DirectAdmin checks its licence against the vendor’s servers and fetches updates from the same infrastructure, so licence faults and update faults present together and are worth diagnosing together. The panel usually keeps serving customers when the licence is unhappy, but new logins may be refused, the update channel stalls, and on a long-expired licence the service eventually stops starting. With releases now arriving every two to three weeks, and 1.711 carrying a privilege-escalation fix, a stuck update is a security issue as much as an inconvenience.
Table of Contents
Short answer: Run da license and da version, compare the bound IP with the server’s real addresses and lan_ip, and correct the licence at the vendor’s client area before refreshing with da update. If the update itself fails, test outbound HTTPS and DNS to the download host, check the system clock, and confirm update_channel is set and no cron still relies on update_versions to update the panel.
Read the licence state
The da CLI on modern builds reports the licence and the version in one place:
da version
da license
The licence output shows the licence ID, the type, the expiry and the IP it is bound to. Compare the IP with what the server actually has:
ip -4 addr show | grep inet
da config-get lan_ip
A mismatch is the most common licence error after a migration or a provider-side IP change. The licence is issued for one public IP; if the server now sits behind NAT with a private address, lan_ip must hold the private address and the licence must remain bound to the public one. Licence changes are made in the client area at the vendor, then refreshed on the server:
da update
systemctl restart directadmin
On older non-Go builds the same refresh was ./getLicense.sh under /usr/local/directadmin/scripts/. If you find that script referenced in runbooks, replace the step with da update, which handles both the licence and the binary on current builds.
Update failures
da update downloads the release for the channel set in update_channel and swaps the binary. When it fails, the message names the stage. A download error usually means outbound HTTPS is blocked or the resolver is broken; CSF rules that allow only inbound traffic, or a resolver problem after an Unbound install, produce it. Test the path with curl against the vendor’s download host and check the resolver:
curl -sI https://files.directadmin.com/ | head -1
dig +short files.directadmin.com
A licence error during update means the download server refused to serve the release for this licence. That happens when the licence is expired, when the requested channel is not included in the licence type, or when the server’s IP does not match. The da license output resolves which.
Note that since 1.704 da build update_versions no longer updates DirectAdmin itself; it refreshes CustomBuild’s version list only. Servers with cron entries that relied on the old behaviour have quietly stopped updating the panel. Check the cron and the channel:
grep -r 'update_versions\|da update' /etc/cron* /var/spool/cron/
da config-get update_channel
The stable channel is the right choice for production. The current channel receives the same releases earlier; beta and alpha are for test servers. For the full CLI reference see The da CLI: update, build and config-set.
Hostname problems
The server hostname is not part of the licence, but it affects two things that look like licence problems: the hostname certificate and the panel URL. A hostname that resolves elsewhere causes ACME failures for port 2222’s certificate, which makes browsers warn on login, and a hostname that is also a hosted domain confuses the web-server templates. Set a dedicated hostname that resolves to the server:
/usr/local/directadmin/scripts/hostname.sh server.example.net
/usr/local/directadmin/scripts/letsencrypt.sh server_cert
There is no hostname key in directadmin.conf: on DirectAdmin 1.712, da config-set hostname fails with "Cannot find ‘hostname’ in the directadmin.conf". The bundled hostname.sh calls the same change-hostname API as the Server Settings page, and letsencrypt.sh server_cert then issues the certificate for port 2222, Exim, Dovecot and Pure-FTPd (we ran it on a 1.712 test server: Let’s Encrypt certificate in about 8 seconds).
Check the logs
The relevant lines are in /var/log/directadmin/error.log and /var/log/directadmin/system.log. Licence failures log with the word license and a reason; update failures log the URL attempted. When the panel refuses to start at all, the journal has the reason:
journalctl -u directadmin -n 50
Common pitfall: the clock
A server whose clock is wrong by more than a few minutes fails TLS validation to the licence servers, and the error looks like a network fault. It also breaks ACME issuance. Confirm time synchronisation before spending time on firewall rules:
timedatectl status
chronyc tracking
Verify
After a fix, run da update and confirm it reports the current release, then log into the panel and check the version shown in the admin dashboard matches da version. Confirm the licence page in the panel shows a future expiry date and the correct IP. Finally, set a weekly check in your monitoring that compares da version against the stable release so the next stalled update is noticed within days rather than at the next security advisory.
DirectAdmin license error at a glance

Official documentation: DirectAdmin documentation, Linux man pages.
Related guides: DirectAdmin Service Monitor false restarts and systemd status handling · Exim, Dovecot or DirectAdmin still serving the old certificate after renewal · Routing mail to Google Workspace or Microsoft 365 for a DirectAdmin-hosted domain (and the 1.703 MX check).
Frequently asked questions
Does a DirectAdmin license error stop hosted websites and email?
No. Apache, nginx, Exim and Dovecot run independently of the panel, so sites and mail keep working; what stops is panel logins, automation through the API and updates until the licence is corrected.
How long does a license refresh take after changing the IP at the vendor?
Usually a minute or two: once the licence is updated in the client area, da update fetches the new licence immediately and a systemctl restart directadmin makes the panel pick it up.
Can I undo this?
Yes. Licence bindings can be changed again in the vendor’s client area, update_channel can be set back with da config-set, and a hostname change is reversed with hostnamectl and the matching da config-set call followed by a certificate reissue.