24/7 support for active customersSales Mon–Fri, 8am–5pm
Support article

Complete guide to Websites & Web Roots

This article is part of the Spark Rack Website Hosting knowledgebase and covers Websites & Web Roots.

This article is part of the Spark Rack Website Hosting knowledgebase and covers Websites & Web Roots. This complete guide explains the full customer-facing lifecycle, the safest operating sequence, the checks that confirm success, and the evidence needed when assistance is required.

The relevant customer area is Services > Manage or Control Panel > Websites. It is used to manage hosted websites and web roots, including domains, aliases, document roots, index files, logs, application URLs, and website-level settings. Controls can differ by product, lifecycle status, account permission, domain state, payment method, or service configuration. When an action is not shown, confirm eligibility and permission instead of following an unrelated workaround.

Before you begin

  • Have an active hosting service and domain
  • Know the intended document root
  • Create a current file and database backup
  • Confirm application compatibility with the target PHP settings
  • Schedule production changes during a controlled window
  • Identify the exact item associated with hosted websites and web roots and confirm its current status.
  • Write down the expected result and the current value before changing anything.
  • Plan a rollback or recovery path for any action that can affect access, billing, data, routing, delivery, or availability.

How the feature fits together

Websites & Web Roots is managed through Services > Manage or Control Panel > Websites. The feature covers domains, aliases, document roots, index files, logs, application URLs, and website-level settings. The portal record is the control point, but the final result may also depend on billing state, user permission, service provisioning, application configuration, DNS caches, external providers, or client software. Exact controls vary by product and authorization.

TermMeaning
Account objectThe exact service, domain, invoice, user, conversation, or document being managed.
Current stateThe status and saved values shown before a change begins.
Desired stateThe specific measurable outcome expected after the change.
DependencyAnother setting or external system that must be correct for the outcome to work.
VerificationAn independent test proving the saved configuration produces the intended customer result.
RollbackThe documented method for restoring the last known-good state.

Recommended lifecycle

  1. Identify the exact account item and confirm that it is active, accessible, and owned by the expected customer.
  2. Read notices, status labels, dates, balances, and pending actions before editing anything.
  3. Define the desired outcome in a measurable way and list every dependency that can affect it.
  4. Record the current state and prepare a rollback that does not depend on memory.
  5. Apply the smallest necessary change and allow processing to complete.
  6. Verify both the saved portal value and the real customer-facing behavior.
  7. Document the outcome, remove temporary access, and schedule any follow-up review.

Detailed operating procedure

Use this sequence as the baseline workflow for Websites & Web Roots. Some steps may be informational when the selected product does not expose that exact control, but the verification and recordkeeping principles still apply.

  1. Open the service’s website or configuration area
  2. Confirm the domain, aliases, web root, active status, and current PHP values
  3. Place public files only in the intended document root and keep secrets outside it
  4. Ensure the expected index file exists with correct case
  5. Change one PHP or application setting at a time
  6. Wait for Saving Changes to complete and confirm the same tab shows the new value
  7. Test public pages, administrative pages, forms, scheduled tasks, and logs
  8. Confirm that dependent settings still point to the intended destination and that no older value is overriding the new one.
  9. Observe the result long enough to catch delayed processing, caching, queued work, or an intermittent failure.
  10. Update internal documentation with the final value, date, owner, result, and any scheduled follow-up.

Verification checklist

  • The domain resolves to the intended service
  • The expected index page loads over HTTP and HTTPS
  • Application URLs and assets use correct paths
  • The selected PHP value persists after refresh
  • No new fatal error appears in logs
  • The selected account item, identifier, domain, invoice, user, or service matches the original request.
  • The portal no longer shows a pending or failed action unless delayed processing is expected and documented.
  • An independent customer-side test produces the expected result.
  • Related billing, security, notification, routing, and renewal settings remain correct.
  • The previous value and rollback information are retained until the change is proven stable.

Common failure patterns

Use the symptom to narrow the investigation. Do not apply every possible fix at once.

  • Files are uploaded one directory above or below the web root
  • An index file has incorrect case
  • DNS still points to the old provider
  • A plugin or component is incompatible with the selected PHP version
  • Several runtime settings are changed at once
  • The correct value was saved on the wrong item, environment, domain, mailbox, record, user, or billing account.
  • A dependent setting, external provider, cache, client, or application continues to use an older value.
  • The item is pending, suspended, expired, unpaid, cancelled, locked, or otherwise not eligible for the requested action.
  • The change completed, but verification reused an authenticated session or cached result that hid the actual behavior.
  • A temporary error was treated as permanent and followed by multiple conflicting edits.

Security, privacy, and data handling

  • Use a unique password stored in a reputable password manager and enable two-factor authentication for every account user who can access it.
  • Give each person an individual account user instead of sharing the owner login. Remove access promptly when responsibilities change.
  • Do not send passwords, two-factor recovery codes, full payment-card data, private keys, API secrets, or unredacted identity documents in a normal support reply.
  • Review unexpected sign-in notices, permission changes, domain changes, payment changes, and credential resets as possible security events.
  • After an access-related incident, rotate affected credentials, review delegated users and contacts, verify domains and DNS, and document the recovery actions.
  • Limit access to hosted websites and web roots to people who need it and review that access when responsibilities change.
  • Before sharing evidence involving domains, aliases, document roots, index files, logs, application URLs, and website-level settings, redact information that is not required to diagnose the issue.

When to contact Spark Rack

Contact Spark Rack when the account shows a failed or inconsistent provider-side action, the required control is missing despite confirmed eligibility and permission, data restoration or protected logs are required, an unauthorized change is suspected, or the problem remains after a controlled rollback and independent verification.

  • The account email address and the exact service, domain, invoice, ticket, or other item involved
  • The page and section used, including the tab or subtab, without copying session tokens from the address bar
  • The expected result and the actual result in separate sentences
  • The approximate time of the last successful use and the first failure, including the time zone
  • The exact error text, response code, bounce text, or visible status
  • The changes made immediately before the issue, including old and new values when known
  • The devices, browsers, networks, applications, or external tools used to reproduce the issue
  • The troubleshooting steps already completed and the result of each step

Closeout and ongoing care

After Websites & Web Roots is working, record the final state and remove any temporary access, files, forwarding paths, test records, or broad permissions that were created for the work. Review related expiration dates, renewal settings, payment status, contacts, and alerts so a future administrative event does not recreate the problem.

Keep the support history, change record, and safe verification evidence for as long as they are operationally useful. Periodic review is especially important after staff changes, migrations, major application updates, domain renewals, payment-method changes, or security incidents.