The server and hosting roadmap

Every guide on Server Brief in seven stages, from how a domain reaches a server to running, speeding up, moving and fixing your own. Follow it start to finish, or jump in at the stage that matches what you need today.

  • 7 stages
  • 47 guides
  • ~3.5 hr of reading
  • 7 hands-on checkpoints

0 of 47 guides read

Tick guides as you finish them. Progress is saved in this browser only.

Start from your goal

  1. Stage 1

    How the web reaches a server

    Beginner 5 guides ~22 min 0/5 read

    The handful of ideas every other guide builds on: what a server is, how a name becomes an address, and what the padlock really means.

    By the end you can

    • Explain what happens between typing a domain and seeing a page
    • Tell an IP address, a port and a domain apart
    • Say what HTTPS protects, and what it does not

    Read in this order

    1. What is web hosting?

      A website is a set of files and usually a database.

      Explainer5 min

    2. What is an IP address? IPv4 and IPv6 explained

      The number every device on the internet uses to find every other device, the difference between IPv4 and IPv6, and public versus private addresses.

      Explainer4 min

    3. What is a port number?

      If an IP address finds the server, the port finds the right program on it.

      Explainer3 min

    4. How DNS works

      DNS turns a name like example.com into the IP address of a server.

      Explainer5 min

    5. How HTTPS works

      What the padlock actually means, what a certificate proves, and what happens in the first fraction of a second of every secure connection.

      Explainer5 min

    Checkpoint

    Read a website like a server does

    1. Run dig example.com +short on your own domain and find the IP address it returns.
    2. Run curl -I https://example.com and identify the status code and the server software.
    3. Open the padlock in your browser and find who issued the certificate and when it expires.

    Words to know IP address Port DNS Web server HTTPS HTTP status code

  2. Stage 2

    Domains and DNS

    Beginner 6 guides ~26 min 0/6 read

    Take control of your domain: who holds its records, what each record does, and how to change them without breaking the website or email.

    By the end you can

    • Point a domain or subdomain at any server
    • Read and write A, CNAME, MX and TXT records
    • Plan a DNS change so it takes minutes, not days
    • Publish SPF, DKIM and DMARC so your email is trusted

    Read in this order

    1. DNS record types explained

      A, AAAA, CNAME, MX, TXT, NS, CAA and SRV: what each DNS record does, with real examples you can copy.

      Reference5 min

    2. What is a nameserver?

      Nameservers hold your domain's DNS records.

      Explainer4 min

    3. How to point a domain to a server

      Connect a domain to your hosting by setting A records, adding www, and checking the change before you rely on it.

      How-to4 min

    4. What is DNS propagation, and how long does it take?

      Why a DNS change reaches some people in minutes and others in hours, how to check its progress, and how to make the next change faster.

      Explainer4 min

    5. How to set up SPF, DKIM and DMARC

      Three DNS records that prove your email is really from you, so it reaches inboxes and nobody else can send as your domain.

      How-to5 min

    Go further

    1. How to flush your DNS cache

      Make your computer forget old DNS answers after a site move or record change.

      How-to4 minOptional

    Checkpoint

    Make a safe DNS change

    1. Find which nameservers control your domain with dig NS example.com +short.
    2. Create a test subdomain, such as test.example.com, with a TTL of 300, pointing at any server.
    3. Check it from two public resolvers, @1.1.1.1 and @8.8.8.8, and watch the TTL count down.
    4. Publish a DMARC record with p=none and a report address.

    Words to know A record CNAME record MX record TXT record TTL Nameserver Domain registrar WHOIS SPF DKIM DMARC

  3. Stage 3

    Choosing hosting

    Beginner 5 guides ~20 min 0/5 read

    Read hosting plans for what they really offer, size a server from your own numbers, and decide how much of the running you want to do yourself.

    By the end you can

    • Choose between shared, VPS, dedicated and cloud for a given site
    • Size memory and CPU from real usage, not plan names
    • Decide between managed and unmanaged with eyes open
    • Read an uptime guarantee for what it actually promises

    Read in this order

    1. Shared, VPS, dedicated or cloud hosting: what is the difference?

      Four labels, one question: how a physical server is divided up, and who looks after your part of it.

      Comparison4 min

    2. Managed or unmanaged hosting: which do you need?

      The server can be identical.

      Comparison4 min

    3. How much RAM and CPU does a website need?

      Rough starting sizes for common sites, why memory runs out before CPU, and how to measure what your own site actually uses.

      Explainer5 min

    4. What does 99.9% uptime actually mean?

      Uptime percentages converted into real downtime per month and year, and what a host's guarantee really promises.

      Reference3 min

    Go further

    1. What is cPanel (and Plesk)?

      Control panels put a web interface on top of a hosting server, so you can manage sites, email, databases and files without the command line.

      Explainer4 minOptional

    Checkpoint

    Write your hosting brief

    1. List what the site runs (CMS, PHP version, database) and where most visitors are.
    2. Estimate monthly transfer from page weight times monthly visits.
    3. Pick a type and a memory size, and write down why.
    4. Check the renewal price, backup policy and how you would leave.

    Words to know Shared hosting VPS Dedicated server Bandwidth Inode Uptime Control panel Root access

  4. Stage 4

    Your first server

    Intermediate 7 guides ~28 min 0/7 read

    From a fresh VPS to a locked-down server serving your site over HTTPS, with updates and backups running on their own.

    By the end you can

    • Log in with SSH keys and no passwords
    • Run a firewall that only opens what you need
    • Serve a site with Nginx and a free certificate
    • Keep the server patched and backed up without remembering to

    Read in this order

    1. How to connect to a server with SSH

      Open a secure command line on a remote server from Windows, macOS or Linux, and understand the host key prompt you see the first time.

      How-to4 min

    2. How to set up SSH keys

      Replace passwords with a key pair, log in without typing a password, and then switch password login off for good.

      How-to4 min

    3. How to set up a firewall on Linux

      Block everything except SSH and the web with UFW on Ubuntu or firewalld on RHEL-based systems, without locking yourself out.

      How-to4 min

    4. How to turn on automatic security updates

      Have the server install security patches by itself every day, on Ubuntu with unattended-upgrades and on RHEL-based systems with dnf-automatic.

      How-to3 min

    5. How to install Nginx on Ubuntu

      Install Nginx, serve your first site from its own folder, and learn the three commands you will use every time you change its configuration.

      How-to4 min

    6. How to get a free SSL certificate with Let’s Encrypt

      Issue a trusted HTTPS certificate in one command with Certbot, redirect HTTP to HTTPS, and make sure it renews by itself.

      How-to4 min

    7. How to back up a Linux server

      Dump the databases, copy the files to another machine every night with rsync and cron, and prove the backup works by restoring it.

      How-to5 min

    Checkpoint

    A server you would trust with a real site

    1. Password login is off; ssh works only with your key.
    2. sudo ufw status (or firewall-cmd --list-all) shows only SSH, HTTP and HTTPS.
    3. curl -I https://your-domain returns 200 with a valid certificate.
    4. A backup ran last night, and you have restored one file from it.

    Words to know SSH SFTP Firewall Nginx Let’s Encrypt SSL/TLS certificate Cron job Root access

  5. Stage 5

    Speed and scale

    Intermediate 4 guides ~16 min 0/4 read

    Make the same server handle many times the traffic, serve visitors from nearby, and put apps safely behind a proxy.

    By the end you can

    • Pick the right cache layer for a slow page
    • Decide when a CDN is worth it, and set one up safely
    • Run an app behind Nginx as a reverse proxy
    • Choose disk redundancy without mistaking it for backup

    Read in this order

    1. What is caching? Browser, page and object caches

      Caching keeps a ready-made copy of something so it does not have to be built again.

      Explainer4 min

    2. What is a CDN?

      A content delivery network keeps copies of your site's files in data centers around the world, so visitors download them from somewhere close.

      Explainer4 min

    3. What is a reverse proxy?

      A server that stands in front of your other servers, takes every request and decides who answers.

      Explainer4 min

    Go further

    1. RAID levels explained: 0, 1, 5, 6 and 10

      How each RAID level spreads data across disks, how many failures it survives, how much space you keep, and why RAID is still not a backup.

      Reference4 minOptional

    Checkpoint

    Measure, cache, measure again

    1. Record time to first byte: curl -o /dev/null -s -w "%{time_starttransfer}\n" https://your-domain/.
    2. Turn on a page cache and confirm a HIT header on the second request.
    3. Measure again and compare.

    Words to know Cache CDN Latency Reverse proxy Load balancer PHP-FPM DDoS RAID

  6. Stage 6

    Moving sites

    Intermediate 5 guides ~21 min 0/5 read

    Move websites and email between hosts in an order that keeps everything working, with a way back if it does not.

    By the end you can

    • Plan a move so nothing the old host did is forgotten
    • Copy a WordPress site and its database to a new server
    • Switch DNS with no visible downtime
    • Move mailboxes without losing a message

    Read in this order

    1. Website migration checklist

      Everything to check before, during and after moving a website to a new host, so nothing is forgotten and nothing breaks.

      Checklist4 min

    2. How to change hosts without downtime

      Run the old and new servers side by side, switch DNS when the new one is proven, and keep the old one answering until the world has caught up.

      How-to4 min

    3. How to move a WordPress site to a new host

      Copy the files and database, test on the new server before anyone else sees it, then switch DNS with the old host kept as your way back.

      How-to5 min

    4. How to migrate email to a new host

      Copy mailboxes over IMAP, switch the MX records, and pick up the stragglers, without losing a single message.

      How-to3 min

    Go further

    1. How to migrate a cPanel account to another cPanel server

      Three ways to move a whole cPanel account (files, databases, email and DNS zone) to a new server, with annotated WHM screenshots for each.

      How-to5 minOptional

    Checkpoint

    Rehearse a move

    1. Copy a test site to a second server.
    2. Test it through your hosts file before touching DNS.
    3. Switch a low-TTL record, then switch it back, and time both.

    Words to know TTL A record MX record cPanel WHM Propagation

  7. Stage 7

    Fixing what breaks

    Intermediate 15 guides ~1 hr 0/15 read

    Read an error, find which layer failed, and fix it. Grouped by what you see, so you can also jump straight here when something is down.

    By the end you can

    • Tell from an error page which part of the stack failed
    • Find the log line that explains it
    • Fix the common causes of every major web error

    Server errors (5xx)

    1. How to fix 502 Bad Gateway

      A 502 means the web server asked the program behind it for a page and got no usable answer.

      Fix7 min

    2. How to fix 504 Gateway Timeout

      The backend is alive but too slow.

      Fix5 min

    3. How to fix 500 Internal Server Error

      A 500 is the server's way of saying "something broke and I won't say what".

      Fix5 min

    4. How to fix 503 Service Unavailable

      The server is up but refusing work for now: maintenance mode, an overload, or a limit being hit.

      Fix5 min

    Access errors (4xx)

    1. How to fix 403 Forbidden

      The server found the page but will not show it.

      Fix5 min

    2. How to fix 404 Not Found errors on your site

      A few 404s are normal.

      Fix5 min

    3. How to fix 429 Too Many Requests

      A rate limit was hit.

      Fix5 min

    Connection and HTTPS

    1. How to fix DNS_PROBE_FINISHED_NXDOMAIN

      The browser asked DNS for the site's address and was told the name does not exist.

      Fix5 min

    2. How to fix ERR_CONNECTION_REFUSED

      The server answered, but nothing was listening on that port.

      Fix4 min

    3. How to fix “Your connection is not private”

      The browser does not trust the site's certificate.

      Fix5 min

    4. How to fix ERR_SSL_PROTOCOL_ERROR

      The browser and server could not agree on a secure connection at all.

      Fix4 min

    5. How to fix ERR_TOO_MANY_REDIRECTS

      Two rules are sending visitors back and forth forever.

      Fix4 min

    WordPress and email

    1. How to fix “Error establishing a database connection”

      WordPress cannot reach its database.

      Fix5 min

    2. How to fix the WordPress white screen of death

      A blank page or "There has been a critical error" means PHP stopped with a fatal error.

      Fix4 min

    3. Why do my emails go to spam?

      Most legitimate mail lands in spam for fixable reasons: missing SPF, DKIM or DMARC, a server with a poor reputation, or a site sending mail it is not allowed to.

      Fix5 min

    Checkpoint

    Know where to look before you need to

    1. Find your web server's error log and read its last 20 lines.
    2. Find PHP-FPM's log, and your database's.
    3. Write the three paths somewhere you will find them during an outage.

    Words to know HTTP status code PHP-FPM Web server Apache