cPanel DNS Manager connects WHMCS to cPanel/WHM or DNSONLY through the WHM API. It provides addon-based domain DNS management and a server module for standalone DNS hosting products. DNSSEC operations use a separate PowerDNS API connection.
This guide documents the module for existing installations. Contact ArkHost to confirm availability and package compatibility before a new purchase.
Before installation
- Use WHMCS 8.9 or newer and a PHP version compatible with your WHMCS release and module package, with cURL enabled.
- Have a valid module license and access to a cPanel/WHM or DNSONLY server.
- Create a dedicated WHM API token with the Manage DNS Records privilege. Use the WHM username that owns the token.
- Back up the WHMCS database, module files, and DNS zones.
Install and configure the addon
- Upload the package's
modules/tree to WHMCS. Keep bothmodules/addons/cpanel_dnsonly_manager/andmodules/servers/cpanel_dnsonly_manager/; do not rename them. - Open System Settings > Addon Modules and activate cPanel DNS Manager.
- Open Configure, enter your license key, and grant access to the required administrator roles.
- Enter the WHM hostname, token, token owner's username, and port. The default WHM port is
2087. Keep SSL enabled. - Set the nameservers for new zones, default TTL, and public resolver used for nameserver checks. NS3 through NS5 are optional; the default TTL is 3600 seconds.
- Save and test with a non-production zone before enabling automated setup for customers.
Set up a DNS hosting product
- Under System Settings > Servers, create a server entry using
cpanel_dnsonly_managerand the WHM connection details, then place it in the intended server group. - Create the DNS hosting product and enable Require Domain on its Details tab.
- On Module Settings, select
cpanel_dnsonly_managerand the intended server group. - Select the automatic setup trigger appropriate for your order workflow and save.
- Test provisioning with a domain you control, then verify the zone and its records on the DNS server.
The provisioning code reads its API connection from the addon settings. A WHMCS server group does not, by itself, select a different WHM backend in this build.
The service domain becomes the zone name. New standalone zones are assigned to cPanel's system user. Existing zones also need a valid owner. A zone visible in WHM can still return You do not have access to a domain named ... when its ownership is missing or incorrect.
Manage records and import zones
The module supports A, AAAA, CNAME, MX, TXT, SRV, CAA, NS, and TLSA records with per-record TTLs. Clients manage their associated zones; administrators can manage zones through the addon. Default nameserver records are protected from client changes.
Import BIND-format zone data using merge, replace, or append mode. Export and back up the current zone first, review the imported records, and test on a disposable zone if you are unsure which mode to use. Replace mode can remove records the domain still needs.
Use the nameserver checker to review delegation. A successful check does not prove that every resolver has refreshed its cached records. Changes take time according to the previous TTL and parent delegation.
DNSSEC prerequisites
Basic zones and records use WHM. For DNSSEC, the module requires a PowerDNS authoritative service and its REST API to manage the same zone. Do not assume that every cPanel installation has that arrangement or that enabling an unrelated PowerDNS API will sign the zone served to the public.
Have the DNS server administrator verify the authoritative backend and configure a restricted API endpoint. Use a private management route or an appropriately protected HTTPS endpoint, a dedicated API key, and a source allowlist limited to the WHMCS server. Do not expose the API to all addresses or open its port globally.
Enter the PowerDNS API URL, PowerDNS API Key, and PowerDNS Server Name in the addon. The server identifier defaults to localhost; use the identifier reported by your actual API.
Enable and verify DNSSEC
- Start with a non-production zone served by the intended authoritative backend.
- Enable DNSSEC in the module and check the generated keys and DS records.
- Publish the correct DS record at the domain's registrar only after confirming the authoritative zone is signed and answering correctly.
- Check the complete DNSSEC chain after delegation changes have propagated.
Disabling signing while a DS record remains at the parent can break validating DNS lookups. Plan removal or replacement of the registrar DS record before disabling DNSSEC or rotating keys.
Automation
The registration hook creates zones; the transfer hook associates an existing zone or creates one. Domain deletion and service termination perform removal or association cleanup according to the relevant hook. Test these lifecycle actions before enabling them for production services, especially where other systems share the DNS server.
After termination, check the zone directly on the DNS server. This build can remove the WHMCS association and return success even when backend zone deletion fails. Suspension and unsuspension do not disable or re-enable DNS service.
Troubleshooting
- For connection failures, check the hostname, port, network restrictions, token, and token owner's username.
- For permission errors, check the token's Manage DNS Records privilege and the zone's ownership.
- If registration does not create a zone, review the WHMCS activity log and the failed API operation. Do not assume a later scheduled retry will repair it.
- For DNSSEC failures, check the separate PowerDNS URL, key, server identifier, source allowlist, and whether that backend serves the zone.
- For licensing problems, check the licensed installation details and contact ArkHost if they need updating.
Review logs privately and redact API keys, authorization headers, and customer data before sharing them. Include the WHMCS, PHP, module, and cPanel versions and the action that failed.
Upgrades and support
Back up files, the database, and DNS data before replacing module files with a compatible package. Open the addon after the update and test both administrator and client workflows. Keep a recovery path to the previous files and database.
Contact ArkHost support for package and compatibility questions. This article does not replace the DNS server administrator's deployment-specific PowerDNS instructions.