the resource allocations your plans sell
Build feature listsControl which tools appear inside the client’s cPanel
Edit DNS zonesAdd, edit, reset and delete zones for domains you host
Private nameserversRegister and use ns1.yourbrand.com and ns2.yourbrand.com instead of your host’s
Transfer accounts in (root)Pull accounts from another cPanel server, or restore cpmove archives.
Create sub-resellers (root)Grant a subset of your own permissions to another account. 
Brand cPanelApply your logo, colours and support links to the client interface
Issue SSLRun AutoSSL for your accounts, or install purchased certificates
View usageDisk, bandwidth and account-level resource statistics

That’s a real hosting business. You can provision a client in about ninety seconds, bill them, support them, and remove them, all without ever contacting your provider.

What you can’t do without root access

This is the section nobody selling reseller hosting writes, and it’s the one that determines whether the model fits your clients.

LockedWhat it means when a client asks
Installing system softwareA client wants Redis, a custom daemon, or a package that isn’t in cPanel’s catalogue. You file a ticket and wait.
PHP extensionsIf the extension wasn’t compiled into the available PHP builds, you can’t add it. Common with imagick, and with older or niche extensions.
EasyApache / PHP buildsYou can usually switch a client between the PHP versions the server offers. You can’t add a version it doesn’t offer.
Apache or NGINX configServer-wide directives, custom modules, and anything outside .htaccess are off limits.
MySQL tuningQuery cache, buffer sizes, max connections. If a client’s database is straining the server, your only tool is optimising their queries.
Firewall & ModSecurityYou can’t whitelist an IP, unblock a locked-out client, or disable a ModSecurity rule that’s breaking a plugin. Every one of these is a support ticket to your provider.
Server backupsYou don’t set the schedule, the retention, or the restore policy. Depending on the host you may not be able to restore a full account yourself.
Dedicated IPsAssigning one requires root. Your accounts share the server’s IP unless your plan includes otherwise.
Service restarts & rebootsApache is hanging at 2am. You can see it. You cannot restart it.
Root SSH / terminalNo shell access at the server level, regardless of your own technical ability.
Resource limitsCPU and memory ceilings per account are set by the provider. You allocate disk and bandwidth; you don’t set the CPU cap.

Read that list again as an operations problem rather than a feature comparison. Every locked item is a support request that leaves your hands. Your client asks you, you ask your provider, and your response time is now your provider’s response time plus your own.

That’s the single most important thing to understand before buying. You are not just renting server resources. You are inheriting your host’s support responsiveness as your own SLA, and passing it to clients who will never know your provider exists.

It’s also why provider choice matters more for resellers than for anyone else, and why support quality is worth more than a few pounds a month on the plan price.

The WHM screens you’ll actually use

WHM’s sidebar is intimidating on day one. In practice, running a reseller account is about ten screens.

Account Functions — Create a New Account, List Accounts, Modify an Account, Suspend/Unsuspend, Terminate, Change Password, Upgrade/Downgrade. This is where most of your time goes. List Accounts is the one you’ll live in: it shows every client, their package, disk usage and status, with a login-as button beside each.

Packages — Add, edit and delete the plans you sell. Covered below.

Feature Manager — Controls which icons appear in your clients’ cPanel.

DNS Functions — Edit DNS Zone, Add/Delete a DNS Zone, Park a Domain. You’ll use these when a client points a domain at you, needs an MX record for external email, or wants a subdomain on a different host.

Transfers (root) — Copy an Account From Another Server, and Restore a Full Backup. This is how client sites come in from wherever they were before. See migrating client sites without downtime for the process.

Resellers (root) — Only if your provider grants it. Creates sub-resellers with a subset of your permissions.

Account Information — Bandwidth usage, disk usage, and your own reseller limits. Check this before you sell a plan you can’t fulfil.

cPanel Branding / Customization — Logo, colours, help links. Limited, and the limits are real. See where white-label seams show.

Manage API Tokens — Under Development. Needed for billing automation.

Support / Contact Server Administrator — Your route to root. You will use this more than you expect.

Packages vs Feature Lists

These get conflated constantly, and the confusion produces plans that don’t work.

A package is a resource allocation. Disk quota, monthly bandwidth, how many addon domains, subdomains, email accounts, databases and FTP accounts the client gets, plus hourly email limits, shell access and which cPanel theme loads.

A feature list controls visibility. It decides which tools appear in the client’s cPanel: whether they see the Terminal icon, the Backup Wizard, the email filters, the cron jobs.

Every package points at one feature list. That’s the relationship. Packages control how much, feature lists control what.

A hosting package defines resource limits such as disk and bandwidth, and points at a feature list that controls which cPanel tools the client can see.

The common mistake is generosity in one and neglect in the other. You build a 10 GB package with fifty email accounts and leave the default feature list attached, which shows the client every tool cPanel ships with, including several your plan doesn’t actually support. They find one, use it, and open a ticket when it doesn’t behave. You’ve generated support load out of a checkbox you never looked at.

The opposite failure is quieter and worse: hiding a feature the client needs, so they conclude your hosting can’t do something it can do perfectly well.

Build the feature list first, then the package that uses it. Step-by-step instructions are in how to create hosting packages in WHM, and the commercial question of how many tiers to offer is covered in how many hosting tiers should you offer.

Resource limits, and what “unlimited” really means

Every reseller plan advertises a disk and bandwidth figure. Those are the two limits that matter least.

Disk, bandwidth and inodes

You hold a pool of disk and bandwidth and allocate it across accounts. Most providers let you allocate more than you hold, on the reasonable assumption that not every client uses their full quota. The mechanics are simple; the judgement call is covered in overselling: what it is and when it’s defensible.

Inodes are the limit that catches people. An inode is roughly one file or folder. A WordPress install is around 3,000. A caching plugin can generate tens of thousands. Every stored email is one. Every backup copy multiplies the count.

Inode limits are usually set per account or across your whole reseller pool, and hitting one is not a graceful failure. File creation stops. Uploads fail, sessions break, and backups can fail silently while the account still shows free disk space. A client with 2 GB used against a 10 GB quota can be completely stuck.

Ask what the inode limit is before you buy. It’s rarely on the pricing page.

CPU, memory and entry processes

This is the limit that determines whether your clients affect each other, and it’s the one you should check first.

Most quality reseller platforms run CloudLinux, which places each cPanel account in its own resource cage (an LVE). Each account gets a ceiling on CPU, physical memory, I/O, processes and entry processes — the number of simultaneous requests it can handle.

Without that isolation, one client’s badly written plugin consumes server resources and every site you host slows down. With it, that client hits their own ceiling and everyone else is unaffected. The client sees a 508 Resource Limit Reached error; your other twenty clients see nothing.

CloudLinux Resource Isolation

 

That difference is worth more than any figure on the plan page. Ask whether the platform runs CloudLinux, and what the per-account CPU and memory limits are. A generous disk allocation on a server without resource isolation is a worse product than a smaller allocation with it.

LimitSet byWhat the client experiences when it’s hit
Disk quotaYou, in the packageUploads fail, email bounces
BandwidthYou, in the packageSite goes offline until reset
InodesProviderFile creation fails despite free disk
CPU / memory (LVE)ProviderSlow responses, 500 or 508 errors
Entry processesProvider508 errors under traffic spikes
Emails per hourYou, in the packageOutgoing mail queues or is rejected

Email sending limits

Packages include a max-emails-per-hour setting per domain, and your provider sets a hard ceiling above it. Leave the default too high and one compromised client can burn the server’s sending reputation. Set it too low and a legitimate newsletter fails.

Because you’re on shared IPs, your clients’ deliverability is partly determined by their neighbours. SPF and DKIM configuration falls to you, not to your provider, and it’s the single most common cause of the “my email isn’t arriving” ticket. Some hosts route outbound mail through a dedicated relay service, which largely removes shared-IP reputation from the equation. Worth asking about.

Who pays for the cPanel licence?

cPanel changed its licensing model in 2019, moving from a flat per-server fee to tiers based on account count. Prices have risen every year since. For anyone running their own server, it’s now a per-account cost that grows as you grow, which is the opposite of how hosting economics are supposed to work.

On a reseller plan, you don’t pay it. Your provider holds the licence for the server and the cost sits inside your plan price. Fifty accounts and five accounts cost you the same in licensing: nothing.

This matters more than it sounds, because it’s a large part of why reseller economics differ from VPS economics. Move to a VPS and the licence becomes yours, billed monthly, scaling with your account count, on top of the server cost. A plan comparison that looks close on headline price often isn’t once licensing is added.

Run your own numbers before deciding: the reseller profit calculator handles the arithmetic, and how to price reseller hosting plans covers what to do with the result.

Current cPanel tier pricing is published on cPanel’s own site and changes annually. Check it there rather than trusting a figure in an article, including this one.

Automation: API access and billing integration

Technical section. Skip to the next heading if you’re planning to provision accounts manually.

Every action available in the WHM interface is also available through WHM API 1. This is what makes a reseller account usable as infrastructure rather than as a dashboard.

The calls that matter for provisioning:

CallDoes
createacctCreates an account against a package
suspendacct / unsuspendacctNon-payment handling
removeacctTermination
modifyacctChange domain, contact, quotas
changepackageUpgrades and downgrades
listaccts / accountsummaryInventory and usage

Authenticate with an API token rather than your password. Generate one in WHM → Development → Manage API Tokens, scoped to the minimum ACLs the integration needs. A token that only ever creates and suspends accounts should not be able to terminate them.

curl -H 'Authorization: whm myreseller:YOUR_API_TOKEN' \ 'https://server.example.com:2087/json-api/createacct?api.version=1\ &username=client01&domain=clientsite.com&plan=starter-10gb&[email protected]'

Account-level operations use UAPI on port 2083 instead, which is how you’d automate anything inside a client’s account rather than around it.

Your token inherits your reseller permissions and nothing more. It can only see and act on your own accounts, and any call requiring root will be refused regardless of how the token is scoped.

This is exactly what billing platforms are doing. WHMCS and Blesta are, at the provisioning layer, a scheduler wrapped around these same API calls: invoice paid, createacct fires; invoice overdue by fourteen days, suspendacct fires. If you’re comfortable with the API, you can build the same behaviour into your own application and skip the billing platform entirely for provisioning, though you’ll still want one for invoicing and tax. WHMCS vs Blesta covers that choice.

Full method reference is in cPanel’s developer documentation.

Security and access hygiene

Three things, none of them optional.

Turn on two-factor authentication in WHM. Your WHM login controls every client site you host. Treat it accordingly.

Understand what “log in as any account” means. You can enter any client’s cPanel without their password and without notifying them. That’s necessary for support and it’s also a significant privacy position. Your terms of service should state that you have administrative access and when you’ll use it. Terms of service and AUP for a small host covers the wording.

Scope and rotate API tokens. One token per integration, minimum permissions, revoked when the integration is retired. A leaked token with full ACLs is equivalent to a leaked password.

And know your escalation path before you need it. When a client site is compromised, malware scanning and cleanup usually sit at the root level, which means your response depends on your provider. Find out now what they’ll do and how fast, not during the incident. When a client site gets compromised walks through the process.

Where the reseller model runs out

Reseller accounts have a natural ceiling. These are the signals you’ve reached it:

  • Repeated requests for software you can’t install. One client wanting Redis is a conversation. Four is a product gap.
  • Clients consistently hitting LVE limits. If a site regularly needs more CPU or memory than the account allows, it needs its own environment. Some hosts sell per-account resource boosts, which buys time.
  • Non-standard stacks. Node, Python or Ruby applications beyond what cPanel’s application manager handles. Docker. Anything needing a persistent process.
  • You need your own backup and restore guarantee. If you’re promising clients a four-hour restore and you can’t perform one yourself, you’re promising your provider’s response time.
  • Deliverability requires your own IP. Volume email senders eventually need IP reputation you control.
  • You’re near your account cap and the next reseller tier costs more than a small VPS.

The move up is covered in outgrowing reseller: moving to VPS or dedicated, and the underlying trade-offs in reseller vs shared vs VPS vs dedicated.

One caution: the move to a VPS trades a support relationship for a server administration job. You get root, and you get everything root is responsible for. Plenty of resellers who “outgrew” their plan discover they mostly wanted a faster support queue.

Is cPanel the only option?

No. DirectAdmin is lighter and cheaper, while Plesk supports Windows and offers a stronger developer toolset. Newer alternatives such as Enhance and AdminBolt are also designed for hosting providers seeking modern management tools and more flexible licensing. CyberPanel, aaPanel and CloudPanel are free or near-free options gaining ground, particularly among hosts squeezed by cPanel’s licensing costs.

cPanel still dominates the reseller market, and that has practical consequences worth weighing. Your clients are more likely to have used it before, so the support burden is lower. Freelancers you hire will know it. And the cpmove archive format is widely supported, allowing accounts to move between cPanel hosts with minimal friction.

If you’re building on a non-cPanel platform, most of this guide still applies conceptually. The permission model is broadly the same: you administer customer accounts, while someone else administers the underlying server.

Before you buy: questions to ask your host

Take this list to any reseller provider you’re evaluating. The answers vary far more than the pricing pages suggest.

  1. Does the platform run CloudLinux or equivalent per-account resource isolation?
  2. What are the CPU and memory limits per cPanel account?
  3. What is the inode limit, per account or pooled?
  4. Which WHM ACLs are enabled on reseller accounts?
  5. Can I restore a client account myself, or must I open a ticket?
  6. Are private nameservers included, and is there a charge?
  7. Is a billing platform licence included, and which tier?
  8. Is AutoSSL enabled for reseller accounts?
  9. What is the outgoing email limit, and is mail routed through a relay?
  10. How are PHP extension and firewall requests handled, and what’s the typical turnaround?
  11. Can I add resources to an individual client account without upgrading my whole plan?

For a worked example: on ChemiCloud reseller plans the answers are CloudLinux isolation with 3 GB memory and 2 CPU cores per cPanel account, private nameservers on every plan, a free WHMCS or Blesta licence (Blesta on Kickstart, WHMCS Starter from Grow upward), daily backups, free SSL, overselling enabled, and a Power Boost add-on for raising CPU and memory on individual client accounts without changing plan. Whichever host you choose, get the same eleven answers in writing before you commit clients to it.


Your first week in WHM

A sensible order of operations once your account is live:

  • [ ] Enable two-factor authentication
  • [ ] Set up private nameservers and confirm they resolve — see private nameservers
  • [ ] Apply your branding to the cPanel interface
  • [ ] Build one feature list
  • [ ] Build one package that uses it
  • [ ] Create a test account against that package
  • [ ] Log into the test account as the client and check what they actually see
  • [ ] Run a test migration of a real site you control
  • [ ] Check the account’s resource usage after a day of traffic
  • [ ] Generate a scoped API token if you’re automating
  • [ ] Terminate the test account

Do all of this before onboarding a paying client. The test account will surface three or four things about your setup that you’d otherwise discover in front of a customer.

Frequently asked questions

Is WHM included with reseller hosting? Yes. WHM is what makes an account a reseller account. If a plan offers cPanel without WHM, it’s a shared hosting plan and cannot create separate accounts for clients.

Can a reseller get root access? No. Root is held by your hosting provider and is not available on any reseller plan, regardless of price. Root requires a VPS or dedicated server.

Do I need to buy a cPanel licence as a reseller? No. Your provider holds the server licence and the cost is included in your plan. You’d only pay for a licence if you moved to your own VPS or dedicated server.

Can clients tell that I’m a reseller? Not if you configure white-labelling properly. Private nameservers, branded cPanel and a branded billing system hide the underlying provider. A few seams remain, mostly in email headers and SSL certificate details.

Can I create sub-resellers? On most plans, yes, if your provider enables the Resellers ACL. You can grant a subset of your own permissions to another account, which is useful for agency partners managing their own client rosters.

How many cPanel accounts can I create? Whatever your plan allows. Reseller plans are typically sold by account count alongside disk and bandwidth, ranging from around 30 accounts at entry level to a few hundred at the top.

What’s the difference between a reseller account and a VPS? A reseller account gives you administrative control over accounts on a server someone else manages. A VPS gives you a server you manage entirely, including the operating system, the software stack, security patching and the cPanel licence. Reseller plans trade control for the provider handling everything below the account layer.

Next steps

If the constraints above are workable for your clients, the practical next step is building the plans you’ll sell: how to create hosting packages in WHM covers the mechanics, and how to price reseller hosting plans covers what to charge for them.

Looking for a reseller platform? ChemiCloud’s reseller hosting includes WHM and cPanel, CloudLinux resource isolation, private nameservers and a free billing platform licence on every plan. 

Leave a Comment

Your email address will not be published. Required fields are marked *

Back to Build Sale

Save up to 84% on Hosting + Free Migration!

Related Articles