Guide

How to back up your website

A website backup is a copy of everything your site needs to come back after a mistake or a hack. Your host may make one: check, and keep your own.

In short: a backup is a photocopy of your records. Your host's backup is a copy kept in the same building: handy after a small mistake, no help if the building is lost or you stop paying the rent. Keep one more copy somewhere else, and check now and then that you can read it.

What a backup should include

The website's files
Its pages, design (the theme), add-ons (plugins or modules), and the pictures and documents you've uploaded.
The database
On WordPress, Drupal and similar systems, your words, events, products, orders and settings live here, not in the files. You need both the files and the database to bring a site back.
Your domain's settings
A screenshot or export of your DNS records (the lines that point your domain at your website and email), so you can set them up again if they're changed or lost.
Email
Mailboxes live with your email service, not with the website, so a website backup doesn't include them. Ask your email service how to export them, or whether it keeps deleted mail.
The originals
Your photos and documents at full size, in storage your organization owns. A website often keeps only smaller copies.
The list of accounts
Who holds the domain, hosting and email, each log-in's owner and each renewal date. See Domain, hosting and email: the difference.

Does my web host back up my site?

Often, yes, but the details differ from host to host: how often, how long each copy is kept, and where. Some plans charge extra for backups or for restoring one, and some say in the small print that keeping a backup is your job. Ask:

  • How often do you back up my site, and how many days back can I go?
  • Does it include the database as well as the files?
  • Is the copy kept away from the server my site is on?
  • Can I restore it myself, or do I ask you? Is there a charge?
  • Can I download a copy?
  • If I stop paying, how long do you keep my site before deleting it?

Even with good answers, keep a copy of your own. If the host loses the account, closes, or your plan lapses, its backups go with it.

Keep your own: the 3-2-1 rule

The 3-2-1 rule, from the US government's cybersecurity agency (CISA):

  • 3 copies of anything important: the live site plus two backups.
  • 2 kinds of storage, such as your host's backups and an online storage account your organization owns.
  • 1 copy away from the rest, so one problem can't take them all.

To make your own copy of a WordPress, Drupal or similar site, use the backup tool in your hosting control panel, or a backup plugin or module, and choose one that runs by itself on a schedule. Keep a few recent backups, not just the latest: a problem you notice late, like a hack, may already be in the newest one.

How often?

  • A site that changes now and then (a club, a town office, a small business): every week.
  • A busy site with new posts, events or orders every day: every day.
  • Before any big change: an update, a new plugin, a redesign or a move to a new host.

A good test: how much work would you hate to redo? Back up at least that often.

Test a restore

You only know a backup works once you've restored one. CISA advises testing that you can bring data back, all of it and part of it, and go back at least seven days.

  1. Check the backups exist. Look at the dates. Are they recent, and does each include the database?
  2. Restore a copy, not the live site. Ask your host to restore a backup to a test copy (often called "staging"), or do it yourself if your host offers one.
  3. Click around. Do the latest pages, pictures and forms work?
  4. Write down how you did it, so the next person can do it on a bad day.

Do it once now, and again whenever the way you back up changes.

On a website builder

Builders host your site and keep it running, but what you can bring back after a mistake differs a lot:

  • Some keep a version history. You can restore an earlier saved or published version of the whole site. Restoring removes later changes.
  • Some have no history to go back to. You can duplicate the site before a big change, but the copy is a new site and may not include everything, such as store orders or the domain.
  • Online stores often let you export products, customers and orders as spreadsheet files (CSV) and download your theme. Pictures usually aren't in the spreadsheet.
  • On any builder, keep your own copy of your words and original photos.

Search your builder's help for "site history", "restore" or "duplicate" to see which kind yours is.

Send this to your web host

Not sure what to say? Copy this into an email, add your website's address, and send it.

Hi,

Could you tell me how [your website address] is backed up?

1. How often do you back it up, and how many days back can we go?
2. Does the backup include the database as well as the files?
3. Is it stored away from the server the site is on?
4. How do we restore one, and is there a charge?
5. Can we download a copy to keep ourselves?
6. When was the last backup?

We'd also like to test a restore to a test copy (not the live site) once. Could you help with that?

Thanks

What PageKiwi can help with

  • Site Watch checks your site every night and emails you if it stops loading, so you know when you might need a backup.
  • Who hosts this website? names your web host, domain company and email service: the people to ask.

PageKiwi Tips

Plain-English website tips by email, coming soon. Unsubscribe in one click.

  • The two dates that take a website offline, and how to never miss them
  • A three-minute accessibility check anyone can do
  • How to spot a fake "your domain is expiring" email

We email you a link to confirm first. Never sold or shared. What we keep · Past tips

Know someone this would help? Share it

Quick question

Did this guide help with your problem?