# Server Brief > Plain-language guides to servers, hosting, DNS and moving websites, with step-by-step fixes for common errors. Every guide shows the date it was last checked and the systems it was written for. Commands are shown in full. ## Hosting - [How much RAM and CPU does a website need?](https://serverbrief.com/how-much-ram-does-a-website-need/): Rough starting sizes for common sites, why memory runs out before CPU, and how to measure what your own site actually uses. - [Managed or unmanaged hosting: which do you need?](https://serverbrief.com/managed-vs-unmanaged-hosting/): The server can be identical. What changes is who installs updates, watches for problems and fixes things at 3 a.m. - [Shared, VPS, dedicated or cloud hosting: what is the difference?](https://serverbrief.com/shared-vps-dedicated-cloud-hosting/): Four labels, one question: how a physical server is divided up, and who looks after your part of it. - [What does 99.9% uptime actually mean?](https://serverbrief.com/what-does-99-9-uptime-mean/): Uptime percentages converted into real downtime per month and year, and what a host's guarantee really promises. - [What is cPanel (and Plesk)?](https://serverbrief.com/what-is-cpanel/): Control panels put a web interface on top of a hosting server, so you can manage sites, email, databases and files without the command line. - [What is web hosting?](https://serverbrief.com/what-is-web-hosting/): A website is a set of files and usually a database. Hosting is the computer that keeps them online and answers every visitor's request, all day, every day. ## Domains & DNS - [DNS record types explained](https://serverbrief.com/dns-record-types-explained/): A, AAAA, CNAME, MX, TXT, NS, CAA and SRV: what each DNS record does, with real examples you can copy. - [How DNS works](https://serverbrief.com/how-dns-works/): DNS turns a name like example.com into the IP address of a server. Here is every step of a lookup, and why caching makes changes take time. - [How to flush your DNS cache](https://serverbrief.com/how-to-flush-your-dns-cache/): Make your computer forget old DNS answers after a site move or record change. Commands for Windows, macOS, Linux and every major browser. - [How to point a domain to a server](https://serverbrief.com/how-to-point-a-domain-to-a-server/): Connect a domain to your hosting by setting A records, adding www, and checking the change before you rely on it. - [How to set up SPF, DKIM and DMARC](https://serverbrief.com/how-to-set-up-spf-dkim-and-dmarc/): Three DNS records that prove your email is really from you, so it reaches inboxes and nobody else can send as your domain. - [What is a nameserver?](https://serverbrief.com/what-is-a-nameserver/): Nameservers hold your domain's DNS records. Changing them moves control of every record to a new provider at once. - [What is DNS propagation, and how long does it take?](https://serverbrief.com/what-is-dns-propagation/): Why a DNS change reaches some people in minutes and others in hours, how to check its progress, and how to make the next change faster. ## Migration - [How to change hosts without downtime](https://serverbrief.com/how-to-change-hosts-without-downtime/): Run the old and new servers side by side, switch DNS when the new one is proven, and keep the old one answering until the world has caught up. - [How to migrate a cPanel account to another cPanel server](https://serverbrief.com/how-to-migrate-cpanel-to-cpanel/): Three ways to move a whole cPanel account (files, databases, email and DNS zone) to a new server, with annotated WHM screenshots for each. - [How to migrate email to a new host](https://serverbrief.com/how-to-migrate-email-to-a-new-host/): Copy mailboxes over IMAP, switch the MX records, and pick up the stragglers, without losing a single message. - [How to move a WordPress site to a new host](https://serverbrief.com/how-to-move-a-wordpress-site-to-a-new-host/): Copy the files and database, test on the new server before anyone else sees it, then switch DNS with the old host kept as your way back. - [Website migration checklist](https://serverbrief.com/website-migration-checklist/): Everything to check before, during and after moving a website to a new host, so nothing is forgotten and nothing breaks. ## DIY - [How to back up a Linux server](https://serverbrief.com/how-to-back-up-a-linux-server/): Dump the databases, copy the files to another machine every night with rsync and cron, and prove the backup works by restoring it. - [How to connect to a server with SSH](https://serverbrief.com/how-to-connect-to-a-server-with-ssh/): Open a secure command line on a remote server from Windows, macOS or Linux, and understand the host key prompt you see the first time. - [How to get a free SSL certificate with Let's Encrypt](https://serverbrief.com/how-to-get-a-free-ssl-certificate-with-lets-encrypt/): Issue a trusted HTTPS certificate in one command with Certbot, redirect HTTP to HTTPS, and make sure it renews by itself. - [How to install Nginx on Ubuntu](https://serverbrief.com/how-to-install-nginx-on-ubuntu/): Install Nginx, serve your first site from its own folder, and learn the three commands you will use every time you change its configuration. - [How to set up a firewall on Linux](https://serverbrief.com/how-to-set-up-a-firewall-on-linux/): Block everything except SSH and the web with UFW on Ubuntu or firewalld on RHEL-based systems, without locking yourself out. - [How to set up SSH keys](https://serverbrief.com/how-to-set-up-ssh-keys/): Replace passwords with a key pair, log in without typing a password, and then switch password login off for good. - [How to turn on automatic security updates](https://serverbrief.com/how-to-turn-on-automatic-security-updates/): Have the server install security patches by itself every day, on Ubuntu with unattended-upgrades and on RHEL-based systems with dnf-automatic. ## Concepts - [How HTTPS works](https://serverbrief.com/how-https-works/): What the padlock actually means, what a certificate proves, and what happens in the first fraction of a second of every secure connection. - [RAID levels explained: 0, 1, 5, 6 and 10](https://serverbrief.com/raid-levels-explained/): How each RAID level spreads data across disks, how many failures it survives, how much space you keep, and why RAID is still not a backup. - [What is a CDN?](https://serverbrief.com/what-is-a-cdn/): A content delivery network keeps copies of your site's files in data centers around the world, so visitors download them from somewhere close. - [What is a port number?](https://serverbrief.com/what-is-a-port-number/): If an IP address finds the server, the port finds the right program on it. The common ports, and how to see which ones are open. - [What is a reverse proxy?](https://serverbrief.com/what-is-a-reverse-proxy/): A server that stands in front of your other servers, takes every request and decides who answers. What it does, when you need one, and a working Nginx example. - [What is an IP address? IPv4 and IPv6 explained](https://serverbrief.com/what-is-an-ip-address/): The number every device on the internet uses to find every other device, the difference between IPv4 and IPv6, and public versus private addresses. - [What is caching? Browser, page and object caches](https://serverbrief.com/what-is-caching/): Caching keeps a ready-made copy of something so it does not have to be built again. The layers that make websites fast, and when each one helps. ## Troubleshooting - [How to fix "Error establishing a database connection"](https://serverbrief.com/how-to-fix-error-establishing-a-database-connection/): WordPress cannot reach its database. Either the login details are wrong, the database server is down, or the database itself is damaged. - [How to fix "Your connection is not private"](https://serverbrief.com/how-to-fix-your-connection-is-not-private/): The browser does not trust the site's certificate. What each NET::ERR_CERT code means, and how to fix it on either side. - [How to fix 403 Forbidden](https://serverbrief.com/how-to-fix-403-forbidden/): The server found the page but will not show it. Usually file permissions, a missing index file, or a security rule. Here is how to tell which. - [How to fix 404 Not Found errors on your site](https://serverbrief.com/how-to-fix-404-not-found-errors/): A few 404s are normal. Sudden ones, or every page except the home page, point to a broken rewrite, a moved page or a bad link. How to find and fix them. - [How to fix 429 Too Many Requests](https://serverbrief.com/how-to-fix-429-too-many-requests/): A rate limit was hit. Slow down if you are the visitor; if you run the site, decide whether the limit is protecting you or blocking real people. - [How to fix 500 Internal Server Error](https://serverbrief.com/how-to-fix-500-internal-server-error/): A 500 is the server's way of saying "something broke and I won't say what". The error log will. Here is where to find it and what it usually says. - [How to fix 502 Bad Gateway](https://serverbrief.com/how-to-fix-502-bad-gateway/): A 502 means the web server asked the program behind it for a page and got no usable answer. Find which part failed in five checks. - [How to fix 503 Service Unavailable](https://serverbrief.com/how-to-fix-503-service-unavailable/): The server is up but refusing work for now: maintenance mode, an overload, or a limit being hit. How to tell which, and clear it. - [How to fix 504 Gateway Timeout](https://serverbrief.com/how-to-fix-504-gateway-timeout/): The backend is alive but too slow. Find the slow request, raise the right timeout only if the work is genuinely long, and fix the cause. - [How to fix DNS_PROBE_FINISHED_NXDOMAIN](https://serverbrief.com/how-to-fix-dns-probe-finished-nxdomain/): The browser asked DNS for the site's address and was told the name does not exist. Check the spelling, your own DNS, then the domain itself. - [How to fix ERR_CONNECTION_REFUSED](https://serverbrief.com/how-to-fix-err-connection-refused/): The server answered, but nothing was listening on that port. Usually the web server is stopped, listening elsewhere, or a firewall rejects you. - [How to fix ERR_SSL_PROTOCOL_ERROR](https://serverbrief.com/how-to-fix-err-ssl-protocol-error/): The browser and server could not agree on a secure connection at all. Usually HTTPS is not set up on that port, or the configuration is broken. - [How to fix ERR_TOO_MANY_REDIRECTS](https://serverbrief.com/how-to-fix-err-too-many-redirects/): Two rules are sending visitors back and forth forever. Usually HTTP and HTTPS, or www and non-www, set differently in two places. - [How to fix the WordPress white screen of death](https://serverbrief.com/how-to-fix-wordpress-white-screen-of-death/): A blank page or "There has been a critical error" means PHP stopped with a fatal error. Find the plugin or theme responsible and switch it off. - [Why do my emails go to spam?](https://serverbrief.com/why-emails-go-to-spam/): Most legitimate mail lands in spam for fixable reasons: missing SPF, DKIM or DMARC, a server with a poor reputation, or a site sending mail it is not allowed to. ## Glossary - [A record](https://serverbrief.com/glossary/a-record/): A DNS record that points a hostname to an IPv4 address. - [AAAA record](https://serverbrief.com/glossary/aaaa-record/): A DNS record that points a hostname to an IPv6 address. - [Apache](https://serverbrief.com/glossary/apache/): A long-established open-source web server, known for per-folder configuration with .htaccess files. - [Bandwidth](https://serverbrief.com/glossary/bandwidth/): The amount of data a hosting plan lets your site send to visitors, usually measured per month. - [Cache](https://serverbrief.com/glossary/cache/): A stored copy of something expensive to produce, kept so later requests can be answered instantly. - [CDN](https://serverbrief.com/glossary/cdn/): A content delivery network: servers around the world that keep copies of your files close to visitors. - [Certificate authority](https://serverbrief.com/glossary/certificate-authority/): An organisation trusted by browsers to issue SSL/TLS certificates after checking who controls a domain. - [CNAME record](https://serverbrief.com/glossary/cname-record/): A DNS record that makes one hostname an alias of another. - [Control panel](https://serverbrief.com/glossary/control-panel/): A web interface for managing hosting without the command line, such as cPanel or Plesk. - [cPanel](https://serverbrief.com/glossary/cpanel/): The most widely used hosting control panel, especially on shared hosting. - [Cron job](https://serverbrief.com/glossary/cron-job/): A command scheduled to run automatically at set times on a Linux server. - [DDoS](https://serverbrief.com/glossary/ddos/): A distributed denial-of-service attack: flooding a site with traffic from many machines to knock it offline. - [Dedicated server](https://serverbrief.com/glossary/dedicated-server/): A whole physical server rented to one customer. - [DKIM](https://serverbrief.com/glossary/dkim/): An email signature, checked against a public key in DNS, that proves a message came from your domain unchanged. - [DMARC](https://serverbrief.com/glossary/dmarc/): A DNS policy that tells receiving mail servers what to do when SPF and DKIM checks fail, and where to send reports. - [DNS](https://serverbrief.com/glossary/dns/): The Domain Name System, which turns names like example.com into the IP addresses computers use. - [Domain registrar](https://serverbrief.com/glossary/domain-registrar/): The company you register and renew a domain name through. - [Firewall](https://serverbrief.com/glossary/firewall/): Software or hardware that decides which network connections may reach a server. - [HTTP status code](https://serverbrief.com/glossary/http-status-code/): The three-digit number a server sends with every response, saying whether the request worked. - [HTTPS](https://serverbrief.com/glossary/https/): Web traffic sent inside an encrypted TLS connection, shown by the padlock in the address bar. - [Inode](https://serverbrief.com/glossary/inode/): A record the file system keeps for every file and folder; shared hosts often limit how many you may have. - [IP address](https://serverbrief.com/glossary/ip-address/): The number that identifies a device on a network, such as 203.0.113.10. - [Latency](https://serverbrief.com/glossary/latency/): The delay before data starts arriving, usually measured in milliseconds. - [Let's Encrypt](https://serverbrief.com/glossary/lets-encrypt/): A free, automated certificate authority that issues trusted 90-day HTTPS certificates. - [Load balancer](https://serverbrief.com/glossary/load-balancer/): A server that spreads incoming traffic across several backend servers. - [MX record](https://serverbrief.com/glossary/mx-record/): A DNS record naming the mail server that receives email for a domain, with a priority number. - [Nameserver](https://serverbrief.com/glossary/nameserver/): A server that holds a domain's DNS records and answers lookups for them. - [Nginx](https://serverbrief.com/glossary/nginx/): A fast, widely used web server and reverse proxy. - [PHP-FPM](https://serverbrief.com/glossary/php-fpm/): The service that runs PHP code for web servers like Nginx, using a pool of worker processes. - [Port](https://serverbrief.com/glossary/port/): A number from 0 to 65535 that directs network traffic to a particular program on a server. - [Propagation](https://serverbrief.com/glossary/propagation/): The time it takes for a DNS change to be seen everywhere, as cached copies of the old record expire. - [RAID](https://serverbrief.com/glossary/raid/): A way of combining several disks so they act as one, for speed, protection against a failed disk, or both. - [Reverse proxy](https://serverbrief.com/glossary/reverse-proxy/): A server that receives requests on behalf of other servers and passes them along. - [Root access](https://serverbrief.com/glossary/root-access/): Full administrator control of a server, with permission to change anything. - [SFTP](https://serverbrief.com/glossary/sftp/): A secure way to transfer files to and from a server over an SSH connection. - [Shared hosting](https://serverbrief.com/glossary/shared-hosting/): Hosting where many websites share one server and the host manages it. - [SPF](https://serverbrief.com/glossary/spf/): A DNS record listing which servers may send email for your domain. - [SSH](https://serverbrief.com/glossary/ssh/): Secure Shell: an encrypted way to log in to and run commands on a remote server. - [SSL/TLS certificate](https://serverbrief.com/glossary/ssl-tls-certificate/): A file that binds a domain name to a public key, signed by a certificate authority, enabling HTTPS. - [Subdomain](https://serverbrief.com/glossary/subdomain/): A name inside your domain, such as blog.example.com or www.example.com. - [TTL](https://serverbrief.com/glossary/ttl/): Time to live: how many seconds resolvers may cache a DNS record before asking again. - [TXT record](https://serverbrief.com/glossary/txt-record/): A DNS record that holds text, used for domain verification and email security. - [Uptime](https://serverbrief.com/glossary/uptime/): The share of time a site or server is available, usually given as a percentage. - [VPS](https://serverbrief.com/glossary/vps/): A virtual private server: a virtual machine with guaranteed resources and full control, on shared hardware. - [Web server](https://serverbrief.com/glossary/web-server/): The software that receives requests from browsers and sends back pages and files. - [WHM](https://serverbrief.com/glossary/whm/): WebHost Manager: the administrator side of cPanel, used to create and manage hosting accounts. - [WHOIS](https://serverbrief.com/glossary/whois/): A lookup that shows a domain's registrar, registration dates, status and nameservers. ## Optional - [All guides](https://serverbrief.com/guides/) - [About Server Brief](https://serverbrief.com/about/)