Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

A document root is the filesystem directory a web server uses as the base for serving files for a website or domain. It is often named public_html on cPanel accounts, but the name and location vary: the server’s active configuration determines which directory applies and how a URL maps to it.

What a document root does

cPanel defines a domain’s document root as “the directory that contains a domain’s publicly-available files.” In a conventional file-serving setup, a web server uses that directory to locate requested content, such as an image or a page generated by a PHP script. A domain can instead be configured to proxy requests to a web application. cPanel explains that a domain serves content either as a document root of files or as a proxy to a web app, but not both at once. cPanel’s explanation of how domains serve content was last modified September 9, 2026.

The document root is a server-side location, not a URL and not necessarily the folder you happen to see first in a file manager. The server configuration ties a domain or part of a site to a filesystem path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How a URL maps to a file

Apache: DocumentRoot

In Apache’s default URL mapping, the server appends the requested URL path to the configured DocumentRoot. For example, Apache’s getting-started guide describes a site with a root of /var/www/html: a request for /work/ can resolve to /var/www/html/work/index.html if that file exists. Apache HTTP Server 2.4’s getting-started guide gives this as an example, not a universal location.

NGINX: root

NGINX uses the root directive to set a filesystem base and appends the request URI when constructing a file path. The directive can appear at different configuration levels, including http, server, and location, so the effective path depends on which configuration applies to a request. See NGINX’s guide to serving static content.

These examples describe common file mapping, not every request. Rewrites, aliases, application routing, and proxy settings can change which file or service handles a URL. When diagnosing a path, inspect the configuration that is active for the relevant domain and request.

Is public_html always the document root?

No. cPanel says public_html is typically the document root for an account’s primary domain; an additional domain may use a separate directory beneath the account’s public_html tree. Apache’s example instead uses /var/www/html. These are conventions and examples, not rules for every server. The configured root for the particular domain is authoritative. cPanel’s domain documentation describes its convention, while Apache’s guide shows its example path.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What happens when you change the document root?

In cPanel, the document root is defined relative to the account’s home directory. Changing the configured path tells the server to look in a different location; cPanel does not move or rearrange the existing site files automatically. If the site should load from the new location, its files must be moved or deployed there as appropriate. See cPanel’s Manage the Domain documentation.

Why a directory URL may show the wrong result

When someone requests a directory rather than a specific filename, the server may look for a configured index page. Apache’s example uses index.html. If no index page is present, the server’s directory-index settings determine whether a list of files is displayed or a different response is returned. If a directory URL fails to show the expected page—or exposes filenames—check both the deployed index file and the listing configuration. cPanel explains this behavior in its Indexes documentation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep private files outside the served tree

Because a document root is part of a site’s public-facing boundary, keep only content intended for web access in the served tree. Where the deployment allows it, store credentials, private backups, unrelated user files, and other sensitive material elsewhere. Apache warns against direct web access to a user’s home directory for security reasons in its URL-to-filesystem mapping documentation. Directory listings also matter: when enabled and no index page is present, visitors may be able to see filenames, as described in cPanel’s Indexes documentation. These general precautions do not establish whether any particular hosting setup is secure.

Check the document root when troubleshooting

  1. Identify the domain and the server or hosting panel that manages it.
  2. Find the configured root for that domain or virtual host; do not assume it is public_html.
  3. Confirm the site files are deployed in that location.
  4. For a directory URL that behaves unexpectedly, check the expected index filename and directory-listing settings.
  5. Check for application routing, rewrites, aliases, or proxy configuration that may handle the request without serving a file from the document root.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.