Website Upload & File Manager

How to Manage File Permissions in DirectAdmin

By the Domain India teamPublished 9 min read
Knowledge base article
Contents (9 sections)

File permissions decide who can read, change and run each file in your hosting account. Get them right and your site works and stays hard to tamper with; get them wrong and you see "403 Forbidden", "500 Internal Server Error" or, worse, a site that anyone can write to. This guide explains the numbers and shows three ways to change them on DirectAdmin hosting: the File Manager, an FTP client and SSH.

Key takeaways

On DirectAdmin hosting, use 644 for files and 755 for folders, and tighten config files that hold passwords (such as wp-config.php) to 640 or 600 if the site still works. Never use 777. Change one item in DirectAdmin's File Manager by selecting it and choosing its permissions option; change a whole site at once with an FTP client or SSH, setting files and folders separately.

1. What the numbers mean

Every file and folder has three sets of permissions:

  • Owner: your hosting account user.
  • Group: a group of users on the server.
  • World (others): everyone and everything else, including other processes.

Each set gets a digit made by adding up read, write and execute:

RightValueOn a fileOn a folder
Read (r)4View the contentsList what is inside
Write (w)2Change or delete the fileCreate, rename or delete items inside
Execute (x)1Run it as a programOpen the folder and reach items inside

So 644 means owner 6 (4+2, read and write), group 4 (read), world 4 (read). 755 means owner 7 (read, write, execute), group and world 5 (read and execute). You will also see them written as letters, for example -rw-r--r-- for 644 and drwxr-xr-x for a 755 folder.

2. The permissions your site should have

ItemPermissionWhy
Files: .html, .php, .css, .js, images644You can edit; the web server can only read
Folders755You have full access; the web server can open them
Config files with passwords (wp-config.php, .env, config.php)640 or 600Hides secrets from other users, if your app still works
Upload or cache folders your app writes to755Your PHP scripts run as your user, so 755 is enough

On our DirectAdmin server, PHP runs through PHP-FPM as your own account user (measured on our DirectAdmin server, 24 September 2026). That matters: your scripts write files as you, the owner, so a folder never needs to be writable by group or world for your site to save uploads. If a plugin's instructions say "set this folder to 777", 755 will work here.

Never set 777

777 lets anything that can reach the file change it. It is one of the most common ways websites get infected, and it fixes nothing on this server that 755 would not. If you find 777 on files or folders, change them back to 644 and 755. If your site was already altered, follow the security checklist for hacked websites.

Folders you should not change

Our DirectAdmin server sets the account's top folders for you: your home folder is 710, the domains folder is usually 711 and each site's public_html is 755. Leave these alone. Making them tighter blocks the web server from reaching your site and gives a 403; making them looser gains nothing.

Your website files live in /home/username/domains/yourdomain.com/public_html, one folder per domain. The File Manager guide shows where each panel keeps them.

3. Change permissions in DirectAdmin's File Manager

This is the easiest way to fix one file or a handful.

  1. Open DirectAdmin.
    Sign in to the client area, open your hosting service and use the button that opens DirectAdmin, or sign in with the details from your welcome email. See how to log in to your control panel if a login fails.
  2. Open File Manager
    from the dashboard, or type "file" in the panel's search box.
  3. Go to the folder.
    Open domains, then your domain, then public_html, and on to the folder that holds the item.
  4. Select the item
    by ticking its checkbox. You can tick several items that need the same value.
  5. Open the permissions option.
    Choose Permissions (or chmod) from the toolbar or the right-click menu; in some versions you can click the number in the permissions column instead.
  6. Set the value.
    Type the number, for example 644, or tick the read, write and execute boxes for owner, group and world.
  7. Save and check.
    Confirm, then look at the permissions column to see the new value.

Menu labels differ slightly between DirectAdmin versions and skins. If you can't find the option, ask support and tell us which file you want to change.

DirectAdmin File Manager with the domains folder open, a folder tree including public_html and Trash Bin, and New Folder, New File and Upload buttons
The Permissions column in DirectAdmin's File Manager shows each item's value.
Recursive changes: files and folders need different numbers

If the File Manager offers to apply permissions to everything inside a folder, don't use it to set one number on a mixed folder. 644 on folders makes them unreachable (403 errors), and 755 on every file marks them all as programs. Set folders and files separately with an FTP client or SSH, as below.

4. Change permissions with an FTP client

FTP clients such as FileZilla can set permissions for a whole site and can treat files and folders separately.

  1. Connect
    with FTP over explicit TLS, using the FTP details from your client area. What settings do I need to upload my website? lists them.
  2. Right-click the folder
    (for example public_html) and choose File permissions.
  3. Fix the folders.
    Enter 755, tick Recurse into subdirectories, choose Apply to directories only and click OK.
  4. Fix the files.
    Right-click the same folder again, enter 644, tick Recurse into subdirectories, choose Apply to files only and click OK.
  5. Tighten secrets.
    Right-click wp-config.php or your .env file on its own and set 600. Load the site to make sure it still works; if not, use 640.

5. Change permissions over SSH

Jailed SSH access is available on every shared hosting plan (cPanel, DirectAdmin, Webuzo). It is off by default; ask support to enable it for your account. Login uses an SSH key, not a password. See enabling and accessing jailed SSH.

Once you are in, these commands reset a whole site. Replace the path with your own domain:

bash
cd ~/domains/yourdomain.com/public_html

# check what you have
ls -la

# folders to 755, files to 644
find . -type d -exec chmod 755 {} +
find . -type f -exec chmod 644 {} +

# tighten the config file that holds your database password
chmod 600 wp-config.php

# find anything still world-writable
find . -perm -o+w -ls

Run the commands from inside public_html, never from your home folder, so that you don't change the permissions of mail or system folders.

6. Fixing errors caused by permissions

What you seeLikely causeFix
403 Forbidden on the whole sitepublic_html or a parent folder tightenedSet public_html back to 755 and leave home and domains as they are
403 on one page, image or folderFile not readable (600 or 000) or folder missing executeSet the file to 644 or the folder to 755
500 error after changing permissionsUnusual values on scripts or .htaccess, such as execute-only or group-writable CGI scriptsSet files to 644 and folders to 755, then check the error log
"Permission denied" when saving in File ManagerFile not owned by your accountAsk support; you can't change a file you don't own
Plugin says a folder "is not writable"Folder set to 555 or lowerSet it to 755

For a full diagnosis, read Understanding and resolving HTTP error 403 and Troubleshooting a 500 Internal Server Error. Your error log shows the exact file the server refused, which is usually faster than guessing.

7. Permissions on Domain India DirectAdmin hosting

Our DirectAdmin hosting runs PHP-FPM as your own user, so the standard 644 and 755 work for WordPress and most other PHP apps with no special folders. Weekly JetBackup backups mean that if a permission change goes badly wrong, you can restore the affected files from JetBackup in your panel; see backing up and restoring with JetBackup.

DA Starter
₹100/mo + GST
  • 10 GB NVMe SSD Storage
  • 50 GB Monthly Bandwidth
  • 1 Website
  • 5 Email Accounts
See plan details
DA Growth
₹150/mo + GST
  • 30 GB NVMe SSD Storage
  • Unmetered Bandwidth
  • 5 Websites
  • 50 Email Accounts
See plan details

Card prices are Domain India list prices on 19 September 2026, excluding 18% GST. Compare every plan on DirectAdmin hosting.

Frequently asked questions

What permissions should files and folders have on DirectAdmin hosting?

Use 644 for files and 755 for folders. Configuration files that hold passwords, such as wp-config.php or .env, can be 640 or 600 as long as the site still works. Never use 777.

Is 777 ever needed on Domain India DirectAdmin hosting?

No. PHP runs as your own account user through PHP-FPM, so your scripts can already write to folders set to 755. 777 only lets others change your files and is a common cause of infections.

How do I change permissions for a whole website at once?

Use an FTP client such as FileZilla: set 755 recursively on directories only, then 644 recursively on files only. With jailed SSH enabled, use find with chmod to set folders and files separately.

Why do I get 403 Forbidden after changing permissions?

A folder in the path is probably too tight, or a file is not readable. Set public_html and the folders inside it to 755 and the files to 644. Do not change the permissions of your home folder or the domains folder.

Why can't I change the permissions of some files?

You can only change files your account owns. If File Manager or FTP reports permission denied on a file, open a support ticket with the file path so we can check its owner.

What does chmod mean?

chmod is the Linux command that changes a file's permissions. File Manager and FTP clients use it behind the scenes when you set a number such as 644.

Ready to tidy up your site? Start with the File Manager guide, or open a support ticket with the file path and the error you see if a permission change doesn't fix it.

DirectAdmin hosting that runs PHP as you

Every DirectAdmin plan includes File Manager, FTP over TLS, weekly JetBackup backups and jailed SSH on request.

See DirectAdmin plans

Ready when you are

Get DirectAdmin hosting from ₹100/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
DirectAdmin File Permissions: 644, 755 and chmod