Back to tutorials
Tutorial

cPanel Webmail Troubleshooting Tutorial (2026): Fix Roundcube Login Loops, Blank Pages, and “Connection to Storage Server Failed”

cPanel webmail troubleshooting tutorial for 2026: fix Roundcube login loops, blank pages, IMAP failures, and SSL/DNS issues fast.

By Anurag Singh
Updated on Oct 05, 2026
Category: Tutorial
Share article
cPanel Webmail Troubleshooting Tutorial (2026): Fix Roundcube Login Loops, Blank Pages, and “Connection to Storage Server Failed”

Most “webmail is down” tickets aren’t real mail outages. You’re usually dealing with bad cookies, a hostname/certificate mismatch, a stuck IMAP service, or a PHP session directory that ran out of space.

This cPanel webmail troubleshooting tutorial gives you a repeatable workflow to get Roundcube/Horde/SquirrelMail working again. It avoids random restarts and guesswork.

These steps assume WHM/cPanel on AlmaLinux/Rocky/CloudLinux (typical on hosting VPS). You’ll need root SSH and WHM access.

If you manage customer hosting, run these checks first. Save reboots or reinstalls for last.

What you’re actually troubleshooting (webmail vs SMTP vs IMAP)

Start by separating the failure. Webmail is an app inside cPanel, and it depends on several moving parts:

  • IMAP (Dovecot) to read mailboxes
  • SMTP (Exim) mainly to send mail from webmail
  • DNS + SSL so users land on a trusted, consistent login host
  • PHP plus local storage for sessions/cache (especially Roundcube)

If Outlook/Thunderbird works but webmail fails, stay on the webmail layer. Focus on ports 2095/2096, certificates, sessions, and PHP.

If both desktop clients and webmail fail, treat it as an IMAP problem until proven otherwise.

Quick triage checklist (5 minutes)

Run these in order. They catch the usual causes fast and keep you from debugging the wrong layer.

  1. Confirm the hostname users should hit (often mail.example.com or the server hostname), then confirm DNS points to the right IP.
  2. Check IMAP is listening (Dovecot): ss -lntp | egrep ':(143|993)\b'
  3. Check disk space and inode pressure: df -h and df -i
  4. Scan for obvious webmail errors in logs: tail -n 200 /usr/local/cpanel/logs/error_log
  5. Verify AutoSSL/cert coverage for webmail endpoints (a rejected cert often looks like a “mysterious” login issue). If renewals look stuck, see HostMyCode’s cPanel AutoSSL troubleshooting.

If you host client sites on a VPS and you’re tired of “webmail is down” escalations that turn out to be certs, DNS drift, or disk pressure, a managed VPS hosting plan can hand off those recurring checks to people who do them every day.

Step 1: Reproduce the failure and capture the exact error

Don’t troubleshoot “webmail doesn’t work.” First, narrow the failure down before you touch the server:

  • Is it Roundcube only, or do Horde/SquirrelMail fail too?
  • Does it fail at login, or after login (mailbox view)?
  • Is it browser-specific (Chrome works, Safari fails)?

Common patterns:

  • Login loop (credentials accepted, then back to the login page)
  • Blank white page (PHP fatal, permissions, missing modules)
  • Connection to storage server failed (Roundcube can’t reach IMAP or TLS negotiation fails)
  • Server error: STATUS: Internal error occurred (usually IMAP/backend trouble)

Step 2: Validate DNS and hostname (the cause of many login loops)

Login loops often come from simple inconsistency. Cookies get set for one hostname, but the browser gets redirected to another.

SSL name mismatches can cause the same “it just keeps looping” behavior.

Check the server hostname

hostnamectl
/usr/local/cpanel/cpanel -V

Your WHM hostname should resolve to the server’s main IP. Run these quick sanity checks:

dig +short $(hostname -f)
curl -I https://$(hostname -f):2096/

Check the domain webmail endpoints

For domain-based access, users usually hit one of these:

  • https://example.com:2096
  • https://mail.example.com (either direct 2096 or via proxy)

Confirm the A records resolve where you think they do:

dig +short A mail.example.com
dig +short A example.com

If you’re mid-migration—or you suspect split-horizon DNS—don’t “fix” webmail yet. First confirm traffic isn’t being split between two servers.

Use the safer workflow in this DNS cutover tutorial.

Step 3: Fix SSL and HTTPS mismatches for webmail ports (2096/2078)

Browsers are unforgiving now. If the certificate doesn’t match the hostname (or the chain is broken/expired), webmail may fail quietly.

You may see repeated redirects. You may also see secure cookies failing to set.

First, see what certificate the server presents on the local webmail service:

openssl s_client -connect 127.0.0.1:2096 -servername $(hostname -f) </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates

Then test the hostname users actually type:

openssl s_client -connect mail.example.com:2096 -servername mail.example.com </dev/null 2>/dev/null | openssl x509 -noout -subject -issuer -dates

If you get the wrong cert, an expired cert, or a broken chain:

  • In WHM: Manage Service SSL Certificates → verify cPanel & Webmail Service has a valid certificate.
  • Make sure AutoSSL covers the server hostname and any mail. subdomains customers use.

If you’re rebuilding an older stack or cleaning up custom proxying, HostMyCode’s SSL certificate setup guide is a solid end-to-end checklist.

Step 4: Check Dovecot (IMAP) health and auth quickly

Roundcube is only as healthy as IMAP. If Dovecot is down, overloaded, or failing TLS, webmail breaks even if SMTP looks fine.

Service status

systemctl status dovecot --no-pager
journalctl -u dovecot -n 200 --no-pager

Port check

ss -lntp | egrep ':(143|993)\b'

Test authentication (safe, fast)

From the server, confirm an IMAPS handshake works:

openssl s_client -connect 127.0.0.1:993 -servername $(hostname -f) -quiet

You should see a Dovecot banner. If TLS fails here, check certificate alignment (service certs) and the system clock.

If the server time is drifting, SSL failures can show up across multiple services. The symptoms often look inconsistent.

Fix time first using VPS time sync troubleshooting.

Step 5: Resolve Roundcube login loops (cookies, proxy headers, session path)

A Roundcube login loop usually means the session cookie isn’t being saved. It can also mean the cookie can’t be reused on the next request.

In hosting environments, the same causes show up repeatedly:

  • Hostname mismatch: user hits mail.example.com but gets redirected to the server hostname (or the other way around).
  • Reverse proxy/Cloudflare “Flexible SSL”: the browser is HTTPS, but the backend appears as HTTP; cookie flags and redirect logic don’t line up.
  • Session storage failure: PHP can’t write sessions (permissions, disk full, inode exhaustion).

Confirm the scheme and headers (common behind proxies)

If you run a front proxy, make sure cPanel sees the correct scheme.

Proxying 2096/2078 is not the same as proxying a normal site vhost. Avoid custom setups unless you understand cPanel’s proxy services.

Quick diagnostic for redirect ping-pong:

curl -Ik https://mail.example.com:2096/ | sed -n '1,15p'

If you see bouncing between HTTP/HTTPS or between hostnames, fix DNS and SSL first.

If Cloudflare is in front, turn off “Flexible” and use Full (Strict) with a valid origin certificate.

Check storage pressure that breaks sessions

df -h /tmp /var /home
df -i /tmp /var /home

On many cPanel servers, PHP sessions land in /var/cpanel/php/sessions or /tmp.

If those fill up, Roundcube logins can loop even when credentials are correct.

One safe place to start (don’t touch mail spools):

find /tmp -maxdepth 1 -type f -name 'sess_*' -mtime +2 -print | head

If you’re repeatedly running out of space or inodes, treat it as a capacity and housekeeping issue.

Look for log growth, backup staging, or runaway temp files. HostMyCode’s VPS log rotation tutorial is a good fix for the “/var filled up and everything started failing” pattern.

Step 6: Fix “Connection to storage server failed” (Roundcube IMAP/TLS failure)

This message means Roundcube can’t maintain a working IMAP connection.

Treat it as IMAP connectivity or TLS first, not as a Roundcube bug.

Verify IMAP from the webmail host context

In most cPanel setups, Roundcube connects locally. Test local IMAPS:

openssl s_client -connect 127.0.0.1:993 -quiet </dev/null

If local works, test via the server hostname Roundcube may be using:

openssl s_client -connect $(hostname -f):993 -servername $(hostname -f) -quiet </dev/null

Watch dovecot logs while reproducing

tail -f /var/log/maillog

Common tells:

  • pam_authenticate() failed (bad password, suspended account, auth path issues)
  • SSL: error (certificate mismatch or time drift)
  • Too many connections (resource limits, abusive client, noisy neighbor)

If one account is hammering IMAP, you’ll need limits and isolation. This is especially common on reseller setups.

That’s easier to manage on a hosting-tuned HostMyCode VPS sized for email + web workloads rather than a minimal general-purpose VM.

Step 7: Blank pages or HTTP 500 in webmail (PHP or permissions)

A blank page is usually a PHP fatal error that never makes it to the browser.

Start with the server-side evidence.

Check cPanel’s error log

tail -n 200 /usr/local/cpanel/logs/error_log

Typical culprits include memory exhaustion, missing PHP extensions, permission/ownership problems, or a filesystem that’s gone read-only.

Common fixes

  • Memory limits: If you see Allowed memory size exhausted, review the account’s CloudLinux/PHP limits.
  • Permissions: For write failures, verify ownership under /home/USERNAME/ and confirm the filesystem isn’t mounted read-only.
  • Disk full: Often shows up as “failed to write session” or cache write errors.

If the server recently had storage latency or IO stalls, fix that first.

Webmail falls over quickly when disk gets slow. Use VPS disk I/O troubleshooting to confirm you’re not fighting iowait.

Step 8: Confirm Exim can send from webmail (and isn’t throttled)

“Send” failing in webmail isn’t always a deliverability problem.

Sometimes Exim is paused, the queue is stuck, or deferrals are piling up.

Check Exim status and queue size

systemctl status exim --no-pager
exim -bpc

If the queue is large or mail is deferred, use a structured queue workflow from VPS email queue troubleshooting.

If bounces mention “Bad HELO,” fix server identity first. Hostname and rDNS alignment matter.

This guide is the quickest path: SMTP HELO/EHLO hostname fix.

Step 9: Targeted cPanel repair steps (safe, minimal)

Once DNS, SSL, disk/inodes, and IMAP look healthy, use cPanel’s built-in tools to clear the remaining issues.

Keep it targeted. Don’t run every repair script you can find during business hours.

Restart cPanel services cleanly

/usr/local/cpanel/scripts/restartsrv_cpsrvd
/usr/local/cpanel/scripts/restartsrv_dovecot
/usr/local/cpanel/scripts/restartsrv_exim

Update cPanel and packages (if you’re behind)

/usr/local/cpanel/scripts/upcp --force

Plan updates. If this server hosts paying customers, take a snapshot first. That gives you a real rollback option.

HostMyCode documents a practical approach here: VPS snapshot tutorial.

Step 10: Prevent repeats with monitoring and simple guardrails

Once webmail is back, spend a few minutes making the next incident faster to diagnose.

  • Monitor key ports: 2096, 993, 587/465, 80/443. When 993 dies, webmail usually follows.
  • Alert on disk and inode thresholds: 80% used is an early warning that still gives you time to react.
  • Keep AutoSSL healthy: many “login loop” reports are really cert/hostname drift.
  • Publish one canonical webmail URL: pick the endpoint customers should use and keep it consistent.

If you want a lightweight monitoring stack for VPS and dedicated servers, this is a solid starter: Uptime Kuma + node exporter alerting.

Summary: the fast path to fixing cPanel webmail

Most webmail failures land in one of four buckets: DNS/hostname inconsistencies, SSL issues on 2096/IMAPS, Dovecot instability, or local storage/session write failures.

Work through the checks in order. You’ll usually recover service in under 30 minutes, without the “try a reboot” roulette.

If you don’t want to carry the pager for certificate renewals, mail queue jams, and disk alerts, run webmail on managed VPS hosting from HostMyCode. You keep root access where it’s useful, and you get help when the routine stuff breaks at 2 a.m.

If you host multiple domains and webmail uptime matters, run it on infrastructure sized for email + web together. HostMyCode offers VPS plans that fit cPanel workloads, plus managed VPS hosting if you want us to handle updates, monitoring, and recurring fixes.

FAQ

Why does Roundcube keep returning to the login screen?

Usually the session cookie can’t stick. Common causes include a hostname/scheme mismatch (HTTP vs HTTPS), redirects between different hosts, or PHP session write failures from disk/inode pressure on /tmp or the session directory.

Fix DNS + SSL first. Then confirm you have free space and inodes.

Webmail is broken but Outlook works—what does that mean?

That usually points to the webmail layer. Check SSL on port 2096, proxy/redirect behavior, and PHP/session storage.

If desktop clients are stable, IMAP is probably fine.

Which logs should I check first for cPanel webmail errors?

Start with /usr/local/cpanel/logs/error_log for UI/PHP issues and /var/log/maillog for Dovecot/Exim authentication, connection, and TLS errors.

Do I need to reinstall Roundcube to fix blank pages?

Almost never. Blank pages are typically PHP fatal errors (memory limits, missing modules), permissions/ownership problems, or filesystem trouble.

Use the logs to identify the failing component before you change anything.

What’s the safest “restart” sequence if customers are locked out?

Restart cpsrvd (cPanel service), then Dovecot, then Exim.

If the root cause is SSL drift or disk pressure, restarts may help briefly but won’t keep it stable.

cPanel Webmail Troubleshooting Tutorial (2026): Fix Roundcube Login Loops, Blank Pages, and “Connection to Storage Server Failed” | HostMyCode