# Restore a File, Database or Account from a DirectAdmin Backup (CLI, Tested)

Source: https://srvscripts.com/guides/restore-directadmin-backup-file-database/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** A DirectAdmin backup is one compressed tar file per account (`user.CREATOR.NAME.tar.zst` on current versions). Website files sit under `domains/` inside it and each database is a plain SQL dump under `backup/`. To bring back one file or one database you do not need to restore the whole account: list the archive with `tar --zstd -tf`, extract the one path, copy it back with the right owner, or feed the SQL dump to `mysql` using the credentials from `da my-cnf`.

We ran every command below on our DirectAdmin test server on 6 October 2026 (DirectAdmin 1.712, AlmaLinux 9.8, MariaDB, three WordPress sites). We broke a site on purpose, restored it from the backup and checked the result; the screenshots are the real terminal output with IP addresses masked.

## How DirectAdmin names and packs backups

Current DirectAdmin versions compress backups with zstd, so the files end in `.tar.zst`; older backups and servers set to gzip end in `.tar.gz`. The name tells you who made the backup and whose it is:

| File name | What it is |
| --- | --- |
| user.admin.bob.tar.zst | User bob, created by the reseller or admin admin |
| reseller.admin.res1.tar.zst | Reseller account res1 |
| admin.root.admin.tar.zst | The admin account itself (what our test produced) |

Inside, the layout we found on DirectAdmin 1.712 is:

- `domains/DOMAIN/public_html/…`: the website files, at the top level of the archive

- `backup/USER_DBNAME.sql`: one dump per database, for example `backup/admin_wp3.sql`. Each table starts with `DROP TABLE IF EXISTS`, and there is no `CREATE DATABASE` or `USE` line, so you choose the target database when you import

- `imap/DOMAIN/MAILBOX/Maildir/…`: the mailboxes, also at the top level

- `backup/home.tar.zst`: the rest of the home directory (dotfiles, `.php` logs)

- `backup/*.conf`, `backup/user.conf`, `backup/.shadow`, `backup/login_keys/` and similar: account settings, password hashes and API login keys. Treat backup files as secret and keep them readable by root and the owner only.

## Make a fresh backup from the command line

If you are about to change something, take a backup first. As root, `da admin-backup` runs the same job as Admin Level → Admin Backup/Transfer and writes the file straight away:

```
mkdir -p /home/admin/admin_backups/manual
chown admin:admin /home/admin/admin_backups/manual
da admin-backup --destination=/home/admin/admin_backups/manual --user=bob
```

`--user` can be repeated for several accounts. On our one-vCPU test server a 132 MB admin account with three WordPress sites took under 7 seconds.

## Restore one file or folder

First find the exact path inside the archive, then extract only that path into a scratch directory and copy it into place with the account owner:

```
B=/home/admin/admin_backups/manual/user.admin.bob.tar.zst
mkdir /root/restore && cd /root/restore
tar --zstd -tf "$B" | grep "example.com/public_html/wp-config.php"
tar --zstd -xf "$B" domains/example.com/public_html/wp-config.php
install -o bob -g bob -m 644 domains/example.com/public_html/wp-config.php \
    /home/bob/domains/example.com/public_html/wp-config.php
cd / && rm -rf /root/restore
```

For a whole folder, extract the folder path instead and copy it with `rsync -a`, then `chown -R bob:bob` the result. Extracting into a scratch directory, rather than with `-C /`, means a typo cannot overwrite live files. Use the permissions the file had (`wp-config.php` is often 600 or 640); 644 is right for ordinary WordPress core files.

In our test we deleted `wp-includes/version.php` from a WordPress site, which made the site return HTTP 500, then restored that one file from the backup. The site returned 200 again straight away:

[](https://srvscripts.com/wp-content/uploads/2026/10/da-file-restore-1006.png)Restoring one deleted WordPress core file from a DirectAdmin backup: HTTP 500 before, 200 after. DirectAdmin 1.712, 6 Oct 2026. IP addresses masked.

## Restore one database

Extract the dump and import it into the existing database. `da my-cnf` prints a MySQL client configuration with DirectAdmin’s own database login; passing it on a file descriptor means the password never appears on the command line or in a file:

```
B=/home/admin/admin_backups/manual/user.admin.bob.tar.zst
mkdir -p /root/restore && cd /root/restore
tar --zstd -xf "$B" backup/bob_wp.sql
mysql --defaults-extra-file=/dev/fd/3 bob_wp < backup/bob_wp.sql 3<
