Emergency server help: get in touch

cPanel Temporary Domain: Free *.cpanel.site Setup

cPanel & WHM 132 introduced temporary *.cpanel.site domains so a site can be built and previewed before its real domain points at the server. This guide covers enabling the feature, creating accounts with a temporary domain and switching to the real one.

Published Updated 7 min read

Building a site before the customer’s domain has been registered, transferred or repointed used to mean hosts-file hacks, preview URLs with the server IP, or a throwaway subdomain of the provider’s own domain. cPanel & WHM 132, released in October 2025, added temporary domains under cpanel.site: a generated hostname that resolves immediately, gets an AutoSSL certificate, and serves the account’s document root until the real domain is attached. This guide covers switching the feature on, using it when creating accounts, and the cutover to the customer’s domain.

Short answer: Turn on the option in WHM → Tweak Settings → Domains (whmapi1 set_tweaksetting key=allow_cpanel_site_temporary_domains value=1), then tick the temporary domain box when creating the account; cPanel assigns a generated *.cpanel.site name that resolves within minutes and gets an AutoSSL certificate. When the real domain is ready, rename the primary domain in place with whmapi1 modifyacct user=USER DNS=example.com on 138, or park the real domain on the account on any version, then update WordPress URLs and remove the temporary alias.

How temporary domains work

When the feature is enabled, WHM can create an account whose primary domain is a randomly generated name such as bright-river-4f2a.cpanel.site. The name is registered in a DNS zone that cPanel operates, pointed at your server’s IP, and issued a certificate by AutoSSL on the next run. The account behaves exactly like any other: it has a document root, mail routing, databases and FTP. The cpanel.site name is intended for previews, not for production mail, and it is not something to advertise to end users as permanent.

The feature depends on the server being able to reach cPanel’s registration service and on a licence in good standing. It is available on 132 and later on every tier, so both LTS 134 and RELEASE 138 servers can use it.

Enable the feature in WHM

Go to WHM → Server Configuration → Tweak Settings → Domains and enable the temporary domain option. The setting name in the interface refers to cpanel.site domains; toggle it on and save. From the shell:

whmapi1 set_tweaksetting key=allow_cpanel_site_temporary_domains value=1
whmapi1 get_tweaksetting key=allow_cpanel_site_temporary_domains

If the key name differs on your build, whmapi1 get_tweaksetting with no key lists them all; search for cpanel_site in the output. Once enabled, the Create a New Account page in WHM shows a checkbox to use a temporary domain instead of typing one, and the corresponding API parameter becomes available.

Resellers can be given the ability through their ACL, so that they can create preview accounts for their own customers; review WHM → Resellers → Edit Reseller Nameservers and Privileges if that is wanted.

Create an account with a temporary domain

In WHM → Account Functions → Create a New Account, tick the temporary domain option. The domain field is filled with a generated name, and the username and password are set as usual. Create the account and note the domain from the confirmation screen.

From the shell the same account is created by asking createacct for a temporary domain rather than supplying one; check the API documentation for your build for the exact parameter, as it has been adjusted between releases. A portable approach is to create the account and then read back the assigned domain:

whmapi1 createacct username=previewacct password='<strong password>' \
  plan=default_plan use_temporary_domain=1
whmapi1 accountsummary user=previewacct | grep -E 'domain|ip'

Within a few minutes the domain resolves, and after the next AutoSSL run it has a valid certificate. Run /usr/local/cpanel/bin/autossl_check --user=previewacct to bring that forward. The developer can now upload the site, install WordPress through WP Toolkit and share the preview link.

Move the real domain onto the account

When the customer’s domain is ready, you have two options. The clean one, on cPanel 138 and later, is to rename the primary domain in place. WHM → Account Functions → Modify an Account lets you change the primary domain, and 138 extended this to handle addon domains too:

whmapi1 modifyacct user=previewacct DNS=example.com

The account’s document root, mail accounts and databases are preserved; cPanel creates the new zone, rewrites the virtual host, and can keep the cpanel.site name as an alias for a short overlap period. The domain rename guide covers what happens to mail and SSL during the change.

The other option, on any version, is to add the real domain as an alias (parked domain) of the temporary one, which is enough for the site to be reachable under both names:

uapi --user=previewacct DomainInfo list_domains
whmapi1 park domain=example.com user=previewacct

Parking is appropriate for a preview-then-launch workflow where the site’s application does not care about its hostname. WordPress does care: its site URL and home URL are stored in the database, so after the switch use WP Toolkit’s change-URL tool or wp search-replace to update them.

Point the real domain’s DNS at the server, wait for AutoSSL to cover the new name, and then remove the temporary domain or leave it in place as an alias. Removing it stops the cpanel.site name from serving the site, which is what most customers want once they have launched.

Verify

Confirm both names resolve and serve the right content:

dig +short bright-river-4f2a.cpanel.site
dig +short example.com
curl -sI https://example.com/ | head -5
uapi --user=previewacct SSL installed_hosts | grep -A3 'example.com'

The SSL check should show a certificate covering the real domain after AutoSSL has run. For a WordPress site, load the admin area under the real domain and confirm no links point back to the temporary name.

Common pitfall

The commonest problem is search engines indexing the cpanel.site preview because a developer shared the link publicly or a crawler found it. Set the site to discourage indexing while it lives on the temporary domain, or add a robots.txt disallow, and remove the temporary alias promptly after launch. The second is expecting mail to work from the temporary domain; it is a preview address and receivers treat unfamiliar shared domains with suspicion. Configure mail only once the real domain is attached and its SPF, DKIM and DMARC records are in place.

CPanel temporary domain at a glance

cPanel Temporary Domain summary card: Turn on the option in WHM → Tweak Settings → Domains (whmapi1 set_tweaksetting key=allow_cpanel_site_temporary_domains…
In short: Turn on the option in WHM → Tweak Settings → Domains (whmapi1 set_tweaksetting key=allow_cpanel_site_temporary_domains value=1), then tick the temporary domain box when creating the account; cPanel assigns a generated *.cpanel.site name…

Official documentation: cPanel & WHM documentation, Linux man pages.

Related guides: Cloudflare in front of cPanel: DNS, proxy mode and real visitor IPs done right · Renaming a primary or addon domain in place (cPanel 138+) · CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting.

Frequently asked questions

Does a temporary cpanel.site domain work for email?

Mail routes for it technically, but it is a shared preview domain that receivers treat with suspicion, so configure mail only after the real domain is attached with SPF, DKIM and DMARC records in place.

How long does a cpanel.site domain take to resolve and get SSL?

The name usually resolves within a few minutes of account creation, and AutoSSL issues a certificate on its next daily run; running autossl_check for the account brings that forward to minutes.

Can I keep the cpanel.site name after moving the real domain onto the account?

Yes. On 138 the rename can keep it as an alias for an overlap period, and on any version a parked domain leaves both names serving the site; remove the alias after launch so search engines do not index the preview.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.